[nSLUG] IP Spoofing

Douglas Guptill dguptill at accesswave.ca
Fri May 13 15:02:39 ADT 2005

On Fri, May 13, 2005 at 02:13:08PM -0300, J. Paul Bissonnette wrote:
> 06:59:53     **IP Spoofing**         <IP>   Source IP: 
> Port:3539  Dest IP: Port:5554
>  Does any one know what this means, it was in the hacker log of my router.

My guess is that a packet has come in from the internet with a source
address that is of the non-routed variety.  Conclusion:  whoever sent
the packet has fudged the source address.

These kind of packets are normally firewalled out.



