LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
查看: 821|回复: 2

[求助]过路高人帮帮啊……

[复制链接]
发表于 2007-2-1 09:02:26 | 显示全部楼层 |阅读模式
arp who-has 192.168.0.27 tell 192.168.0.2
arp who-has 192.168.0.27 tell 192.168.0.2
arp who-has 192.168.0.28 tell 192.168.0.2
arp who-has 192.168.0.28 tell 192.168.0.2
arp who-has 192.168.0.29 tell 192.168.0.2
arp who-has 192.168.0.29 tell 192.168.0.2
arp who-has 192.168.0.30 tell 192.168.0.2
arp who-has 192.168.0.30 tell 192.168.0.2
arp who-has 192.168.0.31 tell 192.168.0.2
arp who-has 192.168.0.31 tell 192.168.0.2
arp who-has 192.168.0.32 tell 192.168.0.2
arp who-has 192.168.0.32 tell 192.168.0.2
arp who-has 192.168.0.33 tell 192.168.0.2
arp who-has 192.168.0.33 tell 192.168.0.2
arp who-has 192.168.0.34 tell 192.168.0.2
arp who-has 192.168.0.34 tell 192.168.0.2
arp who-has 192.168.0.35 tell 192.168.0.2
arp who-has 192.168.0.35 tell 192.168.0.2
arp who-has 192.168.0.36 tell 192.168.0.2
arp who-has 192.168.0.36 tell 192.168.0.2
arp who-has 192.168.0.37 tell 192.168.0.2
arp who-has 192.168.0.37 tell 192.168.0.2
arp who-has 192.168.0.38 tell 192.168.0.2
arp who-has 192.168.0.38 tell 192.168.0.2
arp who-has 192.168.0.39 tell 192.168.0.2
arp who-has 192.168.0.39 tell 192.168.0.2
arp who-has 192.168.0.40 tell 192.168.0.2
arp who-has 192.168.0.40 tell 192.168.0.2
arp who-has 192.168.0.41 tell 192.168.0.2
arp who-has 192.168.0.41 tell 192.168.0.2
arp who-has 192.168.0.42 tell 192.168.0.2
arp who-has 192.168.0.42 tell 192.168.0.2
arp who-has 192.168.0.43 tell 192.168.0.2
arp who-has 192.168.0.43 tell 192.168.0.2
arp who-has 192.168.0.44 tell 192.168.0.2
arp who-has 192.168.0.44 tell 192.168.0.2
arp who-has 192.168.0.45 tell 192.168.0.2
arp who-has 192.168.0.45 tell 192.168.0.2
arp who-has 192.168.0.46 tell 192.168.0.2
arp who-has 192.168.0.46 tell 192.168.0.2
arp who-has 192.168.0.47 tell 192.168.0.2
arp who-has 192.168.0.47 tell 192.168.0.2
arp who-has 192.168.0.48 tell 192.168.0.2
arp who-has 192.168.0.48 tell 192.168.0.2
arp who-has 192.168.0.49 tell 192.168.0.2
arp who-has 192.168.0.49 tell 192.168.0.2
arp who-has 192.168.0.50 tell 192.168.0.2
arp who-has 192.168.0.50 tell 192.168.0.2
arp who-has 192.168.0.51 tell 192.168.0.2
arp who-has 192.168.0.51 tell 192.168.0.2
arp who-has 192.168.0.52 tell 192.168.0.2
arp who-has 192.168.0.52 tell 192.168.0.2
arp who-has 192.168.0.53 tell 192.168.0.2
arp who-has 192.168.0.53 tell 192.168.0.2
arp who-has 192.168.0.54 tell 192.168.0.2
arp who-has 192.168.0.54 tell 192.168.0.2
arp who-has 192.168.0.55 tell 192.168.0.2
arp who-has 192.168.0.55 tell 192.168.0.2
arp who-has 192.168.0.56 tell 192.168.0.2
arp who-has 192.168.0.56 tell 192.168.0.2
arp who-has 192.168.0.57 tell 192.168.0.2
arp who-has 192.168.0.57 tell 192.168.0.2
arp who-has 192.168.0.58 tell 192.168.0.2
arp who-has 192.168.0.58 tell 192.168.0.2
arp who-has 192.168.0.59 tell 192.168.0.2
arp who-has 192.168.0.59 tell 192.168.0.2
arp who-has 192.168.0.60 tell 192.168.0.2
arp who-has 192.168.0.60 tell 192.168.0.2
arp who-has 192.168.0.61 tell 192.168.0.2
arp who-has 192.168.0.61 tell 192.168.0.2

以上是在单位接外网的主机获取的……隔一段时间整个局域网就瘫痪了,解决办法只有把交换机重启……
我想问下大家,是不是那个192.168.0.2的机器有问题?
我们的主机是Debian系统……
那192.168.0.2是老板新买来的笔记本……XP系统的……这几天工作太忙了,一直没过去处理……

希望大家给个处理办法……
是不是应该在192.168.0.2上查毒?
如果只在接外网的linux机器上有什么处理办法?(接外网的主机IP是192.168.0.1)

希望大家帮忙!谢谢!
发表于 2007-2-1 09:41:01 | 显示全部楼层
你要多监听一会,看看who has以后有没有别的信息(比如0.2这台机器告诉别人网关的mac地址)
未必是192.168.0.2有问题,但是它的嫌疑最大
因为别人可能伪造这样的arp请求嫁祸给它,
回复 支持 反对

使用道具 举报

 楼主| 发表于 2007-2-1 12:28:27 | 显示全部楼层
有时这样:

09:46:05.505297 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.505308 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.513115 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.513124 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.522039 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.522048 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.534603 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.534612 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.543395 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5
09:46:05.543404 arp reply 192.168.0.241 is-at 00:0a:e4:c6:ac:c5

我看过了192.168.0.2 的MAC就是00:0a:e4:c6:ac:c5

老板的机器刚买来几天,系统是奸商过来装的……

现在老板的机器上有N多的病毒……网线已经被我拔了,我想知道除了在老板的机器上查毒或者重新安装系统以外,还有什么办法可以解决?
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表