LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-18-2009, 11:56 PM   #1
anupamsaxena
LQ Newbie
 
Registered: Dec 2008
Posts: 4

Rep: Reputation: 0
Unique ID of machine, other than IP-Addr/MAC-Addr to prevent spoofing


Hi All,

I have some computers along with a server which binds the IP address to machine's MAC address; Idea was to force each machine to use only the assigned IP address to access LAN and Internet.
As it is also possible to change the MAC address of a machine, so one can do the spoofing.
Is there something else, which is unique to every machine and can be used to bind with IP address?

Regards,
Anupam
 
Old 12-19-2009, 12:08 AM   #2
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
a physical port on router, maybe.
 
Old 12-19-2009, 03:16 AM   #3
AutoBot
Member
 
Registered: Mar 2002
Location: I can see you from here.
Distribution: Gentoo 1.3b
Posts: 184

Rep: Reputation: 34
Nmap can do OS fingerprinting to give you an idea of each PC.
 
Old 12-19-2009, 04:56 AM   #4
anupamsaxena
LQ Newbie
 
Registered: Dec 2008
Posts: 4

Original Poster
Rep: Reputation: 0
Nmap can be used to infer the remote machine's OS, it is based on a remote device's responses on specific packets.
I'm not sure about whether this information is 'Unique' for machines.
Can we use nmap to get something like 'BIOS String ID' or 'Hard Drive's unique serial number'?
And is it possible to change these values?
 
Old 12-19-2009, 05:40 AM   #5
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
you know, if you apply such a methods, then you are probably expecting some kind of "hackish" users that may give you headache, and you probably won't solve problem the way you are trying to solve it now.
It would be better if you'd actually provided some more information about what are you really trying to do so people here can advice you something closer to actual problem solution.
 
Old 12-19-2009, 06:34 AM   #6
anupamsaxena
LQ Newbie
 
Registered: Dec 2008
Posts: 4

Original Poster
Rep: Reputation: 0
Setup is like this...
A machine can contact DHCP server to get IP address corresponding to its MAC address.
After geting the IP, it goes to Internet via a gateway; Gateway is suppose to take care of whether this 'IP plus MAC combination' is right or not and then only allow/deny the packets to go outside.

As this binding is based on MAC address, so if a user changes its MAC address then it will be alloted a different IP address (which is been given to another user) OR
It can statically assign a different 'IP plus MAC combination'.

Of course it seems "hackish" ...., but I just want to make it sure that the machines are using only the alloted IP addresses. That is why searching an alternative of MAC-Address.
 
Old 12-19-2009, 04:00 PM   #7
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
i'm sorry, what is the problem to assign clients one MAC address and only allow these mac addresses to contact DHCP? or set up DHCP the way it will only assign corresponding IP to MAC address is in list? and drop all others? If guy has no real reason, he won't be so stupid to try all of possible MAC addresses to brute-force DHCP to assign him IP of other user. Also, all the other users could already be connected so he will never succeed.
 
Old 12-19-2009, 04:39 PM   #8
AutoBot
Member
 
Registered: Mar 2002
Location: I can see you from here.
Distribution: Gentoo 1.3b
Posts: 184

Rep: Reputation: 34
I can easily spoof your MAC address, de associate you and connect as your MAC. Wireless or over LAN.

MAC address safety is a myth

You need to figure out a better method, maybe a radius server.
 
Old 12-20-2009, 10:49 PM   #9
anupamsaxena
LQ Newbie
 
Registered: Dec 2008
Posts: 4

Original Poster
Rep: Reputation: 0
Thanks!
The radius server can solve this problem, now I'm configuring 'FreeRADIUS' software.
 
Old 12-20-2009, 10:58 PM   #10
AutoBot
Member
 
Registered: Mar 2002
Location: I can see you from here.
Distribution: Gentoo 1.3b
Posts: 184

Rep: Reputation: 34
Your welcome.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] how to change MAC addr of PC raju.mopidevi Linux - Networking 4 02-08-2009 11:42 AM
get "Client Mac Addr 00 C0 .... Guid DHCP" on boot before grub, Why? MurX Ubuntu 2 02-23-2008 09:43 AM
Configure DHCP server to assign IP using mac addr mayaLinux Linux - Networking 4 12-07-2005 05:00 PM
Obtain IP addr. from MAC addr? Ryand833 Linux - Wireless Networking 3 06-30-2005 01:59 PM
Change my MAC addr borbjo Linux - Networking 4 09-02-2003 06:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration