Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Finding rouge dhcp server

Status
Not open for further replies.

Mturner

IS-IT--Management
Jan 15, 2001
288
GB
Hi all

i think we may have another dhcp server sitting on our network at some point during the day, probally a member of staff bringing in a laptop with ics enabled or something simular, is there tools avalible which can search for dhcp servers and give its netbios name or anything like that?

tia

Marc
 
I don't know of any specific tools, but have you tried performing a port scan on your subnet to look for machines that have the following ports opened?

DHCP Lease UDP:67,68
DHCP Manager TCP:135

 
That may a good start, thanks for that ill give it a try monday
 
I've known people who have used SNORT to detect these kinds of things. I had forgotten about SNORT, until you asked this question. I might have to look into it again myself.


MikeL
 
What makes you think you have a rouge server?

Glen A. Johnson
"Fall seven times, stand up eight."
Proverb

Want to get great answers to your Tek-Tips questions? Have a look at FAQ219-2884
 
Use network monitor to scan for dhcp packets. Why do you think there's a rogue dhcp?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top