Security Basics mailing list archives

Weird traffic


From: "Dissolved" <dissolved () comcast net>
Date: Sat, 10 Sep 2005 10:45:51 -0400

My internet at home has been going up and down (Comcast cable). All of my
neighbors have no problems. I have all cisco equipment, and have been
monitoring the logs and config. Everything looks ok. I decided to run
ethereal on one of my machines to see where the issue was. Initially, I
thought it was just failed DNS queries. But surprisingly, DNS is working.
Here is a few frames I captured about 5 minutes ago. 
-------------------------------------------------------------------
-192.168.3.10 (my machine) ------>   68.87.64.196  |DNS  query

-68.87.64.196--------------------->  192.168.3.10  |DNS response

-192.168.3.10 -----SYN--->  207.46.225.60 (TCP)  |Attempt to connect to
msn.com

-192.168.3.10 -----SYN--->  207.46.225.60 (TCP)  | 2nd Attempt to connect to
msn.com

-0.132.0.37---------->   37.37.0.148   (IP)      |Fragmented IP protocol  

-192.168.3.19.64768 ------>  192.172.177.0.51408 (TCP)  |8byte TCP header
-------------------------------------------------------------------------

Out of the above, IP addresses I don't recognize are:  0.132.0.37,
37.37.0.148, 192.168.3.19 and 192.172.177.0

Note, the last packet had an 8byte TCP header. I thought that was strange.
   
Also, I have no idea why these packets are showing up when I sniff
192.168.3.10. There is no port mirroring going on in any of my switches. 


Thanks in advance fellas


Current thread: