This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Could someone explain me this arp poisoning?

0

Hey guys, I have this .pcap file (download: https://goo.gl/1zqoGN) and I am a little confused. The capture file shows an arp poisoning attack, but my question is: why is the ip address 192.168.0.2 sending all these arp requests (packets 45 to 298)? Could someone explain? Thanks in advance.

asked 17 Jul '15, 08:59

shad0w125's gravatar image

shad0w125
6224
accept rate: 0%

edited 17 Jul '15, 09:03


One Answer:

0

The capture file shows an arp poisoning attack,

I don't think so. Looks more like a network sweep (IP scan via nmap or similar tools). If you want to scan all nodes in the local network you first need to know the MAC address of all possible addresses.

The only strange thing is that the system first seems to have IP address 192.168.0.2 (see the gap in the ARP request) and the it changes its IP address to 192.168.0.3. I have no good explanation for that, but this does not look like an ARP poisioning attack.

Regards
Kurt

answered 17 Jul '15, 10:46

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Well, this is indeed a arp poisoning attack, I got it from a hacking forum to analyse it. By the way, I thought it was a kind of sweep but I was just wondering why it was there. Thanks.

(17 Jul '15, 13:18) shad0w125