Solved

Rouge System

Posted on 2004-08-11
5
204 Views
Last Modified: 2013-12-04
This might sound like a simple question but I am kind of new to the security side of networking.  How am I able to find a rouge system on my network?  I ran GFI's Langaurd and it came back with the IP address it is using and also says it is probably a Unix box.  It is running Samba 2.2.3a(build26).  But when I look for it in active directory users and computers it does not show up.  The Unix box has three open ports 139,110,25.  I can ping it but can't trace it down.  Any suggestions are exteremly invited.


Thank you,
Erick
0
Comment
Question by:ebouza
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 11

Expert Comment

by:cfairley
ID: 11774773
Erick,

I would not show up in AD because it does not have a Domain account.  I would try the following:
nslookup "ip address"

This should give you the DNS name for the box.  Also, search for the IP address in DHCP and/or WINS to get the name for the box.

Just some suggestions, I'm not a security expert either.

Thanks,
0
 
LVL 14

Accepted Solution

by:
dlwyatt82 earned 250 total points
ID: 11775861
If you already have the machine's IP addres, but don't know where to physically find it, I hope you have a managed switch :)
The LanGuard software you mentioned may have also given you the MAC address of the rogue system. If it didn't, you can obtain this information through windows by:

Going to a Windows PC on the same subnet as the rogue system
Pinging the rogue system's IP address.
Run "arp -a" from a command prompt to get the MAC address.

Once you have that, log onto your managed switch for that vlan / subnet, and find out which port the rogue system is plugged into. Once you know which port the culprit is using, you can walk straight to the PC and find out what's going on (assuming you have well-documented cable runs between your patch panel and wall jacks). You also have the option of just unplugging the rogue system's network cable from the switch if you are worried about security and you are sure it is NOT supposed to be on your network.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Is this error real? 2 56
Security Permissions Issues 10 81
Changing Passwords for  Windows and Linux servers  in bulk 7 78
Scan Mac for security breach? 5 82
Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question