RE: Strange echo requests from 127.0.0.1 apparently toroot nameservers

"Terje Trane" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Ken Connelly wrote:
> It's much more important to know what you don't know than
> what you do know!

Quite possible. And even more that I really know what I think I know (so I
draw the correct conclusions). Please do a reality check on this:

I see ICMP traffic, several packets per second, using Ethereal on a PC.
-> something is going on in the PC or on the subnet. It is not a normal ping
'cos it is of much higher frequency. Are there eny natural causes for this
or is it a DoS maybe?

The IP destinations are a mix of internal DNS servers, root and toplevel DNS
server and occationally an other (like yahoo).
-> A DoS on the DNS system?

The IP source is stated as 127.0.0.1.
-> Seems to be originating in the PC

The MAC-address of the source is not the same as the NIC in the PC.
-> Is it not from the PC but from the subnet?

Running tcpdump on another machine connected on the same hub shows nothing
-> It is not leaving the PC (I must check that the nic the tcpdump was run
on was in promiscous mode.)

The MAC-address of the destination is not known on any PC, server or
switch/router in our network. It has a vendor code that is from DEC, and the
ISP's equipment is Cisco.
-> It is spoofed? Does 08:00:2b:00:dc:dc and 08:00:2b:00:01:02 have any
particular meaning?

Is it just a bug in some of the monitoring software that is installed/tested
(some uninstalled)  on the machine? (HP-printer utilities, TopTools, various
scanners)


_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.