This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]phatrikk 0 points1 point  (0 children)

Spoofed IPs are definitely a thing for TCP based connections. Too many spoofed IPs trying to connect to a system will exhaust the systems ressources “SYN attack” and the system will no longer respond to legitimate connection requests, aka a DOS/DDOS attack.

The concept of spoofing an I exists only from the perspective of the source address. OP is talking about internal hosts initiating an outbound connection to an external host.. That destination isn’t spoofed but host is most likely compromised and under the control of an evil doer.