Security Incidents mailing list archives

Re: 169.254.x.x (Dramatic increase in UDP Port 137 (NetBIOS Name Service) probe activity)


From: peak () ARGO TROJA MFF CUNI CZ (Pavel Kankovsky)
Date: Wed, 29 Mar 2000 11:09:31 +0200


On Sat, 25 Mar 2000, Jeffrey D. Carter wrote:

There is one other anomoly in the data below: 4 of the probe clumps
include an interleaved series of a remote address and an address in the
169.254.0.0 netblock....

169.254.0.0/16 is the netblock of choice for another silly Windows feature
called "IP autoconfiguration". Windows pick up a more or less random
address from this range and start using it if they fail to get an
IP address by DHCP...or when they have a bad day or something.

FYI: I have heard the following patch to registry would disable it...

----
REGEDIT4

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DHCP]
"IPAutoconfigurationEnabled"=dword:00000000
----

--Pavel Kankovsky aka Peak  [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."



Current thread: