Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Attack?
From: gdonl @ gv . ssi1 . com (Don Lewis)
Date: Tue, 11 Jun 1996 20:38:45 -0700
To: Darwin Martinez <Darwin_Martinez @ INS . COM>, firewalls @ GreatCircle . COM
In-reply-to: Darwin Martinez <Darwin_Martinez @ INS . COM>

On Jun 11,  7:07pm, Darwin Martinez wrote:
} Subject: Attack?
} All:
} 
} I'm consistently seeing the following message on my FW-1. 
} 
} netbios_dgm 17.x.x.122 17.255.255.255 upd
} and
} netbios_ns 17.x.x.121 17.255.255.255 upd
} 
} 
} Both of these appear on the "secure" side of the firewall's interface, yet
} my client has NO Class A 17 addresses, only network 10 addresses which I'm
} fwxlconf'ing to their appropriate CLass C for the internet. 

Looks like your client has a misconfigured device(s) on their network that
thinks it's address is 17.x.x.x and is sending out broadcasts on the local
network.  Time to break out the network sniffer tools.

} When I try to ping the above network 17 address, no luck.

Because the host you're using to send the ping packets thinks the route
to network 17 is out through the firewall.

If you configure another host on your client's network with a network
17 address, then it should be able to talk to the misconfigured device(s).
Maybe you'll get lucky and it will respond to a telnet or ftp connection
with a login banner that contains its name.

			---  Truck


Follow-Ups:
  • Re: Attack?
    From: "Steven Johnson (BUS)" <johnson @ bayflash . stpt . usf . edu>
Indexed By Date Previous: RealAudio
From: jvelasco @ gu . pro . ec (Martin Velasco)
Next: Re: RealAudio
From: Michael Dillon <michael @ memra . com>
Indexed By Thread Previous: Attack?
From: Darwin Martinez <Darwin_Martinez @ INS . COM>
Next: Re: Attack?
From: "Steven Johnson (BUS)" <johnson @ bayflash . stpt . usf . edu>

Google
 
Search Internet Search www.greatcircle.com