Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations sizbut on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ISA Intrusion attempted

Status
Not open for further replies.

garpal

Technical User
Jul 15, 2002
12
US
I occassionally get these messages, and most come from larger networks, but today I got one from a 192.168 IP address, which I believe should be someone's internal network. Any clue to the seriousness, or how this address could be the source? Has anyone seen this from this type of address before?

---
ISA Server detected an Internet Protocol (IP) half-scan attack from IP address 192.168.0.101.
---

Thanks in advance
 
Its called IP spoofing.
When the person fakes the source IP to an address that is not their own. This is done for (D)DOS attacks and such.
For example...
I want to scan your network, but I don't want you to know its me. So I can use a feature in nmap (popular port scanning tool) called a decoy list. It will send a scan from my mamchine to yours. Now you'll see my IP scanning your IP. If I use a decoy list it will send many more scans using spoofed IPs. So it will look like a alot of people are scanning, making it harder for you to find the real attacker.

See what I mean? If not...
Article on Spoofing:

Cool upcoming game! Check it out!
!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top