[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: arp table overflow due to windows worm



On Sa, 16.10.2004, 16:21, Ben Goedeke wrote:
> Kurt Roeckx wrote:
...
> Hmm. That gives me an idea:
>
> Destination	Gateway	Flags	Metric	Ref	Use	Iface
> 134.102.0.0/16  0.0.0.0 UG	0	0	0	eth1
>
> With such a routing entry the firewall will try and resolve mac
> addresses when the worm is scanning 134.102.xxx.0 subnets, right? I off
> to the site to do some experimenting.

Yes! That's what I want to say with my first posting.

Christian



Reply to: