[nSLUG] IP Spoofing

Douglas Guptill dguptill at accesswave.ca
Fri May 13 15:02:39 ADT 2005


On Fri, May 13, 2005 at 02:13:08PM -0300, J. Paul Bissonnette wrote:
> 06:59:53     **IP Spoofing**         <IP>   Source IP:192.168.0.6 
> Port:3539  Dest IP:24.222.74.248 Port:5554
>  Does any one know what this means, it was in the hacker log of my router.

My guess is that a packet has come in from the internet with a source
address that is of the non-routed variety.  Conclusion:  whoever sent
the packet has fudged the source address.

These kind of packets are normally firewalled out.

Doug.

!DSPAM:4284ebd957542022267353!




More information about the nSLUG mailing list