lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <200403030031.i230VpP23011@netsys.com>
From: skivebug2 at yahoo.com.sg (Ariesto)
Subject: SQL-worm 1 IP multiple MAC???

Hi all,

 

I've just found the old SQL-slammer again in my customer network and notice
something that I've never notice before:

 

The worm sends UDP packet using 1 static spoof source IP and 1 static spoof
dest IP, but the MAC address changes in every packet (mostly the source
mac).  What is happening here??  Have anybody notice this before?? 

 

Cheers,

 

-A

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20040303/8fa0ca39/attachment.html

Powered by blists - more mailing lists