Re: ARP Poisoning



budsz napsal/wrote, On 04/12/08 01:58:
I got movement ARP entry to other MAC ADDR
on the same IP ADDR. Everyone know what happen is? Is that ARP
Poisoning.

Not necessary. It may be misconfigured computer (configured statically to use an address assigned to another computer). Or there may be an unauthorized DHCP server - for example misconfigured Windows with two or more NICs may run one causing the IP conflicts. Yes, it may be intentional attack also.

How to resolve ? You need to found the source of problem and disconnect it. If it is misconfiguration, you may identify the computer via MAC. If it is attack and your LAN is not so large, you may try to disconnect parts of them - when problem disappear you know the segment of the computer you are searching for.

If your LAN isn't small you need to consult your switches from where the attacker MAC come. You can't build reliable large LAN with dumb switches, so I'm sure you have smart switches on your LAN.

But it seems to me your question has nothing to do with FreeBSD with the exception that there is one computer with FreeBSD connected to problematic LAN.


Dan




_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Building to Building wan over fibre?
    ... router, that router box needs to be taught about the second lan. ... given fibre speeds the bottleneck is still the WAN and router, ... switches to go - a wiring closet or server room if you are set up for such ...
    (comp.dcom.wan)
  • Prevent internal LAN intruders
    ... a masqueraded private 10.x.x.x network with unmanaged switches (and ... secure somehow the internal access to the LAN to prevent: ... on the network, access control and data encryption too. ...
    (comp.os.linux.security)
  • Re: LAN failover
    ... detailed documentation besides System's Manager Vol 2, detailing LAN ... I'm plugged into two Cisco different switches, ... In case of failover does LAN failover shouldn't send arp-whois ... broadcast to switches so new ARP address be automatically updated? ...
    (comp.os.vms)
  • Re: Linksys LAN -- network fails at a switch
    ... In article, prg ... I think my switches are more basic than this. ... I can move hosts around on the LAN; they work and no obvious problems. ... If both nics are up, ...
    (comp.os.linux.networking)
  • Re: Help: System keeps coming out of Standby/Hibernate
    ... > But if I Hibernate or Standby it, it switches on automatically after approx ... There are no wake on LAN options set. ... to as "deep sleep" in some setups. ... My suggestion is to dig deeper in the power management documentation for ...
    (microsoft.public.windowsxp.help_and_support)