mac address issue

From: Brian Whitehead (brian_at_whiteheadconsulting.com)
Date: 09/02/03

  • Next message: kelvin tong: "Advise on Security audit tool"
    Date: Tue, 2 Sep 2003 11:19:16 -0500 (CDT)
    To: security-basics@securityfocus.com
    
    

    I was wondering if anyone could point me in the right direction. Lately
    we have been having problems with IP duplication. Looking at the arp
    cache and dhcp logs it looks like either a mac address spoofing issue or
    maybe just a hardware problem. I'm seeing two different mac addresses
    that appear to take over 20-30 different IP's all at one time causing an
    IP conflict and then they are immediately released. I haven't been able
    to find these mac addresses on any device in the building. The switches
    don't seem to agree either. One port on the core switch may have it in
    it's arp cache, but the switch plugged into that port doesn't. Nothing is
    making a lot of sense. This has happened once or twice a day for the last
    4-5 days. If anyone has an idea of what to look at I would appreciate it.

    -- 
    Brian
    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
    October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
    technical IT security event.  Modeled after the famous Black Hat event in 
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
    Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: kelvin tong: "Advise on Security audit tool"

    Relevant Pages

    • RE: gratuitous arp and bad mac
      ... Are you implementing any Layer 2 Switch Fault Tolerance? ... public network only but also NOT recommened in a cluster. ... > I looked at the arp table and found that the mac address for ... > sql-a was now matching the mac for node2. ...
      (microsoft.public.windows.server.clustering)
    • Re: gratuitous arp and bad mac
      ... Teamed NICs are to seperate switches, but the team is in a failover ... so the 2nd switch should be out of the picture. ... >> I looked at the arp table and found that the mac address for ... >> sql-a was now matching the mac for node2. ...
      (microsoft.public.windows.server.clustering)
    • RE: Windows 2000 Static arp not static
      ... The switch still sees the offending machine as having the correct ... MAC address and the victim as having the correct MAC address. ... One that detects these ARP flip-flops. ... unless you meant static arp entries. ...
      (Focus-Microsoft)
    • Re: Sending "magic packets" from OBSD router seems to fail
      ... > through the switch, not the OBSD box. ... > wakeonlan seems to hit the internal ethernet device (attached to the ... the ARP table does not have any entry for this IP. ... its own MAC address. ...
      (comp.unix.bsd.openbsd.misc)
    • Re: How to find MAC addresses on network?
      ... things don't respond to arping. ... The MAC addresses of the devices you connected ... stays in the ARP cache of your computer for some time. ...
      (Ubuntu)