RE: speaking of getting hacked.
"Matt Towers" <[email protected]> Wed, 10 Aug 2005 11:47:23 -0700
| Newsgroups | gmane.network.wireless.seattle.devel |
|---|---|
| Message-ID | <[email protected]> |
Makes sense. That suggests that the destination address I saw almost has to have been a multicast address then, otherwise there shouldn't have been any log entries at all. -MCT -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Casey Halverson Sent: Wednesday, August 10, 2005 11:27 AM To: SeattleWireless Development List Subject: RE: speaking of getting hacked. The firewall, or TCP/IP stack for that matter, will see any packet if the destination Ethernet address is itself. The same goes for multicast and broadcast Ethernet frames. Whether your machine will drop the packet later on is dependent on other things. -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Matt Towers Sent: Wednesday, August 10, 2005 10:44 AM To: 'SeattleWireless Development List' Subject: RE: speaking of getting hacked. I suspect it was a multicast range that I was seeing as well (as opposed to the comcast network address). The logs on my m0n0 box get recycled fairly rapidly, so by the time I wrote this email, the entries in question had been lost. I've just never seen link-local addresses in the logs before. I guess I'd always assumed that any layer 3 addresses that were not part of the local subnet wouldn't be seen by the firewall at all, but now that I've seen it, it seems to make sense. Thanks for the info everybody. -MCT -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Casey Halverson Sent: Wednesday, August 10, 2005 7:23 AM To: SeattleWireless Development List Subject: RE: speaking of getting hacked. > Macs do an odd zeroconf thing where they assign themselves a > link-local address if they can't get a DHCP (or whatever) response. > This is normal. Windows machines will do the same if they cannot find a dhcp server. > I'm not sure why they'd be talking to random network (rather than > host) addresses, though. Are you sure it wasn't talking to a > multicast group? Rendezvous (aka Bonjour, mDNS) runs on 224.0.0.251, > port 5353. Other multicast stuff would be in the range > [224-239].*.*.*.*. > If it was actually sending packets to 24.0.0.0 that seems really > weird. As it happens that block is owned by Comcast. Likely, he was refering to a multicast range. _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev _______________________________________________ Dev mailing list [email protected] http://seattlewireless.net/mailman/listinfo/dev