Re: Strange echo requests from 127.0.0.1 apparently to root nameservers
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Foundstone has a tool, fport, which will "Identify unknown open ports and their associated applications." http://www.foundstone.com Sorry, don't have a direct link to the tool but follow this path: » Home > Resources > Free Tools Quoting Terje Trane <[email protected]>: > > I tried to troubleshoot a PC that all of a sudden would connect but > not > route traffic to a remote site by VPN and started Ethereal to see if I > could > see where the packets were going. > > To my surprise I can see a dozen ICMP echo request packets per second > sent > from 127.0.0.1. Every other is to my internal DNS-servers, and the > rest > (except for a few) to *.root-servers.net and *.gtld-servers.net. > > My thought was that this is malware scanning or trying a DoS on the > DNS, > though AV is up to date and running. However, the firewall technician > says > he cannot see this traffic at the firewall. I tried using tcpdump on > an > other machine on the same hub and cannot see this traffic, so I guess > it > must be local? > > By looking at the MAC-addresses i see that all packets are from > 08:00:2b:00:dc:dc which is not the MAC address of the local PC and > completly > unknown to me, and they are sent to 08:00:2b:00:01:02 which is also > unknown. > 08:00:2b is the vendor code for DEC and we have no DEC equipment here. > > I tried killing the processes I don't know on this PC, but not all will > die. > Is there any way in Windows I can see what process is generating what > TCP/IP > traffic? > > And most important: What can this be? > > > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions