| To: | ilaiy <ilaiy.e@gmail.com> |
|---|---|
| Subject: | Re: ARP Requests |
| From: | "Jason Ross" <algorythm@gmail.com> |
| Date: | Tue, 7 Aug 2007 14:06:08 -0400 |
| Cc: | Kevin <kbiggs81@gmail.com>, pen-test@securityfocus.com |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | pentest-list2@consult.net |
| Delivered-to: | mailing list pen-test@securityfocus.com |
| Delivered-to: | moderator for pen-test@securityfocus.com |
| Dkim-signature: | a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=oeprbhou+vNfT5Ucku+C/Ot/m/nOqO8uSESSCnT1TFk9yn0Lq9OeEdrqfdisLqqXEpMGkXVjXovtYtG89EGmMW33VhGUHMvyDjq19b8SYIqCF3S39lEZwjmDB75QB5x0JfRQplzsQC6qE3gvlLGf/7S31uvdYrcmSPUO8qsWuR8= |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=GxUrBf1HOEPq/2lc2rklETx95oZ9Cee+o1eRzdwHO56cx9r3Q4g7aMGBFTPYhj1ZQHxbpSS5YlbMYaGHncfLXVlTLk4Ij/8Hk2OSflnpMtTvOmRx7F+y3eBuowZbLNwJuI/vtznU0ue99WAGXkkvoxsx1dd2WlPxV8uxFD5i1OQ= |
| In-reply-to: | <849b9b760708062210q5b15ec38jd6900c82fee54df0@mail.gmail.com> |
| List-help: | <mailto:pen-test-help@securityfocus.com> |
| List-id: | <pen-test.list-id.securityfocus.com> |
| List-post: | <mailto:pen-test@securityfocus.com> |
| List-subscribe: | <mailto:pen-test-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:pen-test-unsubscribe@securityfocus.com> |
| Mailing-list: | contact pen-test-help@securityfocus.com; run by ezmlm |
| References: | <46B75E56.1060603@gmail.com> <849b9b760708062210q5b15ec38jd6900c82fee54df0@mail.gmail.com> |
| Resent-date: | Tue, 7 Aug 2007 20:10:29 -0600 (MDT) |
| Resent-from: | pen-test-return-1078484768@securityfocus.com |
| Resent-message-id: | <20070808021029.32BBB2372AA@outgoing3.securityfocus.com> |
| Resent-sender: | listbounce@securityfocus.com |
| Sender: | listbounce@securityfocus.com |
On 8/7/07, ilaiy <ilaiy.e@gmail.com> wrote: > http://blogs.msdn.com/virtual_pc_guy/archive/2005/01/17/354971.aspx > > ./thanks > ilaiy > I'm curious how you figured out that seeing packets being sprayed across the wire was somehow related to a Virtual PC startup error message? As I read the question, I was wondering whether the remote PC was configured for dhcp/bootp and if so, thought that perhaps it was caught in a loop attempting to get an address but was unable to do so. In that case, resetting the network connection to resolve the problem would make some sense. It would seem that I was way off though, based on the fact that Virtual PC gives an error matching that MAC if it's borked and refuses to start up. ./thanks indeed for that insightful help, I certainly learned something new today, and am most impressed with your deductive powers! As a side note, it may be worth noting that ARP requests, by their nature, generally will have a destination of 00:00:00:00:00:00. This is because they are broadcast to the entire network segment. I would venture a guess that the packet 'malformed-ness' is not due to the destination address, but to something else (data contained within the packet, incorrect header info, etc.) It may also be worth examining the source host closely to see if there is something running which is attempting to spoof ARP requests/replies in an effort to capture traffic. Since resetting the network connection "fixed" the issue, I think it's unlikely, but it never hurts to see. -- jason ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Discovering Live Hosts, Nikhil Wagholikar |
|---|---|
| Next by Date: | Re: Discovering Live Hosts, Jure Krasovic |
| Previous by Thread: | RE: ARP Requests, Nicolas villatte |
| Next by Thread: | Discovering Live Hosts, Nikhil Wagholikar |
| Indexes: | [Date] [Thread] [Top] [All Lists] |