Re: speaking of getting hacked.
Wim Lewis <[email protected]> Wed, 10 Aug 2005 01:02:50 -0700
| Newsgroups | gmane.network.wireless.seattle.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Aug 10, 2005 at 12:03:39AM -0700, Matt Towers wrote:
> I'm not quite sure what to make of this. After seeing the last post about
> the pebble box getting hacked, I had a look at my soekris/m0n0wall firewall
> logs. Aside from the regular port-scanning stuff, I saw link-local
> address(es) (169.x.x.x) camped out on my Wireless interface and attempting
> to connect to *network* addresses on various ports (e.g. 24.0.0.0, etc.).
>
> Someone had a Mac over at my place earlier so I'm guessing it may have been
> some rendezvous thing? Anybody have any other ideas what this is?
Macs do an odd zeroconf thing where they assign themselves a link-local
address if they can't get a DHCP (or whatever) response. This is normal.
I'm not sure why they'd be talking to random network (rather than
host) addresses, though. Are you sure it wasn't talking to a
multicast group? Rendezvous (aka Bonjour, mDNS) runs on 224.0.0.251,
port 5353. Other multicast stuff would be in the range [224-239].*.*.*.*.
If it was actually sending packets to 24.0.0.0 that seems really
weird. As it happens that block is owned by Comcast.
--
Wim Lewis <[email protected]>, Seattle, WA, USA. PGP keyID 27F772C1
_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev