RE: Attacking our pc router at work





-----Original Message-----
From: owner-freebsd-questions@xxxxxxxxxxx
[mailto:owner-freebsd-questions@xxxxxxxxxxx]On Behalf Of Mark Jayson
Alvarez
Sent: Wednesday, April 05, 2006 2:04 AM
To: freebsd-questions@xxxxxxxxxxx
Subject: Attacking our pc router at work


Hi,

I have one question. What if I change my ip and mac address at
the same time to that of our pcrouter's ip and mac... Will this
going to kick out that router in our network, causing the rest
of the entire lan to be out of service??

Yes.

No one's gonna caught
me right??

That depends.

Arpwatch can only watch if an ip address has moved
to another mac address but not when both ip and mac has moved
to another ip and mac... Do you know any possible solution to this??


Yes, buy good managed switches and install mac-level filters. People
that run dumb hubs or unmanaged
switches in a large network are effin idiots in my book.

In a small network, like 20 or fewer stations, a savvy admin who
has encountered this trick before (ie: someone who has worked
college networks since there's always a few smart guys in the
fresman dorms who try this every year) can simply start pulling
out patch connections from the main hub or switch until the problem
goes away.

Typically corporate nets don't have these kinds of problems since
not many people want to risk getting fired.

Ted
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Freebsd 5.1 <-> Win XP Networking problems
    ... Danny MacMillan wrote: ... >> from any ip number forming part of that network and from the netmask. ... > located external to my network it should send the packet to the router ... > (using the router's MAC address) instead of arp-ing for the MAC address ...
    (freebsd-questions)
  • Re: Ethernet network wiring ?s
    ... >>> the planned network is designed correctly and for my own education on ... Since you already have a router, ... Apple calls this protocol Bonjour. ... And because Mac 1 and Mac 2 have private network addresses, ...
    (comp.sys.mac.hardware.misc)
  • Re: re-setting router--MORE QUESTIONS...SIGH
    ... Unless your connection device is also a router, ... A MAC address is the ... "permanent" address that is 'burned' into any network device when it is ... enable some kind of wireless security. ...
    (alt.sys.pc-clone.dell)
  • RE: Exploit code for IP Smart Spoofing
    ... The idea Smartspoof is definitely not new. ... I use arp-sk or any other method of providing the router with my MAC ... Current switches ...
    (Bugtraq)
  • Re: Network Connections Dropping
    ... my local DNS in addition to my router as a DNS for getting to my ISP, ... defined hostname and what is their assigned hostname. ... IP address that my Mac now had and vice versa. ... the mac users seem to lose partial network connection. ...
    (comp.sys.mac.system)