VWVortex


+ Reply to Thread
Results 1 to 21 of 21

Thread: Odd network activity

  1. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-05-2012 04:31 PM #1
    My wife just got a message that another computer on our network was using the static IP of her MacBook Pro, X.X.X.7.

    When I run a tracert to any of our other network devices (ap, server, phones on wifi, etc) the tracert only goes to the device and stays in our network.

    But when I run a tracert to .7 it leaves out network and goes through about 20+ hops.

    It's looking like this computer has been compromised somehow...

    Our wifi is WPA2 with a string key- 10 character hey with upper/lower case, numbers and punctuation, no complete words in the key. But I'm not convinced that it's an intrusion through Wifi.

    I'm not really familiar enough with the processes that in on a MBP to easily ID and thing out of the ordinary and nothing besides dashboard was using a high amount of either CPU or RAM.

    Only 5 addresses are open for DHCP (.90 - .95) for our phones, iPad, nook and my work laptop.

    EDIT: As a precaution I have disabled DHCP and put all our mobile devices on static IPs. I've also logged the MAC addresses for all our devices, unfortunately the stupid ActionTec router for FiOS is such a stupid PITA to use.
    Last edited by Hostile; 08-06-2012 at 10:26 AM.

  2. Member
    Join Date
    Feb 11th, 2009
    Location
    Lewiston, Maine
    Posts
    4,063
    Vehicles
    2001 Wolfsburg Jetta
    08-05-2012 05:03 PM #2
    try running ifconfig and see if another computer is running on your network with that ip address
    Quote Originally Posted by winstonsmith84 View Post
    Tax? I don't mind paying state sales tax. Every time a see a pothole, a school that is falling down or a canceled essential state program, I remind myself why.
    Quote Originally Posted by Tornado2dr View Post
    535 members of congress plus 1 pres screwing us all the time...that's dirty pirate hooker level gang rape.

  3. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-05-2012 05:48 PM #3
    I downloaded a network scanner and it's showing the MAC address that is using .7 (wife's laptop's ip) is our Airport Extreme...

    Now I'm perplexed since the IP of the Airport Extreme is .2. Everything else on WiFi is showing it's own MAC, not the AP's MAC.

    EDIT- I power cycled the airport extreme and turned the MBP back on- now the correct MAC is showing for .7...
    Last edited by Hostile; 08-05-2012 at 05:57 PM.

  4. Member
    Join Date
    Feb 11th, 2009
    Location
    Lewiston, Maine
    Posts
    4,063
    Vehicles
    2001 Wolfsburg Jetta
    08-05-2012 05:58 PM #4
    Something is running DHCP and assigned a network address in use already. You should be running DHCP and using mac address filtering, if you can. That would keep any unwanted intruders out of your network.
    Quote Originally Posted by winstonsmith84 View Post
    Tax? I don't mind paying state sales tax. Every time a see a pothole, a school that is falling down or a canceled essential state program, I remind myself why.
    Quote Originally Posted by Tornado2dr View Post
    535 members of congress plus 1 pres screwing us all the time...that's dirty pirate hooker level gang rape.

  5. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-05-2012 06:26 PM #5
    Quote Originally Posted by Egilbe View Post
    Something is running DHCP and assigned a network address in use already. You should be running DHCP and using mac address filtering, if you can. That would keep any unwanted intruders out of your network.
    That doesn't make sense- only two devices on my network are capable of running a DHCP server, my router and my ap. The router was limited to a DHCP range of 90-95 and the AP is set to bridge mode so DHCP is disabled.

  6. Member
    Join Date
    Feb 11th, 2009
    Location
    Lewiston, Maine
    Posts
    4,063
    Vehicles
    2001 Wolfsburg Jetta
    08-05-2012 07:20 PM #6
    Quote Originally Posted by Hostile View Post
    That doesn't make sense- only two devices on my network are capable of running a DHCP server, my router and my ap. The router was limited to a DHCP range of 90-95 and the AP is set to bridge mode so DHCP is disabled.
    Weird.
    Quote Originally Posted by winstonsmith84 View Post
    Tax? I don't mind paying state sales tax. Every time a see a pothole, a school that is falling down or a canceled essential state program, I remind myself why.
    Quote Originally Posted by Tornado2dr View Post
    535 members of congress plus 1 pres screwing us all the time...that's dirty pirate hooker level gang rape.

  7. Geriatric Member ATL_Av8r's Avatar
    Join Date
    Oct 17th, 2002
    Location
    Gapiana
    Posts
    37,954
    08-05-2012 08:42 PM #7
    Are you running any VM software? BootCamp, VMWare, Parallels, VirtualBox?
    MemeGate 2012 - First Responder, post #2

    Quote Originally Posted by .skully.
    Mike, quote me in your signature

  8. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-05-2012 09:38 PM #8
    Quote Originally Posted by ATL_Av8r View Post
    Are you running any VM software? BootCamp, VMWare, Parallels, VirtualBox?
    Nope.

  9. Moderator Flyin18T's Avatar
    Join Date
    Jan 10th, 2001
    Location
    Long Island
    Posts
    2,785
    08-06-2012 08:48 AM #9
    Change all of your clients from dynamic to static IP address. As someone already mentioned configure MAC filtering in the router. (only allow the mac id's you input) Sometimes when you boot up a machine that is dynamic you'll see a message pop up like that. Not to worry. For peace of mind just configure as I mentioned. You'll never see that message again.

    Sent from my HTC_Amaze_4G using Tapatalk 2
    2012 MKVI Jetta GLI / 2008 Civic Si Sedan / 2007 Mazdaspeed 6 / 2004 MKIV Jetta GLI (1.8T) / 1996 MKIII Jetta GLX VR6

    https://twitter.com/Flyin18T

  10. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-06-2012 10:25 AM #10
    As I mentioned in my first post the conflicting IP that popped up was not in my DHCP range (DHCP range was .90-.95 and the conflicting IP was .7) and the only devices set to use DHCP addresses were our iphones and our ipad- our wireless devices.

    All other devices are hard wired (computers, gaming consoles, etc) and had static IPs. I moved the iphones/ipad to static IP as a first step and disabled DHCP on my router.

    Regardless none of this really addresses why a tracert to one of my internal NAT addresses was leaving my network.
    Last edited by Hostile; 08-06-2012 at 10:27 AM.


  11. Senior Member SAPJetta's Avatar
    Join Date
    Feb 3rd, 2001
    Location
    East Bay, CA
    Posts
    26,490
    Vehicles
    2008 Rabbit S(low), 2012 Outback 2.5 Premium
    08-08-2012 10:40 AM #12
    Where are we going and why am I in this handbasket?

    XBL - urparanoid

  12. 08-17-2012 09:54 AM #13
    You could ping the IP address and then check your arp table for its mac address. From the mac address you can determine the manufacturer of the NIC card. That could give you indication if it is one of your devices.

    If you're concerned, change your WPA2 passphrase and enable MAC filter on your wireless AP. It is not a bad idea to have list of the MAC addresses of all your devices.

    What subnet are you using for your internal network? Is it one of the non-routeable private addresses?

  13. Member azunderg's Avatar
    Join Date
    Apr 29th, 2009
    Location
    85006 | Garfield District
    Posts
    1,184
    Vehicles
    MK5 GTI|Fixie|Light Rail
    08-17-2012 12:35 PM #14
    Quote Originally Posted by SpiffyGTI View Post
    Phoenix DMZ
    The Ghetto
    New South | Neuspeed | ECS | Optima

  14. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-17-2012 04:04 PM #15
    ****, it's happening again. Same IP too, 192.168.1.7.

    I fired up a network scanner I had downloaded last time and there are no errant MAC addresses.

    One thing that doesn't make a lot of sense, my FiOS router (192.168.1.1, all IPs are hard-coded to 192.168.1.X) shows a MAC address of 00:1F:90:22:A5:65 on the router's status page but the network scanner IDs it as 00:1F:90:CB:5A:E9.

    The 00:1F:90 portion of the MAC identifies it as an Actiontec Electronics product, but I'm puzzled why the MAC addresses aren't matching up.

    WiFi is disabled on the actiontec router, all devices ultimately go through this to get out to the internet. I also have an Apple AirPort Extreme that I only use for WiFi, it's in bridge mode so it is not doing any routing.
    Last edited by Hostile; 08-17-2012 at 04:29 PM.

  15. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-17-2012 04:31 PM #16
    I just re-ran the scan and now the MAC for .7 is showing as the MAC address from my AirPort which is coded to .2.

    So there are two IPs (.2 and .7) showing the same MAC.

    I refreshed it again and it's back to the MacBook Pro's MAC address.

    When the scanner was showing the AirPort's MAC on .7 the Host Name field in the scanner was blank. When it switched back to the MBP's MAC it updated to who the correct host name, I7-MBP.

    So either something is up with my AirPort extreme or this scanner is flaky. I'm using SoftPerfect Network Scanner.

    EDIT: Here is a network diagram:


    Internet comes into a wiring cabinet in our garage, network drops in rooms connect directly to the switch ports in the FiOS router. The WiFi radio in this router is disabled, a DHCP range of .100-.150 is enabled for the FiOS cable box (lame).

    At my desk the AirPort Extreme is connected directly into the wall plate (connected through the walls directly to a port on the FiOS router). The AirPort handles WiFi and my desktop and server are wired into the switch ports.

    In the living room a switch is connected directly to a wall plate (connected through the walls directly to a port on the FiOS router). The TV, PS3, Xbox and WD TV are all wired into that switch.

    The two iPhones, iPad and MBP all connect to the AP in the AirPort with WPA2.
    Last edited by Hostile; 08-17-2012 at 05:03 PM.

  16. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-17-2012 05:08 PM #17
    Here is a screen cap of the network scanner reporting that the MAC from the AirPort extreme is taking over .7

    Last edited by Hostile; 08-17-2012 at 05:19 PM.

  17. Member Avus's Avatar
    Join Date
    Sep 20th, 2000
    Location
    Toronto
    Posts
    7,429
    Vehicles
    1993 Celica GTS, 2007 S2000
    08-17-2012 05:46 PM #18
    can you configure another device (example: another notebook or cell phone) to use 192.168.1.7? at least you can see if this problem is from your mac book or network...

    or you configure the macbook to use another IP address (example:192.168.1.99) to see if the problem is following the macbook.
    Last edited by Avus; 08-17-2012 at 05:49 PM.
    Windows Vista (32bit only)/7/8 "God Mode"
    - Create new folder on desktop
    - rename folder to the following:
    GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}

  18. Senior Member Hostile's Avatar
    Join Date
    May 29th, 2002
    Location
    NOVA
    Posts
    27,159
    Vehicles
    a subaru and a vw
    08-17-2012 06:02 PM #19
    I can try that. This problem initially popped up almost 2 weeks ago and only re-appeared today- it doesn't appear to easy to reproduce.
    Quote Originally Posted by Swallow Doretti View Post
    I'm going to go out on a limb here and say I've sucked on more ballsacks than you have.

  19. Senior Member SAPJetta's Avatar
    Join Date
    Feb 3rd, 2001
    Location
    East Bay, CA
    Posts
    26,490
    Vehicles
    2008 Rabbit S(low), 2012 Outback 2.5 Premium
    08-17-2012 06:26 PM #20
    Solar flares....
    Where are we going and why am I in this handbasket?

    XBL - urparanoid

  20. Member azunderg's Avatar
    Join Date
    Apr 29th, 2009
    Location
    85006 | Garfield District
    Posts
    1,184
    Vehicles
    MK5 GTI|Fixie|Light Rail
    08-20-2012 10:52 PM #21
    Quote Originally Posted by SAPJetta View Post
    Solar flares....
    Phoenix DMZ
    The Ghetto
    New South | Neuspeed | ECS | Optima

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts