User Tools

Site Tools


networking:dhcp_find_rogue

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
networking:dhcp_find_rogue [2018/07/20 12:33]
gcooper
networking:dhcp_find_rogue [2018/07/20 12:46] (current)
gcooper
Line 33: Line 33:
   - **Filter** on ''bootp.option.dhcp == 2'' packets   - **Filter** on ''bootp.option.dhcp == 2'' packets
     * Shows DHCP Offer packets     * Shows DHCP Offer packets
-  -  
  
 +===== Track It Down =====
 +
 +From a CMD prompt, you can check for:
 +
 +  * Reverse DNS info
 +  * Find the MAC address
 +  * Check for NETBIOS name
 +
 +<file>
 +nslookup <IP of rogue DHCP server>
 +</file>
 +
 +<file>
 +ping <IP of rogue DHCP server>
 +arp -a
 +</file>
 +
 +<file>
 +nbtstat -A <IP of rogue DHCP server>
 +</file>
 +
 +Knowing the manufacturer of the rogue device might help, once you know the MAC address.  Try a lookup here:
 +
 +https://macvendors.com/
 +
 +Finally, use '**Divide and Conquer**' to find the culprit.
networking/dhcp_find_rogue.1532111628.txt.gz · Last modified: 2018/07/20 12:33 by gcooper