Xbox: making up MAC 00:50:F2:* and IP address 0.0.0.1
irwin at princeton.edu
Tue Dec 4 15:37:20 GMT 2001
I've begun seeing IP traffic apparently from a Microsoft Xbox
attached to our campus network.
I'm seeing UDP broadcasts from 0.0.0.1(3074) to 255.255.255(3074).
(Although in a few cases, the IPsrc was 255.255.255.255(3074).
Yes, that's right.) Naturally, these hit my IP egress spoof filters.
3074 is assigned as the xbox port (as per IANA).
The broadcasts are coming from a wide variety of MAC sources, all starting
with 00:50:F2. These are all apparently coming from a single device; it seems
to me that the device uses (makes up?) many different MAC addresses,
I've looked for any technical information that would explain why the
device grabs an IP address not belonging to it, and appears to make up
all those MAC addresses. (This doesn't appear right to me.) Haven't
found anything at Microsoft's xbox site, or other news/web searches,
other than to confirm that someone else has begun seeing the traffic too.
Anyone have any pointers to technical info about why the device is doing
this (and how to get it to behave better)?
OIT Network Systems/Princeton University
More information about the unisog