Quantcast
Channel: LowEndTalk
Viewing all articles
Browse latest Browse all 40417

Netbios flood from another VPS on the same network

$
0
0

My KVM VPS is getting flooded with these (thousands every second). I modified the source IP but it's originating from within the provider's network.

0:42:18.750528 IP 123.234.0.22.50138 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.753594 IP 123.234.0.22.50138 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.753650 IP 123.234.1.196.45654 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.756515 IP 123.234.0.22.50139 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.756606 IP 123.234.1.196.45654 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.758707 IP 123.234.0.22.50139 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.760652 IP 123.234.1.196.45654 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.769613 IP 123.234.0.22.50140 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.769926 IP 123.234.0.22.50140 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.769959 IP 123.234.1.196.54411 > 255.255.255.255.138: NBT UDP PACKET(138)

Deeper inspection shows some type of SMBtrans request for a resource called Name=\MAILSLOT\BROWSE

Does anyone know what this is?


Viewing all articles
Browse latest Browse all 40417

Latest Images

Trending Articles



Latest Images