[Dshield] Strange arpwatch reports

Johannes B. Ullrich jullrich at euclidian.com
Fri Oct 29 13:08:22 GMT 2004


> I'm completely stumped as to what is going on here... anyone have any ideas?

could it be that a user on your network set their MAC address to the
router's mac address in order to get copied on any packets sent to the
router?

It is possible that this person 'forgot' to change the MAC back as they
started using the system for regular use. Are the IPs assigned to
anyone?


-- 
Johannes Ullrich                     jullrich at euclidian.com
contact: http://johannes.homepc.org/contact.htm

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://www.dshield.org/pipermail/list/attachments/20041029/261f5b71/attachment.bin


More information about the list mailing list