arp problem

From: Bartłomiej (bartek@pjwstk.edu.pl)
Date: 04/21/02


Date: Sun, 21 Apr 2002 14:45:15 +0200
From: "Bartłomiej" Konarski <bartek@pjwstk.edu.pl>
To: bugtraq@securityfocus.com


Hi,

I have a small problem.
Situation:
We have linux box running kernel 2.4 with 2 NICs.
Let`s assume that
        eth0 IP 10.1.1.1/8 MAC 11:11:11:11:11:11,
        eth1 IP 192.168.0.1/24 MAC 22:22:22:22:22:22

We can even safely set the eth1 interface down, remove a patchcord from
this interface or it can be dummy0 interface.

On the second machine from network 10.0.0.0 (in our case 10.2.2.2) we try:
# arping 192.168.0.1
and we got the reply:
Unicast reply from 192.168.0.1 [11:11:11:11:11:11] 0.765ms

Looks strange - there is no proxy-arp turned on on any of the interfaces.

What can we do with this knowledge ? For example we can try to find
suspected masquerade machines in our network.
It is also very easy to scan for private networks behind the suspected
machines.

We tried this under Linux kernel 2.4
This technique didn`t work with multihomed MS-Windows machine.
It didn`t work on cisco 2500 series either.

The questions are:
How to turn this off ?
Is it only a feature of the kernel series 2.4 ?

-- 
Bartek Konarski
GPG/PGP Key: http://www.bss.pjwstk.edu.pl/bartek.asc




Relevant Pages

  • Google Summer of Code 2009: Student application
    ... at the Linux Foundation we got the application shown below. ... This project sets the goal of partly moving into the kernel (as a FireWire driver with an ALSA interface) what FFADO currently implements in userspace. ...
    (Linux-Kernel)
  • Re: OT] Joerg Schilling flames Linux on his Blog
    ... handling of driver instances is done inside the kernel and used ... and polite authors of such a program would have added support for not only ... fine grained process privilleges into Linux, ... The interface is mostlythere, and as soon as somebody starts ...
    (Linux-Kernel)
  • Re: [RFC, PATCH 0/24] VMI i386 Linux virtualization interface proposal
    ... with respect a common interface for paravirtualization of Linux. ... kernel, but expect our numbers to match previous results, which showed ... Since the hypervisor now depends on the ...
    (Linux-Kernel)
  • Re: Driver Model 2 Proposal - Linux Kernel Performance v Usability
    ... extra interface and will carry a performance hit - I think this is worth it. ... Linux beats every other OS for that. ... >> and then rarely remove support from interface. ... >> and Kernel versions. ...
    (Linux-Kernel)
  • [BUG] panic 2.6.20-rc3 in nf_conntrack
    ... When I shut down my ppp0 interface the kernel ... This kernel had the ipp2p patch from patch-o-matic-ng applied, ... # Firmware Drivers ... # ACPI Support ...
    (Linux-Kernel)