Link to home
Start Free TrialLog in
Avatar of ebouza
ebouza

asked on

Rouge System

This might sound like a simple question but I am kind of new to the security side of networking.  How am I able to find a rouge system on my network?  I ran GFI's Langaurd and it came back with the IP address it is using and also says it is probably a Unix box.  It is running Samba 2.2.3a(build26).  But when I look for it in active directory users and computers it does not show up.  The Unix box has three open ports 139,110,25.  I can ping it but can't trace it down.  Any suggestions are exteremly invited.


Thank you,
Erick
Avatar of cfairley
cfairley
Flag of United States of America image

Erick,

I would not show up in AD because it does not have a Domain account.  I would try the following:
nslookup "ip address"

This should give you the DNS name for the box.  Also, search for the IP address in DHCP and/or WINS to get the name for the box.

Just some suggestions, I'm not a security expert either.

Thanks,
ASKER CERTIFIED SOLUTION
Avatar of dlwyatt82
dlwyatt82
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial