Bogus routes to host

David Mitchell davem at
Wed Mar 1 18:33:10 UTC 2000

John Drummond <bind at> wrote:

> I think someone is polluting the DNS system.  I keep getting all these
> packets from real hosts, too -- but they're all stamped with the same 
> ethernet address. . .  I've already written CERT once.  

The ethernet address is a red herring - all the packets you see will contain
the ethernet address of the local router which forwarded the packet
onto the LAN your were running the sniffer on.

