I don't know what kind of logs you are looking at, but my snort logs also seemed very strange to me recently. It appeared that strange things were coming from IPs that are near our IP range. The reason for this was MSBlaster and Nachi worm activity, though at first instance I also thought that someone was spoofing an IP address on some subnet (it is relatively easy to spoof an IP in you subnet as promiscious mode ethernet cards will pick up every packet). So basically what I am trying to say is that strange logs don't neccessarilly come from spoofed IPs -- worms and viruses are more often to blame.
Posts are HTML formatted. Put <p> </p> tags around your paragraphs. Put <code> </code> tags around your code and data!
Read Where should I post X? if you're not absolutely sure you're posting in the right place.
Please read these before you post! —
Posts may use any of the Perl Monks Approved HTML tags:
Outside of code tags, you may need to use entities for some characters:
- a, abbr, b, big, blockquote, br, caption, center, col, colgroup, dd, del, div, dl, dt, em, font, h1, h2, h3, h4, h5, h6, hr, i, ins, li, ol, p, pre, readmore, small, span, spoiler, strike, strong, sub, sup, table, tbody, td, tfoot, th, thead, tr, tt, u, ul, wbr
Link using PerlMonks shortcuts! What shortcuts can I use for linking?
See Writeup Formatting Tips and other pages linked from there for more info.
| & || & |
| < || < |
| > || > |
| [ || [ |
| ] || ] ||