Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 12 Oct 2002 22:51:55 -0700
From:      "Alex Pavlovic" <alex.pavlovic@corp-x.com>
To:        "FreeBSD Security" <freebsd-security@FreeBSD.ORG>
Subject:   RE: Kernel log message
Message-ID:  <OIEDKPDGGBLHDIKAKDABAEALCAAA.alex.pavlovic@corp-x.com>
In-Reply-To: <ODEMJJBMDNGMFJHKBCMFGEGHEAAA.ww@austin.rr.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Hi,

There is always a possibility of someone or something performing arp
manipulation in order to redirect the lan traffic. Some common techniques
that come to mind are: MAC spoofing which is efficient against CAM
tables found in switches ( If you are running a switched network )
and ARP spoofing / cache poisoning which might apply to you.
Attacks that can be performed with these range from sniffing to
proxying, MiM, DoS to escaping firewalls. Recently for example certain
data has been published about intreception of ssl traffic
and attack against Microsoft IE certificates.

--
Alex Pavlovic 
Founder and CTO
Corp-X Solutions
http://www.corp-x.com



>  -----Original Message-----
> From: 	owner-freebsd-security@FreeBSD.ORG
> [mailto:owner-freebsd-security@FreeBSD.ORG] 
> Sent:	Saturday, October 12, 2002 5:38 PM
> To:	FreeBSD Security
> Subject:	Kernel log message
> 
> 
> 	Could someone explain to me what the following log message means:
> 
> 	disco.wwallace.net kernel log messages:
> 	> arp: 192.168.100.2 moved from 00:20:78:0d:5a:7f to
> 00:00:78:0d:5a:7f on de0
> 	> Oct  5 08:03:57 disco /kernel: arp: 192.168.100.2 moved from
> 00:20:78:0d:5a:7f to 00:00:78:0d:5a:7f on de0
> 	
> 	The machine in question (192.168.100.2) is a Windows 2000 machine
> that has had the same NIC for years.  Also, only one of the digits in the
> MAC address seems to have changed.  What could cause this?
> 
> 	Thanks,
> 	- William.
> 
> 

[-- Attachment #2 --]
x>"7IPM.Microsoft Mail.Note1

3>
'#&).6pKernel log messageq%oVmEm]0ח
K SMTP:ALEX.PAVLOVIC@CORP-X.COM@:܁|r
mC6r$€	84LZFuP
rcpg1252`n033Och
set0 PxPfprqATahq}
l ;	o05
vIwkd4`cPc HiN,


The  @way!H poibity of spe thgrm
.p u`ti  to 	qi	pc@ ra 
.u m`!hq
P"— qde:мACw
00gqs@CAM#vlu%1 !t( Iy`%R )P)%@twk )p%@ARP%/"?! &Hpgh'pPp *.vA@k $Db.$,!)&!q  R"! oxy,iM60Do =.pp"0	p`lls"`R'q0aA'xamP"d 2p	u`,`@!8a0s !,1'6P@IE9
01 --1(x Pav	c

F)B q-BCTOP->X"q
@#0tp://wGP.ExGmA;P0@36@5#A@0I316BaLzOg@s'eLKJKi-144@@8180@PCb .Fa%bPowr-P	bsd- cq`@Q	BSD.ORG n[ :RS]oCQa`0:Qtp:py60O!@o2p 60K 5:38C0(UQaTUQSQV$Wh;`j!1X7Ke 	MH<NO@K`I\Ql%@9 S$&$a!r8U _)?_QqX0	!o.'GP7e.,Q ko^g@>%1h92.Lp8lP.ZP`v,!4SP::78:0d:5am mamamPrk3YaK`5mPm3n7oh.@i%klmnoH%.k" !#(Ird) W!U  Z!Px$C:%@g!rM"NI%8yg"``8o60 0au!!M t d!%}d	p em1 s"u4dqW$Tc.pu3s?p1-{80mA,QB0<ODEMJJBMDNGMFJHKBCMFGEGHEAAA.ww@austin.rr.com> F F FR'j	 FT9.0
 F6 F7 F8
 F: F< F= FX FY FmC6r$mC6r$8+*VPSTPRX.DLLNITA7nC:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\outlook.pst
478<OIEDKPDGGBLHDIKAKDABAEALCAAA.alex.pavlovic@corp-x.com>=%oeHI,THEREISALWAYSAPOSSIBILITYOFSOMEONEORSOMETHINGPERFORMINGARPMANIPULATIONINORDERTOREDIRECTTHELANTRAF5

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?OIEDKPDGGBLHDIKAKDABAEALCAAA.alex.pavlovic>