WUGNET, the Windows User Group Network
Your Complete Resource Center for "The Best" in Shareware, Computing Tips and Support, Windows Industry News... and much more!
Home Forums Shareware Windows Tips Hot Offers FREE Newsletters Arcade Contact Us About Partners
Search WUGNET: RSS Feeds RSS Feeds Advertise with WUGNET    |    Shareware eBooks
HomeHome FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Disable Acceptance of Gratuitous ARPs?

 
   Home -> Windows Other -> Security RSS
Next:  Exclude Specific Computer from My Document Redire..  
Author Message
TekMason

External


Since: Nov 12, 2008
Posts: 1



(Msg. 1) Posted: Wed Nov 12, 2008 7:20 pm
Post subject: Disable Acceptance of Gratuitous ARPs?
Archived from groups: microsoft>public>win2000>security (more info?)

Hi Guys,

I have a relatively simple question that I have not been able to find an
answer to yet.

How can you prevent Windows from accepting gratuitous ARPs and adding them
to it's arp cache table?

This seems like it would be a very simple solution to prevent
man-in-the-middle attacks that use ARP cache poisoning. I am baffled as to
why the bright engineers at MS would make this a default let alone not give
users/admins the ability to disable it. I can't imagine it being that
difficult to implement it in the TCP/IP stack.

The only downsides that I can think of are:
1) Duplicate IP Address detection on PC bootup.
Not an issue because the stack could listen only for it's own MAC and
respond back accordingly.
2) Clustering and HA systems where gratuitous ARP is use to notify clients
of updates to fail-overed hosts.
In this case MS stack engineers could build a mechanism that allows
gratuitous ARP acceptance for specific IPs.

The way that MS handles gratuitous ARP brings this analogy to mind:
Some guy you have never seen before (cracker) knocks at your door (NIC),
unsolicited (gratuitous), and giving you a card with a "new" phone number
(MAC) for the bank. And then you (Windows IP stack) updating your phone
directory with that number.

Thx,
TekMason
Back to top
Login to vote
Display posts from previous:   
       Home -> Windows Other -> Security All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum
Categories:
 Windows XP
 Windows Vista
  Windows Other
 Office
 Office Other
 Security
  • Home |
  • Shareware |
  • Windows Tips |
  • Hot Offers |
  • FREE Newsletters |
  • Arcade |
  • Forums |
  • eBooks |
  • About WUGNET |
  • Partners |
  • Contact

  • WUGNET Privacy Policy |
  • Link to WUGNET |
  • IT Support