Re: arp table overflow due to windows worm

On Sa, 16.10.2004, 16:21, Ben Goedeke wrote:
> Kurt Roeckx wrote:
> Hmm. That gives me an idea:
> Destination	Gateway	Flags	Metric	Ref	Use	Iface
> UG	0	0	0	eth1
> With such a routing entry the firewall will try and resolve mac
> addresses when the worm is scanning 134.102.xxx.0 subnets, right? I off
> to the site to do some experimenting.

Yes! That's what I want to say with my first posting.


