[Dshield] Mac address

Keen, Wayne Wayne.Keen at dyncorp.com
Tue Mar 5 14:16:52 GMT 2002

what sniffer are you running?

-----Original Message-----
From: Scott Kegley [mailto:scott at mont.lib.md.us]
Sent: Tuesday, March 05, 2002 9:14 AM
To: list
Subject: [Dshield] Mac address

Ok, another newbie question.

While running a sniffer on my network I'm seeing one particular device that
generating a considerably higher amount of HTTP traffic than any other.

This sniffer shows both the Mac and Ip address, in the case of this
device the mac address always stays the same but the ip address keeps
after about every four packets that it sends. Every other mac address I see 
has a consistent ip associated with it. Is this somebody spoofing ip 
addresses? If so how do I shut them down if I don't know their real ip 

Or am I just being a paranoid newbie?


Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:

More information about the list mailing list