IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Re: I'm stumped on how to find the abuser on my LAN
Do you have physical access to your switches, and are you using switches that have LEDs?
New Both. I could do the unplug dance as a last resort.
Or did you have something else in mind? The LED's don't show meaningful activity rates when you're on a chatty Windows network... ;)
New Re: Both. I could do the unplug dance as a last resort.
Even after working hours? I'd think the guilty port would glow red.
New Not on the FS 750
[link|ftp://downloads.netgear.com/files/netgear1/FS726S750_Manual.pdf|ftp://downloads.netg...26S750_Manual.pdf]

Blinking green/yellow only, and they all blink yellow constantly. :)
New AS Greg would say, easy peasy
With physical access, put a hub in between the PIX and the rest of the network.
Put your ethereal running PC on it at well.
That'll give you all the traffic.
New Gotta remember it has to be a SHARED hub, not switched.
And put the NIC in Promiscuous mode.

I have a machine setup for that.

It has 2 NICs in it. One for connecting to the LAN for regular stuff. Another for plugging into a hub, in listen only promicuous mode.

I bought on of the cheapest 10/100 hubs I could find. I leave daisy chained from the private interface of my Linux firewall.

That is the one thing I wish my unmanaged switches had, a mirroring port. (hmmm, an I idea.)

Basically, you could also use a real firewall, rather than a PIX. I hates them, I do, for reasons you are acutely aware of now.


Redo: Actually, now that I remember I am using a new setup, I actually just use the firewall itself to find the culprits. It is easy, run ethereal on the private interface for internal problems... run it on the public interface for external problems.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey

[link|http://it.slashdot.org/comments.pl?sid=134485&cid=11233230|"Microsoft Security" is an even better oxymoron than "Military Intelligence"]
No matter how much Microsoft supporters whine about how Linux and other operating systems have just as many bugs as their operating systems do, the bottom line is that the serious, gut-wrenching problems happen on Windows, not on Linux, not on Mac OS. -- [link|http://www.eweek.com/article2/0,1759,1622086,00.asp|source]
Expand Edited by folkert April 8, 2005, 11:49:47 AM EDT
New That's the ticket.
Sorry I've been quiet on this--trying different things. I don't have a spare hub lying around, but there's one *outside* the PIX, which shows me everything using Ethereal (which puts my NIC in promisc mode automatically, Greg). I can then map ports with the PIX's PAT log (show xlate) and track down traffic.

Found a LAN client which was sending spam.

But I still haven't found the major culprit. :(

Doing the unplug dance as I can.
     I'm stumped on how to find the abuser on my LAN - (FuManChu) - (12)
         Re: I'm stumped on how to find the abuser on my LAN - (dws) - (6)
             Both. I could do the unplug dance as a last resort. - (FuManChu) - (5)
                 Re: Both. I could do the unplug dance as a last resort. - (dws) - (1)
                     Not on the FS 750 - (FuManChu)
                 AS Greg would say, easy peasy - (broomberg) - (2)
                     Gotta remember it has to be a SHARED hub, not switched. - (folkert)
                     That's the ticket. - (FuManChu)
         if it's like that... - (pwhysall)
         Resolution - (FuManChu) - (3)
             I've had days like that. :-) Glad you got it fixored. -NT - (Another Scott) - (1)
                 Days?? Weeks! -NT - (folkert)
             <font size=8>DANG!</font> - (jb4)

Where the decent people won’t see what you’re up to.
116 ms