arp broadcast
Hey Guys, I have windows server 2003 DC, IP address 10.0.0.2, 255.0.0.0, 10.0.0.254 gw. For some crazy reason, on Friday it started doing an arp flood, starting with 10.0.0.3 and scanning up through 10.20.5.171, just counting up. Scanned for malware and virus but none found. Replace NIC, loaded updated patches and drivers, changed switch. Cannot make it stop. HELP Please!!!!!
May 18th, 2010 8:05am

Try to use Colasoft Capsa http://www.colasoft.com/download/arp_flood_arp_spoofing_arp_poisoning_attack_solution_with_capsa.php
Free Windows Admin Tool Kit Click here and download it now
May 18th, 2010 10:42am

Hi Barry, Have you ever tried to locate the attack source after monitoring the Network traffics? If the ARP request source is from the router, please consult the Router Manufacturer to check if the configurations are correct. Also we need to check if any new equipment was added to the network environment recently. Thanks, Miles
May 18th, 2010 10:47am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics