Re: A beginner Q: Tracking a hacker

From: Frank Thyes (frank.thyes@consol.de)
Date: 03/07/02


From: Frank Thyes <frank.thyes@consol.de>
Date: Thu, 07 Mar 2002 16:31:59 +0100

Yaacov Fried wrote:
>
> On my Unix Machine (Redhat 7.1), I have noticed (using tcpdump) that someone
> is trying to poke around with a source IP address 172.23.5.228.

What do you mean with poke arround? Where have you seen this
address?

> AFAIK, this address is not routable. Is it a spoofed source address ?
> So, how does he/she get the responses back ?

If it's really a spoofed address he get no response (blind
spoofing)

> Since our LAN has no connection to the outside world, It must be someone
> from inside the LAN, using tcpdump I know the MAC address associated with
> this IP.

Why should someone who is already in the internal network
spoof his own address? The only reason is, if you have a
internal firewall which cuts the user-net from the
accountancy-net or other importend internal networks
(development).

> Is it the MAC address of the nearest router ?

I think so

> Is there any tool that translte MAC to IP (I think 'arp' is useless in this
> case)

arp -a but if you like to translate all addresses do a ping
on the broadcast address first

>
> Thanks
>
> Jacob Fried

Cheers
Frank



Relevant Pages

  • Re: SSH - slowly (or not at all) connects [a little long]
    ... >> The first NIC's are configured for an internal network, ... The internal network is going to be used for clustering. ... both interfaces have the same MAC configured! ... Also, on the other machines, no MAC is repeated in the above 2 config ...
    (comp.os.linux.networking)
  • Re: how do hackers hack?
    ... in this case MAC address can be the issue but a very insignificant ... firewall, antivirus and all necessary ... > hacking within an internal network? ...
    (microsoft.public.security)
  • Re: Mac and remote desktop
    ... I know that there is a Remote Desktop client for Mac, but how does this work through ISA. ... It discusses how to set up the VPN connection from the Mac so you can RDP into various workstations and servers on the internal network. ... If you are needing to publish only one internal workstation, you could configure ISA to forward 3389 to that workstation, but that would impact every external connection. ... Just remember that if you select the VPN option, you're letting whatever malware might be on that remote machine into your internal network. ...
    (microsoft.public.windows.server.sbs)
  • Re: how do hackers hack?
    ... hacking within an internal network? ... >You MAC address gets stripped out on the first router. ... >network scanners for known vulnerabilities. ...
    (microsoft.public.security)

Quantcast