From owner-freebsd-pf@FreeBSD.ORG Sun May 7 18:22:37 2006 Return-Path: X-Original-To: Freebsd-pf@freebsd.org Delivered-To: Freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BD0E716A404 for ; Sun, 7 May 2006 18:22:37 +0000 (UTC) (envelope-from louisk@cryptomonkeys.com) Received: from mx1.cryptomonkeys.com (abeyance.cryptomonkeys.com [67.42.3.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1510643D48 for ; Sun, 7 May 2006 18:22:36 +0000 (GMT) (envelope-from louisk@cryptomonkeys.com) Received: from [192.168.0.87] (monkey-router.cryptomonkeys.org [65.103.65.190]) (authenticated bits=0) by mx1.cryptomonkeys.com (8.13.5+Sun/8.13.5) with ESMTP id k47IMXAM005032 (version=TLSv1/SSLv3 cipher=RC4-MD5 bits=128 verify=NO) for ; Sun, 7 May 2006 11:22:35 -0700 (PDT) From: Louis Kowolowski To: Freebsd-pf@freebsd.org In-Reply-To: <20060507005418.63149.qmail@web31612.mail.mud.yahoo.com> References: <20060507005418.63149.qmail@web31612.mail.mud.yahoo.com> Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-3RBPMKqUrnw+b16tZ6Zp" Organization: Cryptomonkeys UNIX/Security Consulting Date: Sun, 07 May 2006 11:22:24 -0700 Message-Id: <1147026144.1095.44.camel@localhost> Mime-Version: 1.0 X-Mailer: Evolution 2.4.2.1 FreeBSD GNOME Team Port X-Virus-Scanned: ClamAV version 0.87.1, clamav-milter version 0.87 on abeyance.cryptomonkeys.com X-Virus-Status: Clean Cc: Subject: RE: Stranger addresses X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 07 May 2006 18:22:38 -0000 --=-3RBPMKqUrnw+b16tZ6Zp Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Sat, 2006-05-06 at 21:54 -0300, Aguiar Magalhaes wrote: > Hi Greg, >=20 > I have some windows machine in my LAN, but I'd like to > stop these packages on my network. I don't have DHCP. >=20 > Is it possible ?? >=20 > --- Greg Hennessy =20 >=20 > > =20 > > > Hi list, > > >=20 > > > I've blocking on internal interface some stranger > > addresses=20 > > > from our LAN.. > > >=20 > > > Here are they: 0.0.0.0.68 =20 > >=20 > > DHCP > >=20 > > > 172.16.1.125.137 > > > 172.16.1.125.138 > >=20 > > If you're not using that subnet, then it's nbt > > broadcast chatter.=20 > >=20 > >=20 > > grep /etc/services and google for more.=20 > >=20 > >=20 > >=20 > > Greg > >=20 It looks to me like the format that (t)ethereal uses when printing IPs and ports. I suspect that the last set of digits there are port numbers. --=20 Louis Kowolowski KE7BAX louisk@cryptomonkeys.com Cryptomonkeys: http://www.cryptomonkeys.com/~louisk --=-3RBPMKqUrnw+b16tZ6Zp Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (FreeBSD) iD8DBQBEXjrgZFV69jbeB6gRAjFMAJoCt6Rt0uLAWjtvsCEaI//lOV9VlQCg5PUF AAkLW6xUhCriLQNJNk1iZZQ= =qm+W -----END PGP SIGNATURE----- --=-3RBPMKqUrnw+b16tZ6Zp--