http://qs321.pair.com?node_id=294085


in reply to Spoofing an IP using perl?

I don't know what kind of logs you are looking at, but my snort logs also seemed very strange to me recently. It appeared that strange things were coming from IPs that are near our IP range. The reason for this was MSBlaster and Nachi worm activity, though at first instance I also thought that someone was spoofing an IP address on some subnet (it is relatively easy to spoof an IP in you subnet as promiscious mode ethernet cards will pick up every packet). So basically what I am trying to say is that strange logs don't neccessarilly come from spoofed IPs -- worms and viruses are more often to blame.