Constant arping!

  • Thread starter Thread starter Colin
  • Start date Start date
C

Colin

Hi,
I have a LAN with 6 PCs, a mixture of Win2K Pro and Win NT4 machines. The
LAN address is 192.168.0.x

Looking at the LAN activity with a sniffer, I see that the NT4 machines seem
to be constantly arping for addresses of non-existant machines.

Can anyone explain what they are doing?
Thanks
Colin
 
are they scanning whole address ranges?? if so it could be msblast or
welchia worm.
 
Hi,
They are scanning over the subnet of my LAN, 192.168.0.x but not in
sequential order. Conspicuously it is the NT4 machines that are doing it and
not the Win 2k machines.

I have an up to date virus checker, nothing has been reported.

How can I check specifically for the worms you mention?

Thanks
Colin
 
Back
Top