Re: Any reasons to filter ARP packets?
- From: "Mikhail Zotov" <muxaul@xxxxxxxx>
- Date: 8 Apr 2006 20:49:11 -0700
Ertugrul Soeylemez wrote:
"Mikhail Zotov" <muxaul@xxxxxxxx> (06-04-07 00:58:23):
So getting your MAC address is as simple as sniffing. And we have
seen that it's possible in all cases.
Perhaps, this is even easier. I have disabled "arp" on eth0, and the
log has been empty for some time. Then, records about new connection
attempts appeared. I am not quite sure about output of tcpdump but it
seems information about MAC addresses is provided by the router. Thus,
sniffing is not needed. Just ask the router. ;-)
Yes, as soon as the router gets its hands on your MAC address, it saves
that relation in an internal list. To prevent broadcasting it needs to
know, which MAC address is listening on which of its ports. However,
there is no default way of 'asking' the router. But you can do this
indirectly, which in turn requires sniffing.
Can't this be done in a simpler way? A program sends some SYN packets
to *all* hosts in the LAN, e.g., packets addressed to port 1433
(ms-sql-s) (which appears to be quite common in the LAN). Thus, it
needs to get to know MAC addresses of *all* hosts in the LAN. It seems
it is the router that provides this information since my host doesn't
reply to the requests. This is just a guess but I doubt so many
windoops winnies in the LAN obtain MAC addresses by sniffing the
traffic. (BTW, the ISP seems to be running FC).
Regards,
Mikhail
.
- Follow-Ups:
- Re: Any reasons to filter ARP packets?
- From: Ertugrul Soeylemez
- Re: Any reasons to filter ARP packets?
- References:
- Re: Any reasons to filter ARP packets?
- From: Ertugrul Soeylemez
- Re: Any reasons to filter ARP packets?
- From: Mikhail Zotov
- Re: Any reasons to filter ARP packets?
- From: Ertugrul Soeylemez
- Re: Any reasons to filter ARP packets?
- From: Mikhail Zotov
- Re: Any reasons to filter ARP packets?
- From: Ertugrul Soeylemez
- Re: Any reasons to filter ARP packets?
- From: Mikhail Zotov
- Re: Any reasons to filter ARP packets?
- From: Ertugrul Soeylemez
- Re: Any reasons to filter ARP packets?
- From: Mikhail Zotov
- Re: Any reasons to filter ARP packets?
- From: Ertugrul Soeylemez
- Re: Any reasons to filter ARP packets?
- Prev by Date: Re: https confusion
- Next by Date: Re: how to enable iptables from CLI
- Previous by thread: Re: Any reasons to filter ARP packets?
- Next by thread: Re: Any reasons to filter ARP packets?
- Index(es):
Relevant Pages
|