MManjra Posted September 8, 2006 Posted September 8, 2006 I am having a problem which is driving me crazy. there is someone at the school here who has a static IP assigned to their device which is conflicting with our server. Is there any easy way of finding out where this device is. or any way of stopping this from happening. i have posted a message in staff briefing about this. and tried going round the whole school trying to find out who it is but have not had any luck as yet. Someone Help Me Please...
Geoff Posted September 8, 2006 Posted September 8, 2006 Find out it's arp address. Once you have that you can look up the first few octets and you can find the make (and possibly model) of the network card in the device. That should help narrow things down.
CyberNerd Posted September 8, 2006 Posted September 8, 2006 When the problem occurs, briefly unplug the server and ping or nmap the rogue machine to obtain its mac - and any other info - you might be able to smb straight into the C: drive and get some useful info. also, once you know the mac address you can ask your switches (provided they are managed switches) which port on the switch is using that address.
acb_ Posted September 8, 2006 Posted September 8, 2006 When we wanted to locate a machine whose IP we know, but whose location we didn't, we executed a script on it remotely which sounded the internal speaker (Ctrl G) at frequent intervals, the idea being that we'd be contacted by whoever was nearest to it reporting a problem with it. In the end, no one got in touch; they didn't need to, the machine was sat just outside our office, on our workbench :oops:
PiqueABoo Posted September 9, 2006 Posted September 9, 2006 Mmm.. using ARP to convert IP addresses to NIC vendors via MAC addresses can be useful. I rolled my own CL util for Windows, but IIRC one of the GUI arp spoofers does it (WinArpspoof?) and there are a couple for linux et al. Don't know whether it's got the latter, but if you don't already a nix box this is the kind of scenario where the Slackware-based "BackTrack" live CD should help. Edit: Changed "Auditor" to new name "BackTrack" (http://www.remote-exploit.org).
ITWombat Posted September 9, 2006 Posted September 9, 2006 Just focus on the people who know what an IP address is. In these days of DHCP not many people concern themselves with such geekery. Also block internet access from the IP. That will flush out them out
ChrisH Posted September 9, 2006 Posted September 9, 2006 Also block internet access from the IP. That will flush out them out Thats a great idea apart from if the server needed it.
tickmike Posted September 9, 2006 Posted September 9, 2006 Hi. And welcome. I was playing about with this http://www.mikrotik.com/thedude.php I have only a small network which includes two Static address's on it and it picked them up ok, give it a try its free !. Regards Michael.
MManjra Posted September 10, 2006 Author Posted September 10, 2006 Thanks alot for the replys. in the end i just disconnected the server and started off the ping -t command, then started unpluggin the switches one by one followed port by port and found out it was a Staff Laptop. I will try the other solutions as well just so that if does happen again i wont be running round like a lunatic from one block to another in the feaar that the laptop does not get disconnected before i get there, because that nearly did happen.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now