Re: Strange logon attempts



"Matt" <matthewsatkins@xxxxxxxxx> writes:
I have recently taken over a network. I started to audit failed logon
attempts and am finding a particular computer trying to log on as my
desktop tech once or twice a day. The attempts are coming from a
computer name that I do not recognize. When this first started
happening, I couldn't find a reference for this computer anywhere in my
network. Just yesterday, I found that it was given an IP address lease
a few days ago. What can I do to find where this PC is??

Depends on your network topology.

Take that IP address, get to the subnet it's on via tracert, get to a
machine on that network, arp for that IP to get the mac address,
access the switch for that lan (hopefully it's a managed one) and find
out what port of the switch has the mac address associated with that
ip, find out what cable's plugged into that port, then track that down
a physical machine.

Now, if it's a wirelessly connected machine, then your job becomes
more interesting.

--
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • RE: Exploit code for IP Smart Spoofing
    ... If there is a MAC violation, this is logged and the port is ... traffic of one other host on the switch. ... but there is no way to protect against ...
    (Bugtraq)
  • RE: How to find a changing IP on ethernet network
    ... called "port security". ... tell it how many MAC ... to issue an SMTP trap to your Network Management ...
    (Security-Basics)
  • Re: Snort/ACID only collecting info for itself, not network
    ... A proper network switch keeps all traffic not destined for you ... > your port. ... Which makes me reiterate an original concern: When I click "portscan ...
    (comp.os.linux.misc)
  • Re: Networking over mains cables
    ... blocking just about every port except the basic ones needed to ... without blocking him completely it was useable. ... When entering a network key, ... allow the MAC addresses of the machines I know about. ...
    (comp.sys.acorn.networking)
  • possible arpspoofing
    ... about midnight the network behaves really strange. ... i went there and accessed the switch via ethernet ... the port with the mac-adresse, ... disconnectings, reconnnectings. ...
    (comp.security.misc)