Security Incidents mailing list archives
Re: a lot of spoofed traffic for port 8, does anybody recon this?
From: Devdas Bhagat <devdas () worldgatein net>
Date: Mon, 14 May 2001 22:34:48 +0530
On Mon, 14 May 2001, Bob Johnson spewed into the ether:
port 8 on the client system (i.e. the system it is connecting to the
This is ICMP! There is no concept of ports in ICMP. The 8 reefers to the type of ICMP message. Type 8 is ICMP_ECHO, type 0 is ICMP_ECHOREPLY. Someone/something pinging the modem to see if its alive, maybe?
In his case the modem has a public IP number, so the probe packets come from that address.
192.168/16 is RFC 1918 space, not public IP space. Devdas Bhagat
Current thread:
- a lot of spoofed traffic for port 8, does anybody recon this? Mikael Fors (May 10)
- Message not available
- Re: a lot of spoofed traffic for port 8, does anybody recon this? Devdas Bhagat (May 14)
- Message not available
- Message not available
- Re: a lot of spoofed traffic for port 8, does anybody recon this? Kevin Pietersma (May 14)
- RE: a lot of spoofed traffic for port 8, does anybody recon this? Guy L. Smith (May 14)
- Re: a lot of spoofed traffic for port 8, does anybody recon this? Kevin Pietersma (May 14)
- <Possible follow-ups>
- Re: a lot of spoofed traffic for port 8, does anybody recon this? Jose Nazario (May 14)