[Dshield] Mac address
security at admin.fulgan.com
Tue Mar 5 14:32:53 GMT 2002
Could be several things:
1/ A web server with more than one IP on it's NIC.
2/ A router simply passing along traffic from another network segment.
SK> While running a sniffer on my network I'm seeing one particular device that is
SK> generating a considerably higher amount of HTTP traffic than any other.
SK> This sniffer shows both the Mac and Ip address, in the case of this particular
SK> device the mac address always stays the same but the ip address keeps changing
SK> after about every four packets that it sends. Every other mac address I see
SK> has a consistent ip associated with it. Is this somebody spoofing ip
SK> addresses? If so how do I shut them down if I don't know their real ip
SK> Or am I just being a paranoid newbie?
Stephane mailto:security at admin.fulgan.com
More information about the list