I blocked them on iptables... but I'm still investigating.

On 14 May 2010 21:58, aki <aki275@googlemail.com> wrote:
Hey Simon, I hope you know how urgent and critical your network
situation is. I'd not wait until Monday. Anyway its upto you to
understand the real risk the spoof is carrying since you manage your
network. Personally, I'd already have shut down the reserved subnets
as I wrote earlier. HTHs.

On Fri, May 14, 2010 at 9:01 PM, Simon Mbuthia <simon.mbuthia@gmail.com> wrote:
> Hi aki,
>
> The interesting thing is that the spoofing computer appears to be in my LAN
> because it's accessing the firewall through the internal interface. I did a
> packet sniff using wireshark on "ip.src == 10.230.0.63" and got the ethernet
> address, then did another scan with the expression "ethernet.src ==
> wh.at.i.got" and I got different LAN IP addresses... do I have a botnet or
> what?? The ethernet address is for a 3Com device. I have 3Com switches in my
> LAN. But 3Com switches aren't configured with IP addresses etc... unless
> 3COM themselves hardwired the configurations onto the devices... Anyway, my
> investigations continue on Monday.
>
> Let me know what you think.
>
>
_______________________________________________
Skunkworks mailing list
Skunkworks@lists.my.co.ke
http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
------------
Skunkworks Server donations spreadsheet
http://spreadsheets.google.com/ccc?key=0AopdHkqSqKL-dHlQVTMxU1VBdU1BSWJxdy1fbjAwOUE&hl=en
------------
Skunkworks Rules
http://my.co.ke/phpbb/viewtopic.php?f=24&t=94
------------
Other services @ http://my.co.ke