Community discussions

MikroTik App
 
fivenetwork
newbie
Topic Author
Posts: 45
Joined: Thu Jul 08, 2004 4:39 am

Mysterious Packets and unbeleivable traffic

Fri Jul 16, 2004 8:05 am

We are facing a rather funny problem. We see packets on our routers wherein both the source and destination IPs are not on our network! After tracking down the culprit machine we find a file "syshost.exe" to be the reason behind this. Once this particular file is disabled the activity on our routers stop.

This is perplexing for the traffic generated even over a PPPoE i/f limited at 40000/40000 is an astonishing 12Mbps plus uploads. Consequently the router CPU usage shoots to 100% and performance drops miserably.

How is the above happening??

No IPs are defined on the PPPoE interface. No other interface is connected to the LAN side. Only one other Ether card is used on the WAN side for the Internet connection.

We have also impelemented firewall rules whereby only traffic for authorised IPs are accepted on the router and all else is dropped/rejected.

Still the above happens. Is it because of the stupid bridging function built on WinXP? For we find this only on WinXP machines, so far. :evil:
 
Atom
just joined
Posts: 8
Joined: Fri Jul 02, 2004 1:13 am

Re: Mysterious Packets and unbeleivable traffic

Fri Jul 16, 2004 1:45 pm

Possible virus attack? :P
check it with nod32 (http://www.nod32.com)
 
sten
Forum Veteran
Forum Veteran
Posts: 923
Joined: Tue Jun 01, 2004 12:10 pm

Re: Mysterious Packets and unbeleivable traffic

Sat Jul 17, 2004 1:04 am

You mean you didnt do ingress filtering before???!!
Any network admin with just a little respect for himself does this.
Sounds like your average DoS/DDoS Zombie, BTW.

_// Sten Daniel Sørsdal
 
fivenetwork
newbie
Topic Author
Posts: 45
Joined: Thu Jul 08, 2004 4:39 am

Re: Mysterious Packets and unbeleivable traffic

Mon Jul 19, 2004 12:42 pm

You mean you didnt do ingress filtering before???!!
Any network admin with just a little respect for himself does this.
Sounds like your average DoS/DDoS Zombie, BTW.

_// Sten Daniel Sørsdal
INGRESS Filtering ?? Please elaborate ... Mebbe we are talking same functions but different terminlogy or we are missing something here.
 
User avatar
lastguru
Member
Member
Posts: 432
Joined: Fri May 28, 2004 9:04 pm
Location: Certified Trainer/Consultant in Riga, Latvia
Contact:

Tue Jul 20, 2004 12:27 am

Ingress traffic is the traffic that enters the router (e.g., from the clients)
 
fivenetwork
newbie
Topic Author
Posts: 45
Joined: Thu Jul 08, 2004 4:39 am

Wed Jul 21, 2004 5:54 am

Yeps we do that. But still are unable to figure out how the heck does this mysterious traffic pass through our routers
 
wjw
Frequent Visitor
Frequent Visitor
Posts: 91
Joined: Thu Jun 10, 2004 12:59 am
Location: New Zealand
Contact:

Wed Jul 21, 2004 1:42 pm

What are the IP's? have you tried finding out who's they are, where they are? that may help track the problem...

Who is online

Users browsing this forum: No registered users and 34 guests