Re: rogue IP address

From: Richard Caley (rjc_at_caley.org.uk)
Date: 05/01/03

  • Next message: Burton M. Strauss III: "RE: rogue IP address"
    To: <dondon@pacbell.net>
    Date: 01 May 2003 18:30:05 +0100
    
    

    In article <20030430224002.18480.qmail@www.securityfocus.com>, dondon (d) writes:

    d> Any suggestions on tracing down that system that is associated with the IP
    d> is appreciated!

    Well, to be old fashoned, start a ping, then pull and replace plugs
    until you spot the one which causes the ping to miss a beat. You
    should be able to walk down a tree of hubs/switches like that in less
    time than working out a smarter plan.

    Great big signs at all staff toilets threatening mayhem to whoever it
    is if they don't own up within the week.

    If it's a fairly out-of-the-box linux instalation it may be running
    sendmail, which may give you a way to contact the person responsible
    if they read mail sent to root.

    Perhaps you can block that IP at some firewall or router, then wait to
    see who calls support to say their network connection has died.

    If you can sniff packets, perhaps you can spot what they are doing, if
    so that may give a clue who they are, or at least a clue as to
    services they are using. From there you could, for instance, tell a
    file server they are using to reject connections from that IP and
    again wait for them to complain.

    The fun story-to-tell-in-the-pub way would be to find out what sort of
    linux it is, find a recent security report and crack the
    machine. Probably not worth the effort, but nice to think about when
    pulling plugs and planning the mayhem to apply when you find them.

    -- 
    Mail me as MYFIRSTNAME@MYLASTNAME.org.uk        _O_
                                                     |<
    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most 
    recognized corporate security certification track, provides a comprehensive 
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization 
    of pertinent security tools. For a limited time you can enter for a chance 
    to win one of the latest technological innovations, the SEGWAY HT. 
    Log onto http://www.securityfocus.com/FastTrain-security-basics 
    ----------------------------------------------------------------------------
    

  • Next message: Burton M. Strauss III: "RE: rogue IP address"

    Relevant Pages

    • Re: Ctrl H
      ... I am a PHD physics student, I solved and solve many hard problems ... the clue in my first post. ... Security mode = Safe mode, trivial for any who boot and press F8 ... all the time?, Please, dont post messages based on personal ...
      (microsoft.public.windowsxp.general)
    • Re: [Full-Disclosure] Feeding Stray Cats
      ... Let's face it...this list is a mixed bag - some with clue, ... Speaking of responsibility, in a security related vein, those caring about ... the signal to noise ratio of the list who would like to flame me anyway ... may flame me live and in person. ...
      (Full-Disclosure)
    • Re: [fw-wiz] SCADA
      ... I don't expect this system is secure even with two different firewalls and an AV software product installed. ... We can write a lot on the Firewall Wizards list about the woes of mixing today's connected business needs with yesterdays isolation is a form of security. ... As I have read this thread, and a variety of otherrs over the years, I keep coming to the conclusion that many seem to miss the point that "those who have a clue" are ignored, or their chants/rants about how to secure systems like SCADA are missed or ignored. ... Similair point to broader corporate network security, do not let insecure protocols pass the perimiter. ...
      (Firewall-Wizards)
    • Re: Comodo Personal Firewall
      ... because they don't have a clue what's going ... Why are you showing popups then? ... Application Recognition Database ... determine their security risks. ...
      (comp.security.firewalls)
    • RE: p2p and ISA
      ... allow the user to install the application. ... > recognized corporate security certification track, ... This ALL INCLUSIVE curriculum utilizes lectures, ... For a limited time you can enter ...
      (Focus-Microsoft)