- Red, 2250 points or more
Can anyone pls help me out in finding whts this stats shows ?is this an spoofin type of case or anythng related to that since the brdcast ip is 255.255.255.255 ??
SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts
Se5/2 X.X.X.X Null 255.255.255.255 11 CC3C 0045 3
Se4/0 X.X.X.Y Null 255.255.255.255 11 CC3C 0045 3
Se5/2 X.X.X.X Null 255.255.255.255 11 C775 0045 6
Se4/0 X.X.X.Y Null 255.255.255.255 11 C775 0045 6
This is possibly output of "show ip cache flow".
Note that port numbers are in hex.
CC3C - 52284.
C775 - 51061.
The above are the source ports. ( we dont bother abt that).
0045 - 69 - which is TFTP port.
Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.
You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.
Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.
Hope that helps!