-
Strange Ip Addresses
My log file told me that a couple of exploits(LSASS and DCOM exploits) were tried on my system's one of the VM (windows xp2) from the following IPs
10.8.240.93
10.8.154.135
But how is this possible, since these addresse are in the reserved RFC 1918 address range and should never appear on public internet.
Any clues ?
-
What sort of log file?
Nepenthes for example reports quite a bit of "standard" traffic as Unknown DCOM Exploit (or something similar.. I don't have my log handy at the moment).
Also what is your network setup and where the box that's logging in relation to the box that's being targeted?
I can think of plenty of possibilities, but knowing more about your network would help filter out various possibilities.