|
-
June 17th, 2003, 09:24 PM
#11
Ok.... I laid my trap and lo and behold I have 7 packets.... all from that IANA reserved address, all to the same, non-existant address, all with TTL's within 2 or 4 of each other, all the same size, all with the same sequence ID.... Yes, the same sequence ID over the period of an hour or so....... Bloody wierd if you ask me. I'm almost tempted to plop a machine out there with that dest address and see if a conversation takes place. They have to be crafted packets though - or am I mislead - I thought the sequence ID began witha random number......
VERY interesting!!
Sorry to create more work for you. :-)
So, we have some bizarre Trojan out there sending these mysterious packets.
Who knows how many of the millions of home users are 0wn3d by this thing? Is this some impending Internet apocalypse waiting to happen?
I am not a packet-sniffing expert- is it possible for ISP's or companies to block these packets? Do they have a unique footprint you can block on aside from the packet size? I would think if you blocked all packets of that size you would lose some legitimate packets as well.
Thoughts?
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|