Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: IP address assignment problem

Subject: RE: IP address assignment problem
Date: Fri, 25 Aug 2006 12:35:39 -0600

We evaluated this as well and there were only 2 options we found that we
could do:

One was to restrict MAC addresses to the switch port.  Thus any other
machine plugged into that port wouldn't work.

The other was to go to a DHCP by MAC environment, so only authorized MAC
addresses would get IP's.

While it would keep accidental abuse at bay (such as a vendor plugging
into our network), since it's trivial to forge a MAC address a
deliberate attack wouldn't be stopped by either option as an attacker
could unplug a system than take over it's identity with his own machine,
and the security improvement may not be worth the administrative
headache.

-----Original Message-----
From: Davy Davidson [mailto:davy_emp@hotmail.com] 
Sent: August 25, 2006 1:53 AM
To: focus-ms@securityfocus.com
Subject: IP address assignment problem

Hi,
I have a little problem and seek for ur thoughts, let's assume I'm in a
very 
open environment where everyone can very easily try to get his/her
laptop on 
the network and IP addresses are assigned by a DHCP server and we are in
a 
domain environment, how do I prevent machines that are not part of our 
domain to be assigned an IP address?

Thanks

_________________________________________________________________
Don't just search. Find. Check out the new MSN Search! 
http://search.msn.com/


------------------------------------------------------------------------
---
------------------------------------------------------------------------
---



---------------------------------------------------------------------------
---------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>