LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-14-2002, 01:53 AM   #1
saravanan1979
Member
 
Registered: Jan 2002
Posts: 163

Rep: Reputation: 30
eth0 is enabled in promiscous mode


Hello
My ethernet card has been enabled in promiscous mode by an hacker how can i turn it off and bring it to the normal mode.
Regards
Saravanan
 
Old 06-14-2002, 12:13 PM   #2
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
what's the card?
 
Old 06-15-2002, 12:13 AM   #3
saravanan1979
Member
 
Registered: Jan 2002
Posts: 163

Original Poster
Rep: Reputation: 30
Ethernet card maeans my network card
 
Old 06-15-2002, 03:28 AM   #4
DMR
Member
 
Registered: Jun 2001
Location: Fairfax, California
Distribution: RH 9.0, RH 7.3, Mandrake 8.0
Posts: 986

Rep: Reputation: 30
Quote:
Originally posted by saravanan1979
Ethernet card maeans my network card
What David meant, I believe, is: what is the make and model of your card. The way one enables/disables promisc. mode can depend on the chipset of the card.

What makes you so sure that a hacker did this in the first place?
 
Old 06-15-2002, 03:38 AM   #5
saravanan1979
Member
 
Registered: Jan 2002
Posts: 163

Original Poster
Rep: Reputation: 30
Model of my card is Reasltek rtl8139.My system has been hacked for the past 1 week and my ISP has confirmed this,and there has been a login id with root access created in /etc/passwd file.
 
Old 06-15-2002, 07:37 AM   #6
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
It looks like the rx mode is set by the driver, have you rebuilt the module? is it using a module? if not then you may need to rebuild the kernel
 
Old 06-15-2002, 07:50 AM   #7
saravanan1979
Member
 
Registered: Jan 2002
Posts: 163

Original Poster
Rep: Reputation: 30
yes it is using it as a module no probs it can recogonise the network card.The only problem was another module eth0:0 was running in the machine it had a global IP and a Diffrent subnet mast so when i use ifconfig i could see

Lo
eth0
eth0:0
Known i used ifconfig eth0:0 <ip> subnetmask<> down and resdtarted my network.Know etherner card started in normal mode!!!!!!!!!!!!!
 
Old 06-15-2002, 07:51 AM   #8
saravanan1979
Member
 
Registered: Jan 2002
Posts: 163

Original Poster
Rep: Reputation: 30
By the way can u tell me how to reduild the kernel,eager to know
 
Old 06-15-2002, 08:01 AM   #9
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
yea looks like a virtual lan was setup on it.

there are some kernel howto's that explain how to build a kernel in detail
 
Old 06-15-2002, 08:24 AM   #10
MasterC
LQ Guru
 
Registered: Mar 2002
Location: Salt Lake City, UT - USA
Distribution: Gentoo ; LFS ; Kubuntu ; CentOS ; Raspbian
Posts: 12,613

Rep: Reputation: 69
Sweet, you got hacked! I invite people to hack me. In fact if I had a static IP I would post it here so people could hack me. I don't exactly have anything on my computer that they would really want anyway. Just some good ol Videos and a few songs, no bank account crap or anything good. Besides, I figure I can hopefully figure out how they'd do it, and apply it. Like the VLAN on your system, I want to allow my buddy who lives about 3 miles away to be able to "connect" to my PC. I figure if a hacker can do it, why can't my buddy? And things like that.

Cool

<edit>
Right here is an excellent example of a kernel how to. I copied it from a search I did. That link is curteousy of PBHarris.
</edit>

Last edited by MasterC; 06-15-2002 at 08:29 AM.
 
Old 06-15-2002, 08:50 AM   #11
saravanan1979
Member
 
Registered: Jan 2002
Posts: 163

Original Poster
Rep: Reputation: 30
Actually My setup was such that we had a Router connected in a network in which the Linux machine was and any request coming on port 80 was redirected to the Linux machine via router.So please can u tell me what this virtual LAN is,i have heard of virtual network but what is this virtual Lan??any tutorials regarding this..
 
Old 06-15-2002, 09:01 AM   #12
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
basically it will allow one card to act as two, in the sense that it would have two ip addresses and may occupy two networks. It is mostly used when you want to restrict certain machines access to certain resources and allow others to access other resources, with only one nic.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Eth0 : Promiscuous mode enabled singhrishi Linux - Software 1 10-10-2003 01:24 PM
Eth0 : Promiscuous mode enabled singhrishi Linux - Hardware 1 10-10-2003 01:24 PM
Eth0 : Promiscuous mode enabled singhrishi Linux - Networking 0 10-10-2003 07:10 AM
Eth0 : Promiscuous mode enabled singhrishi Linux - Software 0 10-10-2003 04:23 AM
Network card in Promiscous mode thetwin Linux - Security 2 07-29-2003 07:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration