Firewall found Mac Spoofing? now comp won't take IP

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Firewall found Mac Spoofing? now comp won't take IP

Post by Sava700 »

Ok here is the problem... I came home to find Ole ladies computer which is run from ICS on mine It runs WinXP Home not connecting to the internet.. I check a few things and found a Mac Spoofing Security thing on my Sygate firewall I put on it. I look over to my computer which is the HOST running 2000Prof's monitor is not showing anything its pretty much in standby mode and the computer still running however. I restarted the HOST comp with no problems ran a full virus scan and a few other scans to find nothing different or any problems. I go back to her computer to see that the "ipconfig" is showing some weird 169.353.255.255 in place of the assigned IP but it should be like 198.164.0.1 as the ICS from the HOST is telling what it should get. So as of now I have no connection at her comp cause it won't renew the IP as if the connection is dead. I'm running SYgate firewall on the HOst computer also but nothing of spoofing here or anything strange on the securty logs either. I see no strange applications running of any sort on either computers either. So a few questions: one is how do I get her computer to renew the darn IP that I want it to have another is what the hell is the Mac Spoofing and why did it seem to cause issues between both computers?
User avatar
greEd
Posts: 807
Joined: Wed May 09, 2001 12:00 am
Location: Maryland

Post by greEd »

Typically MAC spoofing only occurs on the LAN so I wouldnt worry too much about it being a remote attack. In its simplest form an attacker poses as the host (in your case the win2k system) and says all information coming from clients (in your case the XP system) will instead go the attacker ... the attacker will then pass the information along to your win2k system all while watching every packet that moves to/from your LAN.

The IP currently assigned ( 169.353.255.255 ) on the XP system is a default ip the system will assign the nic if it doesnt have a static IP assigned to it or cannot obtain an IP from a DHCP server (in this case your win2k host). Did you recently install Sygate on the win2k system?
"I'm doing a (free) operating system (just a hobby, won't be big and professional...) for AT clones... It's not portable and it probably [won't ever] support anything other than AT hard disks, as thats all I have :-(." --Posted on Usenet August 1991 by Linus Trovalds
http://www.computerglitch.net
curiosity builds security | dd if=/dev/zero of=/dev/hda bs=512 count=100
EOF
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Post by Sava700 »

no sygate has been on both computers for a few months. I reckon the ICS has crashed so I need to reset it again. I'll try to redo it and get the connection back up. I think I just need to go ahead and get a darn router and forget about the ICS lol but everything goes through my sygate so it enables me to watch traffic on other computer just in case. Have found she likes to download bad files :nope:
Blessmac
New Member
Posts: 2
Joined: Tue Dec 07, 2010 3:42 am

Post by Blessmac »

You can try to ProteMac NetMine. It is very good soft to monitor user activity .
FunnyLui
New Member
Posts: 1
Joined: Fri Dec 17, 2010 7:29 am

Post by FunnyLui »

• Just tried ProteMac NetMine on my work's computer... Nice... it protects mycomputer from unwanted intrusions without any problems just installed it today and it works fine. ( protemac.com/netmine/ )
Post Reply