IP address impersonation



We have a remotely hosted 6.0 server that has apparently been impersonated by a colocated server. The provider allows root access and we have set up our server from a base 6.0 installation. We were allocated an ip address and mostly we have had a good experience with this setup. However, twice in three weeks we have had difficulty in logging in and have had to crash boot the server. Analysis of the logs revealed that another machine on the hoster's network had assigned itself our ip address. Even when we provided the suspect mac address it seemed the hoster had trouble in finding out/appreciating what the problem was.

I have little experience of this sort of thing, but can anyone else offer some advice on

1) is this a recognized form of attack? I can see that it could be used for password harvesting and traffic interception, but are there other implications.

2) Are there ways to mitigate this kind of problem? We have other hosted servers on machines with similar (root) access. They presumably could also be impersonated. We found this out by inspection of our own log files; could the provider be doing something more to prevent this?
--
Robin Becker
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: SSH Attempts: Link to RedHat?
    ... > into his server with root access. ... i'd also check what ports were open on the local machine, ... outdated software run by an inexperienced admin. ...
    (Incidents)
  • Re: [Full-Disclosure] Automated ssh scanning
    ... server however I have a feeling the Kernel was left out of the patching. ... > use a local exploit to gain root access. ... if the admin and other account were ... > setup with strong passwd's and this account was either setup with a ...
    (Full-Disclosure)
  • Re: Restricting Access and Protecting Code
    ... I have written an application in PHP that will be used by telecoms and ISP's. ... It will be installed on a server that will only be running this app. ... As Colin said - you do not have to provide them with root access - nor should you do so! ... Static IP's are generally set up at install time, ...
    (comp.lang.php)
  • Re: Unsecured scripts and site hacking?
    ... As far as root access goes, ... A> is only available locally to the server. ... does the script of Alison fall into this category? ... command and pressing enter) and let the customer reinstall his/her site. ...
    (comp.lang.perl.misc)
  • [Full-Disclosure] Hacking competitions at RootWars.org
    ... Each team will be given root access on a default install of Linux, ... access to my exploit FTP Server. ... target IP addresses, and a username/password for each target IP ... are not allowed to attack other teams in any way. ...
    (Full-Disclosure)