Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 18 Jul 2002 10:47:21 -0700
From:      "Craig Miller" <craig@millerfam.net>
To:        "freebsd-security" <freebsd-security@freebsd.org>
Subject:   wierdness in my security report
Message-ID:  <006301c22e83$2b3d5b30$fe01a8c0@Desktop>

next in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Anyone have any ideas as to what might be causing the following to appear in my security report?

 arp: 12.236.220.1 moved from 00:b0:64:b7:6f:54 to 00:b0:64:b7:6f:a8 on dc0
> Jul 17 05:47:56 server /kernel: arp: 12.236.220.1 moved from 00:b0:64:b7:6f:54 to 00:b0:64:b7:6f:a8 on dc0
> arp: 12.236.220.1 moved from 00:b0:64:b7:6f:a8 to 00:b0:64:b7:6f:54 on dc0
> Jul 17 05:47:57 server /kernel: arp: 12.236.220.1 moved from 00:b0:64:b7:6f:a8 to 00:b0:64:b7:6f:54 on dc0

I thought those : delimited fields would be MAC addresses, but they don't match the MAC addresses of either of the two cards in my free-bsd box.  I have not checked the MAC addresses of the other network cards on my network.

Also, where does the "server /kernel" name come from.  "kernel" is not the name I gave my kernel, so I am suspicious.

Thanks,

--Craig


[-- Attachment #2 --]
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2716.2200" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face=Arial size=2>Anyone have any ideas as to what might be causing 
the following to appear in my security report?</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
<DIV>&nbsp;arp: 12.236.220.1 moved from 00:b0:64:b7:6f:54 to 00:b0:64:b7:6f:a8 
on dc0<BR>&gt; Jul 17 05:47:56 server /kernel: arp: 12.236.220.1 moved from 
00:b0:64:b7:6f:54 to 00:b0:64:b7:6f:a8 on dc0<BR>&gt; arp: 12.236.220.1 moved 
from 00:b0:64:b7:6f:a8 to 00:b0:64:b7:6f:54 on dc0<BR>&gt; Jul 17 05:47:57 
server /kernel: arp: 12.236.220.1 moved from 00:b0:64:b7:6f:a8 to 
00:b0:64:b7:6f:54 on dc0<BR></DIV>
<DIV><FONT face=Arial size=2>I thought those : delimited fields would be MAC 
addresses, but they don't match the MAC addresses of either of the two cards in 
my free-bsd box.&nbsp; I have not checked the MAC addresses of the other network 
cards on my network.</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>Also, where does the "server /kernel" name come 
from.&nbsp; "kernel" is not the name I gave my kernel, so I am 
suspicious.</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>Thanks,</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>--Craig</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV></BODY></HTML>

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?006301c22e83$2b3d5b30$fe01a8c0>