Net forensics question

From: Burnette, Michael (MWB@rh-law.com)
Date: Fri May 23 2003 - 07:23:47 PDT

  • Next message: stephen_larsonat_private: "linking a word document to a computer"

    What would explain the following scenario (or what if anything would this scenario tell you about the machine in question):
    
    1) A traceroute to a public internet address times out at 30 hops. The last 10 hops bounce between the same two hosts.
    2) No DNS information available on the host.
    3) ping times out unless the TTL is increased.
    4) ping -a returns what appears to be a short netbios name, not a FQDN  
    
    I there any way to know if the IP is static or dynamically assigned?  There seem to be clues here.
    
    Thanks,
    Michael Burnette
    Atlanta, GA
     
    
    
    This message and any attachments are intended for the use of the addressee(s) only and may be confidential and covered by the attorney/client and other privileges. If the reader is not the intended recipient, DO NOT READ, notify sender and delete this message. In addition, be aware that any disclosure, copying, distribution or use of the contents of this message is strictly prohibited.
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon May 26 2003 - 07:25:55 PDT