Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
ARP spoofing?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
evoweiss
Veteran
Veteran


Joined: 07 Sep 2003
Posts: 1676
Location: Edinburgh, UK

PostPosted: Sun Aug 14, 2016 8:59 am    Post subject: ARP spoofing? Reply with quote

Hi all,

I recently used arp -a and got some weird results (I forgot to copy them) involving a .ru domain. A reboot and everything is fine again. I have been good about using a passwordless ssh set-up to get into my work computer, disabling the ability to ssh in as root, checking for rootkits, etc.

There are two windows computers (updated, etc.) that are also connected to the home network. Is there a good (and straightforward) way to prevent this from happening in the future?

Best,

Alex
Back to top
View user's profile Send private message
eccerr0r
Watchman
Watchman


Joined: 01 Jul 2004
Posts: 7051
Location: almost Mile High in the USA

PostPosted: Sun Aug 14, 2016 2:41 pm    Post subject: Reply with quote

arp should be local collision domain only. It should be impossible for you to get a .ru domain unless your domain is in .ru and even if you got one somehow, I'm not sure how someone could exploit it as the packets would end up on your home network and get dropped (if you're on a firewalled subnet).

Getting that data you got is probably the only way we can get any suggestions on what you should do, else you're probably at a dead end here. Your machine somehow requested a machine on your network that somehow got a reverse lookup that's in .ru. Is your home network on a private network or is this machine on the public network?
_________________
Intel Core i7 2700K@ 4.1GHz/HD3000 graphics/8GB DDR3/180GB SSD
What am I supposed watching?
Back to top
View user's profile Send private message
krinn
Watchman
Watchman


Joined: 02 May 2003
Posts: 6964

PostPosted: Sun Aug 14, 2016 3:57 pm    Post subject: Reply with quote

You could first limit ssh to your country ip range, people generally don't really change country everyday.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum