[CLUE-Tech] Finding rogue IPs.

Dave Price davep at kinaole.org
Tue Nov 26 10:26:15 MST 2002


On Tue, Nov 26, 2002 at 09:28:21AM -0700, David Anselmi wrote:
> Jim Ockers wrote:
> [...]
> 
> > A destructive (disruptive) test is one way to do this.  Start by 
> > identifying which hub it's plugged into:
> 
> 
> The hubs (3com) have a console port on the back, but they require a 
> management module to be "managed".  I'll have to plug in and see if the 
> port does anything without it.  I've always wondered what you could do 
> with a managed hub, have to spend some time and see.

If it is like most, you will be able to use SNMP to access data on
individual ports:

Traffic - Switch On and Off, etc ...

I liked the idea that was floated about filtering internet traffic at
your firewall to shut off the bad guy - see who squacks, and squack
back.

aloha,
dave




More information about the clue-tech mailing list