MichealC4
Programmer
- Jun 26, 2003
- 457
I have some Windows XP clients that are pinging the heck out of our domain controllers. Packet traces (which I don't have on me at the moment) look like your typical ICMP ping echo request. Type 8, code 0, payload is ABCDEFHIJKLMNOPQRSTUVWXYABCDEFGH (in all caps, as opposed to the payload being in all lowercase for typing it in in the command line). Snort sees IPLen as 20 and DgmLen as 60 while the firewall (pix) sees it as either Len: 8 or Len: 40. Sometimes, it (the client) will ping one domain controller 4 or 5 times, other times it will ping each once or twice, making it up to 3 or 4 domain controllers. My question is, is there some diagnostic setting that could have been turned on on the controllers? AV software finds nothing, anti-spyware didn't remove the problem. We think that this is what is causing a DoS and bringing down internet access at one of our campuses. It appears to be all clients doing this. However, it hasn't been noticed at our other two campuses. Doesn't mean it hasn't been happening, we just haven't heard about it or seen it yet.
----------------------------
"Will work for bandwidth" - Thinkgeek T-shirt
----------------------------
"Will work for bandwidth" - Thinkgeek T-shirt