Hi all,

 

I’ve just found the old SQL-slammer again in my customer network and notice something that I’ve never notice before:

 

The worm sends UDP packet using 1 static spoof source IP and 1 static spoof dest IP, but the MAC address changes in every packet (mostly the source mac).  What is happening here??  Have anybody notice this before??

 

Cheers,

 

-A

Reply via email to