LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-17-2010, 07:45 AM   #1
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Rep: Reputation: 47
arp spoofing


is there an easy way to detect which host is running arp spoofing/poisoning?
 
Old 09-17-2010, 07:56 AM   #2
gratuitous_arp
LQ Newbie
 
Registered: Jul 2009
Posts: 28

Rep: Reputation: 17
You're looking for something that does dynamic arp inspection. One such program for Linux is ArpON; you can find others if you google around.
 
Old 09-17-2010, 08:00 AM   #3
sem007
Member
 
Registered: Nov 2006
Distribution: RHEL, CentOS, Debian Lenny, Ubuntu
Posts: 638

Rep: Reputation: 113Reputation: 113
Quote:
Originally Posted by qrange View Post
is there an easy way to detect which host is running arp spoofing/poisoning?
You can use arpwatch

Regards,
 
Old 09-17-2010, 08:21 AM   #4
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
thanks, but that does not help me. I can already see what MAC addresses are spoofed with arp -n
(or better yet arping -d)
what I want to know is which computer is spoofing them.

Last edited by qrange; 09-17-2010 at 08:26 AM.
 
Old 09-20-2010, 02:19 PM   #5
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Contact your networking / switch admin(s)? They should be able to determine which port the MAC address is associated with, which should help determine the offender's physical location.
 
Old 09-21-2010, 01:47 AM   #6
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
hm, but does the spoofed MAC address have to be the same as the computer that is sending fake ARP replies?
my guess not, and that any computer network interface can construct ARP packet as it pleases.
anyway, the admins are rather incompetent and don't believe me.
 
Old 09-21-2010, 11:58 AM   #7
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Can you describe more about your situation? It sounds like you're on a hostile subnet, and are receiving little or no network staff support. (Sometimes a technical solution is not the answer to a meatspace problem.)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
arp poisoning vs arp spoofing sulekha Linux - Networking 1 05-13-2009 04:22 AM
solution to prevent arp spoofing h725 Linux - Security 2 01-22-2009 04:20 PM
arp spoofing- who's vulnerable? abolishtheun Linux - Networking 1 12-26-2008 04:54 AM
need help : iptables problems? arp spoofing romeo_tango Linux - Security 5 03-12-2007 06:43 AM
"Arp spoofing" muppski Linux - Security 9 02-11-2006 04:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration