Trace an attempt
Results 1 to 8 of 8

Thread: Trace an attempt

  1. #1
    Banned
    Join Date
    Jul 2001
    Posts
    8,442

    Trace an attempt

    Is there a way I can track down where an IPX address came from?

    We had someone try to login with my coworkers account, until it locked her out last night. I have the IPX address of the last intrusion and would like to find the pc it came from. Does anyone know of a good way to go about this?

  2. #2
    Registered User silencio's Avatar
    Join Date
    Sep 2000
    Location
    Savannah
    Posts
    3,960
    Isn't part of an IPX address the MAC? Do you run any network management software (openview, insight manager, SMS, or maybe Visio Enterprise) that can query a database for the MAC?
    Deliver me from Swedish furniture!

  3. #3
    Registered User Wayward Clam's Avatar
    Join Date
    Dec 2000
    Location
    the depths of Lake Superior
    Posts
    3,778
    I don't know the answer to your question, but I'd highly recommend doing the following if you haven't already...

    -get your coworker to change not only the password to a highly secure one, but the login/access name s/he was using.

    -have "dummy" account under your coworker's previous login name, with no rights to anything.

    One attempt can mean repeated attempts in the future, one of which may succeed eventually..
    Flash! Don't heckle the supervillain!

  4. #4
    Geezer confus-ed's Avatar
    Join Date
    Jul 1999
    Location
    In front of my PC....
    Posts
    13,087
    Mmmm I don't see that knowing where an attack came from helps ... who are you gonna call the FBI ?

    Securing your network seems a better way to channel your energies....

  5. #5
    Registered User
    Join Date
    Dec 2000
    Location
    Circle Pines,MN,USA
    Posts
    805
    Originally posted by confus-ed
    Mmmm I don't see that knowing where an attack came from helps ... who are you gonna call the FBI ?

    Securing your network seems a better way to channel your energies....
    If he got the IP he could get ISP .. notify the provider.. maybe the police, if he hadn't already spent efforts securing his network he wouldn't have detected someone trying to get in.

    If its internal IP he would know the offender immediately and deal with it then.

    I do not know how cleetus

  6. #6
    Banned
    Join Date
    Jul 2001
    Posts
    8,442
    Powers that be and their infinite wisdom told us to not bother looking into it further. Not my problem if we get broken into, sick and tired of telling them of problems with this place and being ignored.

  7. #7
    Geezer confus-ed's Avatar
    Join Date
    Jul 1999
    Location
    In front of my PC....
    Posts
    13,087

    Arrow If you can't do anything...say something!

    Originally posted by Cleetus
    Powers that be and their infinite wisdom told us to not bother looking into it further. Not my problem if we get broken into, sick and tired of telling them of problems with this place and being ignored.
    Now Cleetus don't take this as an attack, please ... !

    But from where I'm stood you need to inform them of your concerns in writing, I don't know whether this falls into your 'ballpark', that is when/if you have a major security breach it'll be your head on the block.....

    My advice is to write your concerns down (in words laymen understand with your reasoning) & send them to your immediate boss, but also cc it to everybody who might be affected (the more senior the better!) .... 'cos it might affect them ! ... You need to learn the corporate game - lesson one is covering your own arse !

  8. #8
    Banned
    Join Date
    Jul 2001
    Posts
    8,442
    Last time I went "over" my boss with a major concern, we got the job done. AT MY EXPENSE!!!! I am now not getting a raise, nor am I getting any education reimbursment, nor am I getting a x-mas bonus(10% of salary), all because they said by doing this I wasn't a team player.
    I tried to trace where this came from(within the company, believe me, we are pretty damn secure from the outside, at least on the novell side) and they told me to stop. This company has not backed me in anyway, I document everything and can't wait for the IT sector to start turning around to move on. I have turned this place around to where only one COMPETENT tech could easily run it, but that will not happen because it would take a COMPETENT management to actually understand what the heck is going on or to branch our Texas operations completley away from the corporate operations.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •