[Dshield] Mac address

Scott Kegley scott at mont.lib.md.us
Tue Mar 5 14:14:08 GMT 2002

Ok, another newbie question.

While running a sniffer on my network I'm seeing one particular device that is 
generating a considerably higher amount of HTTP traffic than any other.

This sniffer shows both the Mac and Ip address, in the case of this particular 
device the mac address always stays the same but the ip address keeps changing 
after about every four packets that it sends. Every other mac address I see 
has a consistent ip associated with it. Is this somebody spoofing ip 
addresses? If so how do I shut them down if I don't know their real ip 

Or am I just being a paranoid newbie?


