Security Basics mailing list archives

Re: Strange pings from 127.0.0.1


From: Kelly John Rose <mllists () ptbcanadian net>
Date: Thu, 24 Jun 2004 23:06:08 -0400

I agree with you fully, thus my statement that:

"unless it's an internal machine"

But if it's not an internal machine, all you can really do is figure out that it isn't an internal machine, and perhaps which switchport it's on. Which personally is not overly that useful. imho.

But, I guess if you are collecting every little bit of knowledge, that could be something vaguely useful.

.....Kelly John Rose.....

SecurityFocus Lists wrote:

On Tue, 2004-06-22 at 14:07, Kelly John Rose wrote:
Nope, that's completely useless. You can for one spoof mac addresses, so having any mac address is more or less meaningless. But, also, there is no reliable way to use the mac address to find the machine, unless it's an internal machine, you having the mac addresses of all internal machines written down, and the person is not spoofing.

Not completely useless... with a sniffed MAC, there's a good chance I
can investigate a little and determine whether it is internal, and if it
is, what switchport it's on (and therefore, in my case, which room it is
in).  Even determining the traffic is coming from outside my network is
a helpful bit of knowledge.

-matt


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------




---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: