impossible IP packet

impossible IP packet

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
impossible IP packet rossella 03-18-2005
Posted by on March 18, 2005, 8:23 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi, we have a couple of servers on our network that are sending UDP
packets port 137 and 138, NetBIOS, to themselves. The source IP and
destination IP is the same and they show up in our IDS as 'impossible
ip packets', I'm wondering if you think something on these servers
might have been miss configured at one time. They're Windows 2003
servers, one is our PDC and the other is a DHCP server. Thank you for
any help you may give.



Rossella Mariotti-Jones

Network Analyst, CCNA

Chemeketa Community College / IT

T 503 589 7775

F 503 399 4898

E rossella@chemeketa.edu

www.chemeketa.edu



Posted by Maxime Ducharme on March 18, 2005, 7:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Hello

Looks like LAND attacks :
http://www.securityfocus.com/archive/1/392354/2005-03-02/2005-03-08/0

Some Win2003 hosts are known to become unresponsive for some
seconds upond reception of these LAND attacks.

Configure your external firewalls to drop packets coming from
a range that is behind your firewall (spoofed packets),
and see if activity continues. If not, that means these packets
are not generated by your servers.

HTH

Maxime Ducharme
Programmeur / Spécialiste en sécurité réseau

> Hi, we have a couple of servers on our network that are sending UDP
> packets port 137 and 138, NetBIOS, to themselves. The source IP and
> destination IP is the same and they show up in our IDS as 'impossible
> ip packets', I'm wondering if you think something on these servers
> might have been miss configured at one time. They're Windows 2003
> servers, one is our PDC and the other is a DHCP server. Thank you for
> any help you may give.
>
>
>
> Rossella Mariotti-Jones
>
> Network Analyst, CCNA
>
> Chemeketa Community College / IT
>
> T 503 589 7775
>
> F 503 399 4898
>
> E rossella@chemeketa.edu
>
> www.chemeketa.edu
>




Posted by Maxime Ducharme on March 18, 2005, 9:55 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Another important point

A server that sends a packet to itself wont
use network media (i.e. cable) to send the
packet since it is local.

If the IDS isnt on the same machine, it should not
see these packets, so these are likely to come from
somewhere else.

It can be Internet, or another server. Try to capture
the MAC address and see if it is your router or a server.

Good luck :)

Maxime Ducharme
Programmeur / Spécialiste en sécurité réseau

> Hi, we have a couple of servers on our network that are sending UDP
> packets port 137 and 138, NetBIOS, to themselves. The source IP and
> destination IP is the same and they show up in our IDS as 'impossible
> ip packets', I'm wondering if you think something on these servers
> might have been miss configured at one time. They're Windows 2003
> servers, one is our PDC and the other is a DHCP server. Thank you for
> any help you may give.
>
>
>
> Rossella Mariotti-Jones
>
> Network Analyst, CCNA
>
> Chemeketa Community College / IT
>
> T 503 589 7775
>
> F 503 399 4898
>
> E rossella@chemeketa.edu
>
> www.chemeketa.edu
>




Similar ThreadsPosted
Packet Filtering July 1, 2005, 11:52 am
blocked packet February 16, 2008, 12:32 am
Firewall vs. Packet Filter? October 26, 2006, 1:43 am
Packet fragmentation question April 9, 2007, 4:11 pm
cisco pix 525 and packet filter August 2, 2007, 4:56 am
Packet Drops in the Internet December 3, 2007, 2:22 pm
Re: Likelihood of IT using a Packet Sniffer August 11, 2008, 5:24 pm
Re: Likelihood of IT using a Packet Sniffer August 11, 2008, 10:55 pm
Re: Likelihood of IT using a Packet Sniffer August 12, 2008, 2:14 am
Re: Likelihood of IT using a Packet Sniffer August 12, 2008, 11:20 am

The site map in XML format XML site map

Contact Us | Privacy Policy