RE: speaking of getting hacked.

"Matt Towers" <[email protected]> Wed, 10 Aug 2005 10:44:25 -0700
Newsgroups gmane.network.wireless.seattle.devel
Message-ID <[email protected]>
I suspect it was a multicast range that I was seeing as well (as opposed to
the comcast network address).  The logs on my m0n0 box get recycled fairly
rapidly, so by the time I wrote this email, the entries in question had been
lost.

I've just never seen link-local addresses in the logs before.  I guess I'd
always assumed that any layer 3 addresses that were not part of the local
subnet wouldn't be seen by the firewall at all, but now that I've seen it,
it seems to make sense.

Thanks for the info everybody.

-MCT

-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Casey Halverson
Sent: Wednesday, August 10, 2005 7:23 AM
To: SeattleWireless Development List
Subject: RE: speaking of getting hacked.

> Macs do an odd zeroconf thing where they assign themselves a 
> link-local address if they can't get a DHCP (or whatever) response. 
> This is normal.

Windows machines will do the same if they cannot find a dhcp server.
 
> I'm not sure why they'd be talking to random network (rather than
> host) addresses, though.  Are you sure it wasn't talking to a 
> multicast group? Rendezvous (aka Bonjour, mDNS) runs on 224.0.0.251, 
> port 5353. Other multicast stuff would be in the range 
> [224-239].*.*.*.*.
> If it was actually sending packets to 24.0.0.0 that seems really 
> weird. As it happens that block is owned by Comcast.

Likely, he was refering to a multicast range.

_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev

_______________________________________________
Dev mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/dev