RE: rogue IP address

From: Anthony (anthony2_at_xs4all.nl)
Date: 05/04/03

  • Next message: Pierre BETOUIN: "Re: ARP Poisoning"
    To: <dondon@pacbell.net>, <security-basics@securityfocus.com>
    Date: Sun, 4 May 2003 21:09:47 +0200
    
    

    Perhaps you can tryout the following,

    1. NTOP (Get more details on what the specific host is doing
    2. Use simple nmap to get more details and perhaps use Nessus to
    disable/scan the host.

    Anthony

    -----Oorspronkelijk bericht-----
    Van: dondon@pacbell.net [mailto:dondon@pacbell.net]
    Verzonden: donderdag 1 mei 2003 0:40
    Aan: security-basics@securityfocus.com
    Onderwerp: rogue IP address

    Someone on our network assigned an IP address to their own system without
    my knowledge. Using LANguard network scanner, the best I can tell is that
    it's a Linux box. The port-to-IP mapping table on our Asante switch
    doesn't see to work correctly.

    Any suggestions on tracing down that system that is associated with the IP
    is appreciated!

    Andy

    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-security-basics
    ----------------------------------------------------------------------------


  • Next message: Pierre BETOUIN: "Re: ARP Poisoning"

    Relevant Pages

    • Re: NMAP Switches, -sS, -sT, etc.
      ... using NMAP to conduct "intensive/comprehensive" security testing. ... Host is down: ... Concerned about Web Application Security? ...
      (Pen-Test)
    • RE: block internet at two workstations
      ... The removal of a default gateway or DNS entry from the ... host itself would also work but if these people know anything about ... >prospectus based upon the core principle concepts of security. ... >INCLUSIVE curriculum utilizes lectures, ...
      (Security-Basics)
    • Different Outputs using different Portscanners...
      ... Superscan in windows ... enabled, but nmap didnt.. ... prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
      (Security-Basics)
    • Re: Different Outputs using different Portscanners...
      ... You also have to realise that nmap does not scan every port neither does ... Superscan unless you tell it too. ... > prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
      (Security-Basics)
    • Re: unknown ip protocol
      ... Below are IP protocol numbers and nmap man for protocol scan. ... which protocol are in use for a targeted host with -sO option. ... Even if a TOE security function cannot be bypassed, deactivated, or corrupted, it may still be possible to defeat it because there is a vulnerability in the concept of its underlying security mechanisms. ...
      (Focus-IDS)