image
image

Go Back   macosx.com > Mac Help Forums > Networking & Compatibility

Reply
 
LinkBack Thread Tools
  #1  
Old June 3rd, 2004, 03:08 PM
gorilla beta tester
 
Join Date: Sep 2000
Location: Los Angeles
Posts: 174
Thanks: 0
Thanked 1 Time in 1 Post
stizz is on a distinguished road
Can someone please tell me what this means?

Jun/03/2004 04:09:19 Target IP(192.168.42.255), Target Port(138) Packet Dropped
Jun/03/2004 04:09:19 Spoof IP(192.168.42.101), Spoof Port(138)
Jun/03/2004 04:09:19 Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,
Jun/03/2004 04:09:19 Target IP(192.168.42.255), Target Port(138) Packet Dropped
Jun/03/2004 04:09:19 Spoof IP(192.168.42.101), Spoof Port(138)
Jun/03/2004 04:09:19 Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,
Jun/03/2004 04:00:03 Target IP(164.67.62.194), Target Port(123) Packet Dropped
Jun/03/2004 04:00:03 Spoof IP(192.168.42.101), Spoof Port(123)
Jun/03/2004 04:00:03 Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,





I assume this means someone attacked me early this mornig,...but I have no way to make a damage assesment.

1 D-Link wirekess g router behind a dsl modem that feeds a pc and 2 macs via ethernet and lets me be wireless on my powerbook. I have no encryption, wanted to share my web connect. But if I was attacked,..I don't know. From the above log, am I in danger?
__________________
stizz

17" 1.33GHz G4 PowerBook
512Mb Ram
Tiger 10.4.6


Dula Core 1.66GHz Mini
2 Gb Ram
Tiger 10.4.6 / WinXP Pro
Reply With Quote
  #2  
Old June 3rd, 2004, 03:26 PM
brianleahy's Avatar
Colonel Panic
 
Join Date: Sep 2000
Location: Northern Ohio
Posts: 1,580
Thanks: 0
Thanked 0 Times in 0 Posts
brianleahy is on a distinguished road
It looks to me (I could be wrong) like your firewall successfully thwarted the attack, dropping the incoming packets.
__________________
OS X 10.4
G5 Dual 2GHZ / 160GB / 1GB RAM / Superdrive
Apple 20" Cinema Display
SmartDrive 120GB Firewire HD
Maxtor 250GB SATA


Visit my wife's eBay store !!

http://stores.ebay.com/Catchy-Creations-by-brendaonline

Now pining for a MacBook Pro...
Reply With Quote
  #3  
Old June 3rd, 2004, 04:08 PM
Zammy-Sam's Avatar
Desertchild
 
Join Date: Feb 2002
Location: Germany
Posts: 6,658
Thanks: 0
Thanked 0 Times in 0 Posts
Zammy-Sam is on a distinguished road
Is this your d-link log?
192.168.x.x sounds very much like a lan-member..
__________________
iBook 600; 12''; 640mb; 8mb Rage; DVD-CDRW-Combo, 20GB
P4 1.6; 2x80GB Raid1 (file-server)
tiBook 1Ghz, Superdrive, 768MB, 64mb 9000, 60GB
Reply With Quote
  #4  
Old June 3rd, 2004, 07:51 PM
scruffy's Avatar
Notorious Olive Counter
 
Join Date: Dec 2000
Location: Soviet Canuckistan
Posts: 1,726
Thanks: 0
Thanked 0 Times in 0 Posts
scruffy is on a distinguished road
Yes, that's the idea - it thinks someone is trying to spoof an internal IP address, when really they're on the outside. So - is that ethernet address 00-0A-95-AF-6A-F4 legitimate on your LAN? If so, then it's a false positive; if not then your firewall blocked it correctly...
__________________

What is the robbing of a bank compared to the founding of a bank?
-- Bertold Brecht
Reply With Quote
  #5  
Old June 3rd, 2004, 10:56 PM
gorilla beta tester
 
Join Date: Sep 2000
Location: Los Angeles
Posts: 174
Thanks: 0
Thanked 1 Time in 1 Post
stizz is on a distinguished road
Zammmy Sam,

yes, it is part of my d-link log and IP(192.168.42.x) is my LAN


Scruffy,
MAC(00-0A-95-AF-6A-F4) is not my powerbook. What else might it be? Its not the Routers MAC, and nothing else in the network is wireless. How do I check the MAC address on my Wifes PC?


And so at least I'm relieved to hear that it loks like my firewall succesfully thwarted the attacks. Here is more of the log for urther analysis:*

Time
Message
Source
Destination
Note

Jun/03/2004 18:47:33
Target IP(164.67.62.194), Target Port(123)
Packet Dropped

Jun/03/2004 18:47:33
Spoof IP(192.168.42.101), Spoof Port(123)

Jun/03/2004 18:47:33
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 17:39:18
Target IP(164.67.62.194), Target Port(123)
Packet Dropped

Jun/03/2004 17:39:18
Spoof IP(192.168.42.101), Spoof Port(123)

Jun/03/2004 17:39:18
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 16:31:03
Target IP(164.67.62.194), Target Port(123)
Packet Dropped

Jun/03/2004 16:31:03
Spoof IP(192.168.42.101), Spoof Port(123)

Jun/03/2004 16:31:03
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 15:22:46
Target IP(164.67.62.194), Target Port(123)
Packet Dropped

Jun/03/2004 15:22:46
Spoof IP(192.168.42.101), Spoof Port(123)

Jun/03/2004 15:22:46
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 14:14:31
Target IP(164.67.62.194), Target Port(123)
Packet Dropped

Jun/03/2004 14:14:31
Spoof IP(192.168.42.101), Spoof Port(123)

Jun/03/2004 14:14:31
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 13:17:35
Wireless PC connected
00-0A-95-F2-5A-DA

Jun/03/2004 13:11:35
Wireless PC connected
00-0A-95-F2-5A-DA

Jun/03/2004 13:09:43
Target IP(192.168.42.255), Target Port(138)
Packet Dropped

Jun/03/2004 13:09:43
Spoof IP(192.168.42.101), Spoof Port(138)

Jun/03/2004 13:09:43
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,
Jun/03/2004 13:09:43
Target IP(192.168.42.255), Target Port(138)
Packet Dropped

Jun/03/2004 13:09:43
Spoof IP(192.168.42.101), Spoof Port(138)

Jun/03/2004 13:09:43
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 13:06:13
Target IP(164.67.62.194), Target Port(123)
Packet Dropped

Jun/03/2004 13:06:13
Spoof IP(192.168.42.101), Spoof Port(123)

Jun/03/2004 13:06:13
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 13:03:35
Wireless PC connected
00-0A-95-F2-5A-DA

Jun/03/2004 12:57:36
Target IP(192.168.42.255), Target Port(138)
Packet Dropped

Jun/03/2004 12:57:36
Spoof IP(192.168.42.101), Spoof Port(138)

Jun/03/2004 12:57:36
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,
Jun/03/2004 12:57:36
Target IP(192.168.42.255), Target Port(138)
Packet Dropped

Jun/03/2004 12:57:36
Spoof IP(192.168.42.101), Spoof Port(138)

Jun/03/2004 12:57:36
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 12:57:35
Wireless PC connected
00-0A-95-F2-5A-DA

Jun/03/2004 12:51:35
Wireless PC connected
00-0A-95-F2-5A-DA

Jun/03/2004 12:45:36
Target IP(192.168.42.255), Target Port(138)
Packet Dropped

Jun/03/2004 12:45:36
Spoof IP(192.168.42.101), Spoof Port(138)

Jun/03/2004 12:45:36
Spoof Attack fromd MAC(00-0A-95-AF-6A-F4) Detect,

Jun/03/2004 12:45:36
Target IP(192.168.42.255), Target Port(138)
Packet Dropped

Jun/03/2004 12:45:36
Spoof IP(192.168.42.101), Spoof Port(138)
__________________
stizz

17" 1.33GHz G4 PowerBook
512Mb Ram
Tiger 10.4.6


Dula Core 1.66GHz Mini
2 Gb Ram
Tiger 10.4.6 / WinXP Pro
Reply With Quote
  #6  
Old June 4th, 2004, 12:30 AM
gorilla beta tester
 
Join Date: Sep 2000
Location: Los Angeles
Posts: 174
Thanks: 0
Thanked 1 Time in 1 Post
stizz is on a distinguished road
I apologize for the length, that is only 4 out of 20 pages of the log. I really don't know much about wireless, and appreciate any help in securing my network. From whta I gather so far, attacks have been unsuccesful?
__________________
stizz

17" 1.33GHz G4 PowerBook
512Mb Ram
Tiger 10.4.6


Dula Core 1.66GHz Mini
2 Gb Ram
Tiger 10.4.6 / WinXP Pro
Reply With Quote
  #7  
Old June 4th, 2004, 03:43 AM
Zammy-Sam's Avatar
Desertchild
 
Join Date: Feb 2002
Location: Germany
Posts: 6,658
Thanks: 0
Thanked 0 Times in 0 Posts
Zammy-Sam is on a distinguished road
Here an idea: check all MAC-adresses from your computers that are connected to your d-link router. For windows open dos prompt and type 'winipcfg /all' to get the MAC.
Do you have MAC-filtering on? I would recommend this, eventhough the attack was successfully blocked (if it wasn't a false positive).
__________________
iBook 600; 12''; 640mb; 8mb Rage; DVD-CDRW-Combo, 20GB
P4 1.6; 2x80GB Raid1 (file-server)
tiBook 1Ghz, Superdrive, 768MB, 64mb 9000, 60GB
Reply With Quote
  #8  
Old June 6th, 2004, 02:59 AM
scruffy's Avatar
Notorious Olive Counter
 
Join Date: Dec 2000
Location: Soviet Canuckistan
Posts: 1,726
Thanks: 0
Thanked 0 Times in 0 Posts
scruffy is on a distinguished road
Hmm. I missed the wireless part. It could be anyone connecting from the inside then; they could be in another apartment, across the street... It could even be accidental - their laptop just happened to pick up your access point not theirs.
__________________

What is the robbing of a bank compared to the founding of a bank?
-- Bertold Brecht
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 10:35 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0 RC1
Copyright 2000-2010 DigitalCrowd, Inc.