Bonjour à tous,
mon problème est en fait de determiner si un avec serveur windows 2003 de type contrôleur de domaine principal ce genre de chose est normal :
Code :
- 2 0.049963 172.16.0.x ARP Who has 172.16.89.138? Tell 172.16.0.x
- 4 0.112496 172.16.0.x ARP Who has 172.16.89.139? Tell 172.16.0.x
- 5 0.175174 172.16.0.x ARP Who has 172.16.89.140? Tell 172.16.0.x
- 6 0.237460 172.16.0.x ARP Who has 172.16.89.141? Tell 172.16.0.x
- 7 0.299968 172.16.0.x ARP Who has 172.16.89.142? Tell 172.16.0.x
- 8 0.362467 172.16.0.x ARP Who has 172.16.89.143? Tell 172.16.0.x
- 9 0.424971 172.16.0.x ARP Who has 172.16.89.144? Tell 172.16.0.x
- 10 0.487429 172.16.0.x ARP Who has 172.16.89.145? Tell 172.16.0.x
- 11 0.503030 172.16.0.x ARP Who has 172.16.3.255? Tell 172.16.0.x
- 12 0.550057 172.16.0.x ARP Who has 172.16.89.146? Tell 172.16.0.x
- 15 0.612705 172.16.0.x ARP Who has 172.16.89.147? Tell 172.16.0.x
- 17 0.674953 172.16.0.x ARP Who has 172.16.89.148? Tell 172.16.0.x
- 19 0.721787 172.16.0.x ARP Who has 172.16.2.180? Tell 172.16.0.x
- 20 0.737455 172.16.0.x ARP Who has 172.16.89.149? Tell 172.16.0.x
- 22 0.799959 172.16.0.x ARP Who has 172.16.89.150? Tell 172.16.0.x
- 23 0.862467 172.16.0.x ARP Who has 172.16.89.151? Tell 172.16.0.x
- 24 0.924937 172.16.0.x ARP Who has 172.16.89.152? Tell 172.16.0.x
- 25 0.987472 172.16.0.x ARP Who has 172.16.89.153? Tell 172.16.0.x
- 26 1.050119 172.16.0.x ARP Who has 172.16.89.154? Tell 172.16.0.x
- 27 1.112515 172.16.0.x ARP Who has 172.16.89.155? Tell 172.16.0.x
- 29 1.174992 172.16.0.x ARP Who has 172.16.89.156? Tell 172.16.0.x
- 30 1.237458 172.16.0.x ARP Who has 172.16.89.157? Tell 172.16.0.x
- 31 1.299976 172.16.0.x ARP Who has 172.16.89.158? Tell 172.16.0.x
- 36 1.362452 172.16.0.x ARP Who has 172.16.89.159? Tell 172.16.0.x
- 37 1.424968 172.16.0.x ARP Who has 172.16.89.160? Tell 172.16.0.x
- 38 1.487663 172.16.0.x ARP Who has 172.16.89.161? Tell 172.16.0.x
- 41 1.549977 172.16.0.x ARP Who has 172.16.89.162? Tell 172.16.0.x
- 43 1.612474 172.16.0.x ARP Who has 172.16.89.163? Tell 172.16.0.x
- 45 1.674948 172.16.0.x ARP Who has 172.16.89.164? Tell 172.16.0.x
- 48 1.737454 172.16.0.x ARP Who has 172.16.89.165? Tell 172.16.0.x
- 49 1.743675 172.16.0.x ARP Who has 172.16.2.243? Tell 172.16.0.x
- 50 1.799965 172.16.0.x ARP Who has 172.16.89.166? Tell 172.16.0.x
- 51 1.862468 172.16.0.x ARP Who has 172.16.89.167? Tell 172.16.0.x
- 53 1.925250 172.16.0.x ARP Who has 172.16.89.168? Tell 172.16.0.x
- 55 1.987480 172.16.0.x ARP Who has 172.16.89.169? Tell 172.16.0.x
- 56 2.003322 172.16.0.x ARP Who has 172.16.1.195? Tell 172.16.0.x
- 57 2.034642 172.16.0.x ARP Who has 172.16.1.241? Tell 172.16.0.x
- 58 2.049980 172.16.0.x ARP Who has 172.16.89.170? Tell 172.16.0.x
- 59 2.112540 172.16.0.x ARP Who has 172.16.89.171? Tell 172.16.0.x
- ...
|
x etant bien enttendu le même nombre à chaque fois, 172.16.0.x etant l'ip du controleur de domaine principal et que ces requettes se font le long de la journée tout les jours.
peut-etre que ca va vous paraitre stupide mais je nais pas asser d'experience pour etre sur de ce que c'est, j'ai bien sur enttendu parlé du flood/scan mais on m'a aussi vagement parlé d'un recensement éffectué par les controleur de domaines...donc je préfere demander à des gens qui savent mieux que moi. sachant que ces requêtes arp inonde le reseau, il me semble bizarre que ca soit voulut .
merci d'avance de vos réponses.
Message édité par gg2laba le 04-05-2006 à 08:25:46