RE: Strange echo requests from 127.0.0.1 apparently toroot nameservers
"Terje Trane" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Ken Connelly wrote: > It's much more important to know what you don't know than > what you do know! Quite possible. And even more that I really know what I think I know (so I draw the correct conclusions). Please do a reality check on this: I see ICMP traffic, several packets per second, using Ethereal on a PC. -> something is going on in the PC or on the subnet. It is not a normal ping 'cos it is of much higher frequency. Are there eny natural causes for this or is it a DoS maybe? The IP destinations are a mix of internal DNS servers, root and toplevel DNS server and occationally an other (like yahoo). -> A DoS on the DNS system? The IP source is stated as 127.0.0.1. -> Seems to be originating in the PC The MAC-address of the source is not the same as the NIC in the PC. -> Is it not from the PC but from the subnet? Running tcpdump on another machine connected on the same hub shows nothing -> It is not leaving the PC (I must check that the nic the tcpdump was run on was in promiscous mode.) The MAC-address of the destination is not known on any PC, server or switch/router in our network. It has a vendor code that is from DEC, and the ISP's equipment is Cisco. -> It is spoofed? Does 08:00:2b:00:dc:dc and 08:00:2b:00:01:02 have any particular meaning? Is it just a bug in some of the monitoring software that is installed/tested (some uninstalled) on the machine? (HP-printer utilities, TopTools, various scanners) _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions