Security Incidents mailing list archives

Weird Packet


From: Leon Rosenstein <l_rosenstein () MONTELSHOW COM>
Date: Tue, 20 Feb 2001 10:53:33 -0500

Hi everyone.  I got this one packet last night (it was picked up by
zonealarm) and I was wondering if I might call on the talented people on
this list to help me learn how it was possible that the packet was on the
internet in the first place.

The firewall has blocked Internet access to your computer (NetBIOS Name)
from 10.1.1.205 (NetBIOS Name).

Time: 2/19/2001 21:51:48

How is it possible to have that non-routable IP send a packet my system?  I
know it could be forged but what would be the point?  I also know Nmap has a
decoy feature but that was the only packet that arrived.  None arrived
before (except the usual DNS and RPC scans which are starting to get kind of
annoying) and none after.  I am not scared that I am hacked or etc, I am
just interested in knowing strictly from a learning standpoint.  I know we
discussed something like this about 2 weeks ago but the fact that is
specifically a netbios scan might be a little different.  Anyway please feel
free to respond on or off list.

Thx guys (and ladies)

Leon


Current thread: