Security Incidents mailing list archives

Ether Broadcast


From: "Guins, Shawn (US - Dallas)" <sguins () DELOITTE COM>
Date: Tue, 19 Dec 2000 12:29:20 -0600

Hello all-
I've noticed unusual Ether Broadcast on my internal network.  I haven't been
able to locate the server that is making these broadcasts.  These packet are
listed by two of my sniffers I use as "Unknown Protocol".  It broadcasts
around 24.5 Kbs, so it's a good deal of data.  This might not be the
appropriate list, so I apologize for the change in topic.  Can anyone tell
me what this is?  There's what is being transmitted:

EtherPeek Decoded Packet File
Saved: Tue Dec 19 10:55:13 2000

Packet #5655
  Flags:        0x00
  Status:       0x00
  Packet Length:1514
  Timestamp:    10:51:30.038601 12/19/2000
Ethernet Header
  Destination:  ff:ff:ff:ff:ff:ff Ethernet Broadcast
  Source:       02:01:00:00:00:00
  Protocol Type:88-6f
  Packet Data:  
  ¿.ÞÀ............  bf 01 de c0 03 02 00 00 01 00 00 00 00 00 00 00 
  .............OE8:  00 00 00 00 00 00 00 00 03 00 02 00 2e 8c 38 3a 
  ......0......ð.o  00 00 00 00 00 00 30 10 00 00 00 00 00 f0 ff 6f 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff 0f 
  ................  ff ff ff ff ff ff ff 0f 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  ff ff ff ff ff ff ff 0f ff ff ff ff ff ff ff 0f 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  2...............  32 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ................  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  ........          00 00 00 00 00 00 00 00 
Frame Check Sequence:  0x84280800

Shawn T. Guins
Security Admin/Systems Admin
Deloitte & Touche LLP
IAS Technology Center
972-450-0807             972-458-0210 Fax

Suite 500, Two Hillcrest Green
12720 Hillcrest Road
Dallas, TX 75230

- This message (including any attachments) contains confidential information
intended for a specific individual and purpose, and is protected by law.  -
If you are not the intended recipient, you should delete this message and
are hereby notified that any disclosure, copying, or distribution of this
message, or the taking of any action based on it, is strictly prohibited.


Current thread: