Security Basics mailing list archives

Re: Weird IP


From: Venky Shankar <asynchronous.ack () gmail com>
Date: Wed, 04 Feb 2009 16:42:46 +0530

Can you attach some relevant parts of the log file i.e. lines having the
ip 172.16.x.x ?

Would be interesting to see he seq/ack numbers.

Rgds,
-Venky

Joseph Hanna wrote:
Hi everyone,

I am working on a case of fraud in my little organisation where we are
dealing with fraudulent credit cards. The only thing I can see is the
IP address has been logged as
172.16.x.x but isn't that Class B internal? How are they doing this? I
mean how are packets being routed between our web-server and that IP?
Any recommendations other than my blanked block all Class A and Class
B IPs?

Thanks Heaps,
J

  


Current thread: