I've come across some strange activity recently.
Thousands of ICMP packets per second... I wish I would have saved the Ethereal snapshot I took when it was occuring.
They were all ICMP packets with a SRCIP=0.0.0.0 and DSTIP=0.0.0.0. Looking at the mac layer it had various SRC MAC addresses and a consistant DST MAC address of FF:FF:FF:FF:FF:FF.
I narrowed it down to a single port on my switch and disabled that port, by the time I got a tech out there to analyze this "attack" or packet storm, it had disappeared.
What would cause a host(s) to send out thousands of ICMP packets per second? I mean it was bad I was seeing up to 3,000pps. They were all about 74bytes in size if I remember correctly.