la 10-07-2022 03:59 PM
Buna ziua,
Am observat ca ONT-ul, HG8147X6, imi trimite permenent pe toate porturile rj45 (adica toate porturile fizice, mai putin wifi), mesaje de tip broadcast, EtherType ( https://en.wikipedia.org/wiki/EtherType ) necunoscut - 0x8300. Si la voi e la fel?
Extras din mesaje:
13:02:52.427541 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427547 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427548 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427618 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427620 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427621 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427622 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
13:02:52.427623 b8:5f:b0:36:c5:a2 (oui Unknown) > Broadcast, ethertype Unknown (0x8300), length 60:
0x0000: 0000 0000 0001 0000 0000 0000 0000 0000 ................
0x0010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0020: 0000 0000 0000 0000 0000 0000 0000 ..............
Unde 0001, contine 1,2,3,4... in functie de portul lan ar routerului pe care a venit mesajul.
Un set de astfel de mesaje, fara ca setul sa aiba un numar de mesaje fixe, vine o data pe secunda, e aproape un broadcast flood, iar sursa este mac-ul ONT-ului, din LAN.
Singura referinta gasita pe internet pentru EtherType 0x8300 este: https://gist.github.com/riobard/c7eb86aa3586c36ffaa75f7be... , unde un tip din china se plange ca ont-ul ii trimite astfel de mesaje, doar ca lui ii scrie o poezie :)))).
>>>Ma ingrijoreaza aceste mesaje, pentru ca poate fii un protocol obscur/custom de discovery folosit de un malware/backdor pentru a identifica device-urile infectate.<<<
Si la voi este la fel? Aveti idee ce reprezinta? Ati mai intalnit asa ceva? Aveti idee cum il opresc din a mai trimite astfel de mesaje?
Bogdan 🙂
la 10-07-2022 07:43 PM
la 11-07-2022 12:27 AM
la 11-07-2022 12:40 AM
la 11-07-2022 12:48 AM
la 11-07-2022 11:47 AM
la 11-07-2022 11:51 AM
la 22-07-2022 05:35 PM
@Orange Romania S.A. 2024
Cod unic de înregistrare: 9010105
Numar inregistrare Registrul Comertului: J40/10178/1996
Sediul social: Clădirea Tandem, Strada Matei Millo, nr.5, Sector 1, Bucuresti
Certificatul Tip de furnizor