[nSLUG] IP Spoofing

J. Paul Bissonnette jpaulb at eastlink.ca
Fri May 13 17:38:07 ADT 2005


Dop Ganger wrote:

> On Fri, 13 May 2005, J. Paul Bissonnette wrote:
>
>> 06:59:53     **IP Spoofing**         <IP>   Source IP:192.168.0.6 
>> Port:3539 Dest IP:24.222.74.248 Port:5554
>> Does any one know what this means, it was in the hacker log of my 
>> router.
>
>
> A machine was trying to connect to your machine on port 5554. This was 
> probably someone infected with a virus that scans for other machines 
> that have been infected by Sasser, as Sasser uses port 5554. Since the 
> source address is RFC1918 space, I suspect it was a machine on your 
> local subnet as I believe Eastlink filters out reserved addresses at 
> the gateway.
>
> Not something to really worry about, unless you have a machine 
> 192.168.0.6 on your own network, in which case you may want to run a 
> virus scan.
>
> Cheers... Dop.
>
>
>
> _______________________________________________
> nSLUG mailing list
> nSLUG at nslug.ns.ca
> http://nslug.ns.ca/cgi-bin/mailman/listinfo/nslug
>
> 
>
Thanks, Don't have a 192.168.0.6 on my network. Unless some one 
installed it while I was away. :wink:

-- 

J. Paul Bissonnette
http://canadian-dream.com


!DSPAM:4285103263497162812837!




More information about the nSLUG mailing list