[Dshield] Mac address

Keen, Wayne Wayne.Keen at dyncorp.com
Tue Mar 5 14:16:52 GMT 2002


what sniffer are you running?

-----Original Message-----
From: Scott Kegley [mailto:scott at mont.lib.md.us]
Sent: Tuesday, March 05, 2002 9:14 AM
To: list
Subject: [Dshield] Mac address


Ok, another newbie question.

While running a sniffer on my network I'm seeing one particular device that
is 
generating a considerably higher amount of HTTP traffic than any other.

This sniffer shows both the Mac and Ip address, in the case of this
particular 
device the mac address always stays the same but the ip address keeps
changing 
after about every four packets that it sends. Every other mac address I see 
has a consistent ip associated with it. Is this somebody spoofing ip 
addresses? If so how do I shut them down if I don't know their real ip 
address?

Or am I just being a paranoid newbie?

Thanks
Scott

_______________________________________________
Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:
http://www1.dshield.org/mailman/listinfo/list




More information about the list mailing list