par tomtom » 23 Juin 2003 20:01
Bonsoir,
<BR>
<BR>Je recherche des personnes qui seraint clientes chez noos.
<BR>Je sniffe un peu sur ma carte red de temps en temps, pour voir un peu ce qui se passe, et je suis assez surpris :
<BR>
<BR>Voila le resultat d'une minute de scan sans aucune appli connectée à Internet :
<BR>
<BR> 0.000000 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.80? Tell 81.67.0.1
<BR> 1.199839 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.20? Tell 81.67.0.1
<BR> 2.799541 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.80? Tell 81.67.0.1
<BR> 3.998187 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.240? Tell 81.67.0.1
<BR> 5.596893 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.20? Tell 81.67.0.1
<BR> 6.596412 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.13? Tell 81.67.0.1
<BR> 7.448030 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.38? Tell 81.67.0.1
<BR> 8.616364 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.80? Tell 81.67.0.1
<BR> 9.796148 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 10.994768 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 11.993509 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 13.192831 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 13.193181 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.43? Tell 81.67.0.1
<BR> 13.193488 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.43? Tell 81.67.0.1
<BR> 14.192394 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.39? Tell 81.67.0.1
<BR> 15.192539 10.201.168.1 -> 255.255.255.255 DHCP DHCP Offer - Transaction ID 0xffffc036
<BR> 15.222611 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.39? Tell 81.67.0.1
<BR> 16.010238 10.201.168.1 -> 255.255.255.255 DHCP DHCP ACK - Transaction ID 0xffffc036
<BR> 16.590898 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.223? Tell 81.67.0.1
<BR> 17.590307 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.20? Tell 81.67.0.1
<BR> 18.989494 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.20? Tell 81.67.0.1
<BR> 19.988944 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.231? Tell 81.67.0.1
<BR> 21.188291 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.39? Tell 81.67.0.1
<BR> 22.587582 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.79? Tell 81.67.0.1
<BR> 23.987261 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.134? Tell 81.67.0.1
<BR> 25.586001 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.20? Tell 81.67.0.1
<BR> 26.785839 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.134? Tell 81.67.0.1
<BR> 28.584193 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.79? Tell 81.67.0.1
<BR> 29.584186 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.27? Tell 81.67.0.1
<BR> 30.783011 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.179? Tell 81.67.0.1
<BR> 31.882510 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 32.840359 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.134? Tell 81.67.0.1
<BR> 33.883491 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.88? Tell 81.67.0.1
<BR> 34.980801 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.90? Tell 81.67.0.1
<BR> 36.180571 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.39? Tell 81.67.0.1
<BR> 37.179457 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 38.578742 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.27? Tell 81.67.0.1
<BR> 40.178648 10.201.168.1 -> 255.255.255.255 DHCP DHCP Offer - Transaction ID 0xffffcc72
<BR> 40.964454 10.201.168.1 -> 255.255.255.255 DHCP DHCP ACK - Transaction ID 0xffffcc72
<BR> 40.964599 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.90? Tell 81.67.0.1
<BR> 42.176785 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.21? Tell 81.67.0.1
<BR> 43.575870 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.125? Tell 81.67.0.1
<BR> 44.878191 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.1.134? Tell 81.67.0.1
<BR> 45.304145 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.167? Tell 81.67.0.1
<BR> 46.174464 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.125? Tell 81.67.0.1
<BR> 47.574116 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.39? Tell 81.67.0.1
<BR> 48.875205 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR> 50.572647 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.2.39? Tell 81.67.0.1
<BR> 51.371611 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.3.46? Tell 81.67.0.1
<BR> 52.118168 212.198.1.5 -> 224.0.0.1 IGMP V2 Membership Query
<BR> 52.571044 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.125? Tell 81.67.0.1
<BR> 53.872748 02:00:00:00:00:00 -> ff:ff:ff:ff:ff:ff ARP Who has 81.67.0.249? Tell 81.67.0.1
<BR>
<BR>
<BR>Une requete Arp par seconde, sur un reseau ou je suis tout seul, ils jouent à quoi ? Vous pensez que c'est pour reperer des rigolos qui utiliseraient leur arrivée reseau pour se recuperer plusieurs IP ?
<BR>
<BR>Si d'autres sont chez noos, je voudrais bien savoir si ils font ça partout...
<BR>
<BR>T.
<BR>
<BR>_________________
<BR>"Ce n'est pas parce qu'un problème n'a pas été résolu qu'il est impossible à résoudre" A. Christie<BR><BR><font size=-2></font>
One hundred thousand lemmings can't be wrong...