OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: David Gibson (hermesgibson.dropbear.id.au)
Date: Wed Feb 20 2002 - 23:30:15 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Wed, Feb 20, 2002 at 10:25:45PM -0700, Ben Greear wrote:
    > Btw, here's a tcpdump trace from the strongarm box:

    Hmm... yes these look as if they are mangled ping packets. What are
    the IP addresses of the machines you're using?
    >
    > 21:24:17.358065 0:2:2d:b:27:a0 0:60:b3:69:56:67 0800 96: ip_hl < 5 (0)
    > 0054 0000 4000 4001 e041 ac01 0101 ac01
    > 0164 0800 48c3 d10e 0100 9479 743c e074
    > 0900 0809 0a0b 0c0d 0e0f 1011 1213 1415
    > 1617 1819 1a1b 1c1d 1e1f 2021 2223 2425
    > 2627 2829 2a2b 2c2d 2e2f 3031 3233 3435
    > 21:24:18.357950 0:2:2d:b:27:a0 0:60:b3:69:56:67 0800 96: ip_hl < 5 (0)
    > 0054 0000 4000 4001 e041 ac01 0101 ac01
    > 0164 0800 45c3 d10e 0200 9579 743c e174
    > 0900 0809 0a0b 0c0d 0e0f 1011 1213 1415
    > 1617 1819 1a1b 1c1d 1e1f 2021 2223 2425
    > 2627 2829 2a2b 2c2d 2e2f 3031 3233 3435
    > 21:24:19.357835 0:2:2d:b:27:a0 0:60:b3:69:56:67 0800 96: ip_hl < 5 (0)
    > 0054 0000 4000 4001 e041 ac01 0101 ac01
    > 0164 0800 3ac3 d10e 0300 9679 743c ea74
    > 0900 0809 0a0b 0c0d 0e0f 1011 1213 1415
    > 1617 1819 1a1b 1c1d 1e1f 2021 2223 2425
    > 2627 2829 2a2b 2c2d 2e2f 3031 3233 3435
    > 21:24:21.357605 0:2:2d:b:27:a0 0:60:b3:69:56:67 0806 72: arp-#2 for proto
    > #1540 (1) hardware #2048 (0)
    > 0800 0604 0001 0002 2d0b 27a0 ac01 0101
    > 0000 0000 0000 ac01 0164 7267 652d 6963
    > 653a 2f65 7463 2f70 636d 6369 6108 0300
    > 0000 0000 0000 0000
    > 21:24:21.567581 0:60:b3:69:56:67 0:2:2d:b:27:a0 0806 42: [|arp]
    > 0800 0604 0002 0060 b369 5667 ac01 0164
    > 0002 2d0b 27a0 ac01 0101

    -- 
    David Gibson			| For every complex problem there is a
    davidgibson.dropbear.id.au	| solution which is simple, neat and
    				| wrong.  -- H.L. Mencken
    http://www.ozlabs.org/people/dgibson