Re: Question on identifying cable-modem activity

Re: Question on identifying cable-modem activity

NewsGroups | Search | Tools
 comp.dcom.modems.cable  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Re: Question on identifying cable-modem activity Todd H. 12-13-2007
Posted by Peter Pearson on December 16, 2007, 2:14 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>
> http://www.askapache.com/security/sniffing-on-ethernet-undetected.html
>
>
> This is probably overkill for your situation, and the cable modem
> isn't going to care if it sees some packets from your machine, but if
> you're interested in being as certain as possible you aren't changing
> anything, this would be the way to go.

Thank you for helpfully goading me out of procrastination
mode. For the benefit of other lost souls wandering these
parts, this sequence of commands seemed to make my Linux box
disinclined to transmit:

sudo ifconfig eth1 down
sudo ifconfig eth1 hw ether 00:00:00:00:00:00 promisc
sudo ifconfig eth1 0.0.0.0
sudo ifconfig eth1 -arp up

and this sequence of commands restored normal network access:

sudo ifconfig eth1 down
sudo ifconfig eth1 hw ether 00:15:F2:3D:9D:C9 -promisc
sudo ifconfig eth1 arp
sudo ifconfig eth1 192.168.1.99 (restore normal IP address)
sudo route add default gw 192.168.1.1 (restore normal gateway route)

As for the fun part, the data, five minutes of sniffing caught
3431 messages, about 3100 of which were like this:

Cisco_e4:4f:5d Broadcast ARP Who has 68.189.121.12? Tell 68.189.121.1
Cisco_e4:4f:5d Broadcast ARP Who has 68.185.88.154? Tell 68.185.88.1
Cisco_e4:4f:5d Broadcast ARP Who has 68.185.93.107? Tell 68.185.88.1

So clifto's prediction of ARP traffic was exactly right.

There were also several dozen messages between Vonage sites
and my telephone adapter. Logical.

Inevitably, traces of mischief: two ping requests from 122.25.177.46,
= p2046-ipad201aobadori.miyagi.ocn.ne.jp

--
To email me, substitute nowhere->spamcop, invalid->net.

Similar ThreadsPosted
Re: Question on identifying cable-modem activity December 13, 2007, 3:45 pm
Re: How Sticky Are CableModem AUPs? August 29, 2006, 5:58 pm
Re: How Sticky Are CableModem AUPs? August 29, 2006, 10:18 pm
Re: How Sticky Are CableModem AUPs? September 7, 2006, 4:11 am
Re: How Sticky Are CableModem AUPs? September 20, 2006, 5:37 pm
Cable Modem Activity August 9, 2007, 10:47 pm
Constant activity on router / cable modem - ARP??? December 23, 2005, 1:07 am
Technical Question ??? June 23, 2005, 7:07 am
SB5100 Question June 24, 2005, 5:17 pm
Rca cable question August 4, 2005, 4:52 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map