Great Circle Associates Firewalls
(April 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Ethernet Address Mfg
From: Sami Yousif <syousif @ iname . com>
Organization: TeddyR Computers
Date: Tue, 14 Apr 1998 20:54:24 -0500
To: "David A. Lane" <dlane @ mantech . com>, firewalls @ greatcircle . com
References: <3 . 0 . 3 . 32 . 19980414123348 . 006a1c00 @ corp-02 . mantech . com>
Reply-to: syousif @ iname . com

David A. Lane wrote:
> 
> Greetings,
> 
> Someone is trying to make a mess of my system and I have managed to catch
> the "MAC" address, but I cannot seem to correlate it to a vendor.  I have
> pulled the IANA Ether Types list, but it does not seem to appear.  Anybody
> have a lead on 00e0.1E9F.16DB?

First thing: Remember that MAC addresses CAN be faked....

According to the database at
http://www.cavebear.com/CaveBear/Ethernet/vendor.html
 
the  "00e01e" prefix is used by Cisco. 

That means that what you are seeing is really from the "other" side of
one of the interfaces on your router and thus  shows up as the address
of the router .

What that would allow you to do is "follow" the router trail...
(tedious, but feasable) 

If the system is a Novell fileserver (based on your .sig), are you
passing IPX through your router? If so, does the other side REALLY need
to see your IPX traffic?  If not, you can safely disable IPX on that
router. If IPX is needed, you will need the cooperation of those in
charge of the "other" segments...

A traffic monitor like NetXray would be useful.

A shareware one called "EtherLoad" may also help.(version 2.00 works
great on an old 80286 laptop w/ a pocket ethernet adapter :-)  [can use
ODI or packet drivers]) 

http://ftp.sunet.se/ftp/pub/network/monitoring/ethload/


 

-- 

---
Sami Yousif

mailto:syousif @
 iname .
 com
mailto:syousif @
 swbell .
 net
http://www.mav.net/teddyr/syousif
http://teddyr.home.ml.org
ftp://teddyr.dyn.ml.org


[eMail sent to any of my addresses is subject to the Conditions outlined
in http://www.mav.net/teddyr/emailtos.shtml]

[Note: I no longer support ARNet (arn.net) as an ISP nor WTAMU
(wtamu.edu) as an educational institution nor LEK (lektech.com) as a
Computer
Supplier] {http://www.mav.net/teddyr/access/banned.shtml}

[heard somewhere: "You have the right to remain clueless. Anything you
know may be used against you in a court of law"]

Another day, so many more LARTS to go. [BOFH, BUFH]



<time is on my side>

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


References:
Indexed By Date Previous: Re: Ethernet Address Mfg
From: trall @ almaden . ibm . com
Next: Re: socks versus fw-1 [Part IIb/II]
From: Frank Willoughby <frankw @ in . net>
Indexed By Thread Previous: Re: Ethernet Address Mfg
From: "Paul D. Robertson" <proberts @ clark . net>
Next: Re: Ethernet Address Mfg
From: trall @ almaden . ibm . com

Google
 
Search Internet Search www.greatcircle.com