Hi,
I've got a D-Link wireless router. Last night I got about 200 attack logs sent to me from it - one every few minutes. The contents looked like the following:
Nov/21/2005 08:12:37 Target IP(192.168.0.255), Target Port(138) Packet Dropped Nov/21/2005 08:12:37 Spoof IP(192.168.0.104), Spoof Port(138) Nov/21/2005 08:12:37 Spoof Attack fromd MAC(XX) Detect, Nov/21/2005 08:04:06 SMTP: send mail succeed Nov/21/2005 08:04:05 Target IP(192.168.0.255), Target Port(137) Packet Dropped Nov/21/2005 08:04:05 Spoof IP(192.168.0.104), Spoof Port(137) Nov/21/2005 08:04:05 Spoof Attack fromd MAC(XX) Detect,
The MAC address in this log corresponds to my MAC address. I've replaced it here with XX.
The Spoof IP is the IP of my system. The Target IP doesn't exist.
It seems like this attack is internal. But I am not sure why it is occurring. Can anyone shed any light?
My system is running Windows XP.
Thanks for your help.
Regards, Steve