×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Help !!!!!!!! IP flow Stats

Answered Question
Aug 21st, 2003
User Badges:
  • Red, 2250 points or more

Hi


Can anyone pls help me out in finding whts this stats shows ?is this an spoofin type of case or anythng related to that since the brdcast ip is 255.255.255.255 ??


SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts

Se5/2 X.X.X.X Null 255.255.255.255 11 CC3C 0045 3

Se4/0 X.X.X.Y Null 255.255.255.255 11 CC3C 0045 3

Se5/2 X.X.X.X Null 255.255.255.255 11 C775 0045 6

Se4/0 X.X.X.Y Null 255.255.255.255 11 C775 0045 6


regds

prem

Correct Answer by thisisshanky about 14 years 3 days ago

This is possibly output of "show ip cache flow".


Note that port numbers are in hex.


CC3C - 52284.

C775 - 51061.


The above are the source ports. ( we dont bother abt that).


0045 - 69 - which is TFTP port.


Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.


You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.


Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.


Hope that helps!


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
thisisshanky Thu, 08/21/2003 - 07:21
User Badges:
  • Purple, 4500 points or more

This is possibly output of "show ip cache flow".


Note that port numbers are in hex.


CC3C - 52284.

C775 - 51061.


The above are the source ports. ( we dont bother abt that).


0045 - 69 - which is TFTP port.


Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.


You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.


Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.


Hope that helps!


spremkumar Fri, 08/22/2003 - 21:49
User Badges:
  • Red, 2250 points or more

hi shankar


will be thkful if u can provdie me the link where i can convert the hexadec port numbers into decimal numbers..


thks

prem

thisisshanky Fri, 08/22/2003 - 23:24
User Badges:
  • Purple, 4500 points or more

Prem,


No need of any link for that.


Open windows calculator (Start Menu - > Run-> calc -- hit enter key).


On the Calc software, go to View - > Scientific. Click scientific to see DEC, HEX, BIN options on the calc.


Now Check the HEX checkbox and input the hex string that you see on the output of "show ip cache flow".


After you input the string, check the DEC checkbox. This will immediately convert your HEX port number into DEC (decimal) port number.


Or you could do a manual calculation.


Any hex number say ABCD =


A*16exp3+B*16exp2+C*16exp1+D*16exp0.


Calculating using the above formula,


0045 for example =


0*16exp3+0*16exp2+4*16exp1+5*16exp0 = 16*4+5=69


which is TFTP


Hope that helps!@

Actions

This Discussion