Grimsqueaker
Well-Known Member
- Joined
- Feb 14, 2005
- Messages
- 110
- Reaction score
- 0
I have been picking up what Sygate firewall thinks is a Code Red DoS attack from the 196.46 network which seems to be the WBS IP range. The IP address changes in this network but the remote MAC is always 01-00-20-00-01-00. The event lasts for a few minutes and normally happens less than 10 times. I have been using the "stop all active response" function which seems to make Sygate happy.
Has anyone else experienced this? Does anyone know if this is Sygate making a stupid mistake like assuming that Windows help is a hijack?
Backtracing and using whois yields the following:
OrgName: African Network Information Center
OrgID: AFRINIC
Address: CSIR/icomtek
Address: 43A
Address: PO Box 395
City: Pretoria
StateProv: Gauteng
PostalCode: 0001
Country: ZA
NetRange: 196.46.0.0 - 196.46.15.255
CIDR: 196.46.0.0/20
NetName: AFRINIC-196-46-0-0
NetHandle: NET-196-46-0-0-1
Parent: NET-196-0-0-0-0
NetType: Transferred to AfriNIC
Comment: This IP address range is under AFRINIC responsibility.
Comment: Please see http://www.afrinic.net/ for further details,
Comment: or check the WHOIS server located at whois.afrinic.net.
RegDate: 2005-02-21
Updated: 2005-02-21
OrgAbuseHandle: GENER11-ARIN
OrgAbuseName: Generic POC
OrgAbusePhone: +230 4666616
OrgAbuseEmail: [email protected]
# ARIN WHOIS database, last updated 2005-05-23 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Has anyone else experienced this? Does anyone know if this is Sygate making a stupid mistake like assuming that Windows help is a hijack?
Backtracing and using whois yields the following:
OrgName: African Network Information Center
OrgID: AFRINIC
Address: CSIR/icomtek
Address: 43A
Address: PO Box 395
City: Pretoria
StateProv: Gauteng
PostalCode: 0001
Country: ZA
NetRange: 196.46.0.0 - 196.46.15.255
CIDR: 196.46.0.0/20
NetName: AFRINIC-196-46-0-0
NetHandle: NET-196-46-0-0-1
Parent: NET-196-0-0-0-0
NetType: Transferred to AfriNIC
Comment: This IP address range is under AFRINIC responsibility.
Comment: Please see http://www.afrinic.net/ for further details,
Comment: or check the WHOIS server located at whois.afrinic.net.
RegDate: 2005-02-21
Updated: 2005-02-21
OrgAbuseHandle: GENER11-ARIN
OrgAbuseName: Generic POC
OrgAbusePhone: +230 4666616
OrgAbuseEmail: [email protected]
# ARIN WHOIS database, last updated 2005-05-23 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Last edited: