Re: how to find hidden host within LAN



By the way, I would also recommend placing an IDS (intrusion detection
system) in a strategic place in your network. They can be implemented
in a manner where they are "hidden" on the network by not using an IP
address, these "shadow boxes" as they are called are very usefull in
finding stuff like this out. Check out snort and their used to be a
decent front end for snort called acid. (not sure if acid is still
around or been renamed or whatever - its been years since I worked
somewhere they would't spring for a Cisco IDS.

-Chuck


On Nov 25, 2007 6:39 AM, desant1@xxxxxx <desant1@xxxxxx> wrote:
Hi everybody
I'm using RH ES4 with iptables as gateway/firewall for my
LAN.
In the last week i notice in the iptables logs that a host within
my lan is doing a lot of traffic.
The destination/source address of the
packets and the used port suggest that this host is using peerToPeer
application (emule or similar).
The problem is that i'm not able to
identify this host within my LAN:
I can see his IP address (192.168.x.
y) and i can find his mac address througth ARP, but i can't ping it and
there is no host within my lan with this Mac address.
I can't
traceroute it.
Can someone help me to find this hidden host?

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list


--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list



Relevant Pages

  • Re: IDS is dead, etc
    ... > wouldn't call 'em an IDS, I think they're something different, much ... the host. ... Ensure Reliable Performance of Mission Critical Applications ... Precisely Define and Implement Network Security and Performance Policies ...
    (Focus-IDS)
  • Re: making Samba work [Solved]
    ... > Microsoft uses 'domain' to describe a lan network topology interchangeably ... You can use in your LAN ... If you internally use the same mechanisms to resolve host names ... No DNS server needed then. ...
    (Fedora)
  • [fw-wiz] Corporate H/N IPS
    ... Two new categories will be Host and Network Intrusion Prevention Systems, ... IDS, they actively block traffic deemed as malicious, almost like a firewall ... previous names for a HIPS have included Network Node IDS ...
    (Firewall-Wizards)
  • Re: Problems with broadcast? with two ethernet adaptors up
    ... > ssh astro.queensu.ca ... It means that anything sent to a host on the old classful "C" network ... hosts on your LAN. ... It defines the LAN hosts' IP address range and hence a LAN network route. ...
    (comp.os.linux.networking)
  • Re: [fw-wiz] How to find hidden host within LAN
    ... I've seen this on our network in recent months also. ... do with virtual machines that default to using 192.168.x.x and ... In the last week i notice in the iptables logs that a host within ... my lan is doing a lot of traffic. ...
    (Firewall-Wizards)