I have been seeing some unusual IP activity on a terminal server
and was wondering if it's possible to set up a sniffer off of a
dial in port????
There is an IP address appering in the log files of the terminal
server that does not belong, looks kinda like:
22.214.171.124 is a normal address on the terminal server and
along comes 126.96.36.199 (broadcast). The address in question
never goes out of the terminal server into the real network and
appears to be coming from a dial up connection.
Earl Pray, Network Analyst, Information Warfare Security Center