|
Question : ARP poisoning attack
|
|
i want a tool to prevent ARP poisoning attack in windows XP. i tried to but a static ARP entry but it does not prevent it.
|
Answer : ARP poisoning attack
|
|
The static ARP entry needs to be on the gateway, not on the XP client. The problem here is not that your machine doesn't know how to get to the gateway, but that your packets from the gateway (and any other hosts that are receiving gratuitous ARP packets for resolving your IP) are being redirected to another host.
ARP poisoning attacks can be defended against by using a switch that supports port security.
Setting static ARP entries on all (or at least critical) hosts will help, but is probably not practical in anything beyond a small network. This is not effective on all operating systems, since Windows will accept dynamic ARP updates even if you set static entries.
For Linux and similar OSes, there is arpwatch to monitor unusual ARP traffic, but I don't think there is anything like it for Windows. Even so, arpwatch doesn't defend against ARP attacks, it just lets you know about it.
|
|
|
|