The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    How to protect against ARP poisoning?

    Discussion in 'Networking and Wireless' started by nizzy1115, Jan 15, 2009.

  1. nizzy1115

    nizzy1115 Notebook Prophet

    Reputations:
    2,557
    Messages:
    6,682
    Likes Received:
    1
    Trophy Points:
    205
    Since it is so easy to do, say on a corporate scale, how can an admin protect their network from nat poisoning? I know using vlans to segment the network and secure off different areas of the place would help, but what if say joe the accounting intern on the accounting network nat poisoned another computer in there which allowed him to receive information or passwords from another computer on the accounting vlan? I can not see any way to protect this? And also, is the only way to detect it is being done to a specific computer by doing a tracert to that computer, right?
     
  2. nizzy1115

    nizzy1115 Notebook Prophet

    Reputations:
    2,557
    Messages:
    6,682
    Likes Received:
    1
    Trophy Points:
    205
    The one thing i was thinking of is if a script could be written to auto tracert a packet to every host and then compare it against the known good connection path. And if different raise a flag. Is any of this possible on router level without using a script?

    I know there are a few networking guys here ;)
     
  3. nizzy1115

    nizzy1115 Notebook Prophet

    Reputations:
    2,557
    Messages:
    6,682
    Likes Received:
    1
    Trophy Points:
    205
    Someones gotta know...
     
  4. Shyster1

    Shyster1 Notebook Nobel Laureate

    Reputations:
    6,926
    Messages:
    8,178
    Likes Received:
    0
    Trophy Points:
    205
    What's NAT poisoning? Do you mean DNS poisoning or DNS cache poisoning?
     
  5. nizzy1115

    nizzy1115 Notebook Prophet

    Reputations:
    2,557
    Messages:
    6,682
    Likes Received:
    1
    Trophy Points:
    205
    Frick i meant ARP poisoning! I dunno why i said nat lol!
     
  6. Shyster1

    Shyster1 Notebook Nobel Laureate

    Reputations:
    6,926
    Messages:
    8,178
    Likes Received:
    0
    Trophy Points:
    205
    Have you had a look-see at the Wikipedia article on ARP Spoofing?