Results 1 to 14 of 14

Thread: Rouge PC

  1. #1
    Senior Member Stringent's Avatar
    Join Date
    Jul 2003
    Location
    Neverland
    Posts
    5,227
    Thanks
    45
    Thanked
    155 times in 117 posts
    • Stringent's system
      • Motherboard:
      • Intel DQ57TM
      • CPU:
      • Intel i5 760
      • Memory:
      • 8GB
      • Storage:
      • 1TB
      • Graphics card(s):
      • NVIDIA Geforce 260GTX
      • PSU:
      • Corsair HX620
      • Case:
      • Coolermaster Centurion
      • Operating System:
      • Microsoft Windows 7 Ultimate x64
      • Monitor(s):
      • Dual Iiyama 24"
      • Internet:
      • Patchy

    Rouge PC

    Have found a rouge pc on our network which we can't work out what/where it is. Its picked up a DHCP IP address. Is there any way to narrow it down to which switch its on so we can go um, confiscate it.

  2. #2
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Rouge PC

    if you have a cisco switch then go into the DHCP of your server and get its MAC address, log in to the switch and type sh mac-address-table.

    This will give you all the MAC addresses and tell you what port its on.
    □ΞVΞ□

  3. #3
    TiG
    TiG is offline
    Walk a mile in other peoples shoes...
    Join Date
    Jul 2003
    Location
    Questioning it all
    Posts
    6,213
    Thanks
    43
    Thanked
    47 times in 42 posts

    Re: Rouge PC

    You mean its red/pink in colour?

    Not just cisco switches but pretty much all switches allow that.

    TiG
    -- Hexus Meets Rock! --

  4. #4
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Rouge PC

    I have only ever used Cisco managed switches so I didn't want to assume.
    □ΞVΞ□

  5. #5
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Rouge PC

    If its a red PC - it shoulod be obvious

    How big a network you are talking about? Traceroute? Are the switches managed?
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  6. #6
    Senior Member Stringent's Avatar
    Join Date
    Jul 2003
    Location
    Neverland
    Posts
    5,227
    Thanks
    45
    Thanked
    155 times in 117 posts
    • Stringent's system
      • Motherboard:
      • Intel DQ57TM
      • CPU:
      • Intel i5 760
      • Memory:
      • 8GB
      • Storage:
      • 1TB
      • Graphics card(s):
      • NVIDIA Geforce 260GTX
      • PSU:
      • Corsair HX620
      • Case:
      • Coolermaster Centurion
      • Operating System:
      • Microsoft Windows 7 Ultimate x64
      • Monitor(s):
      • Dual Iiyama 24"
      • Internet:
      • Patchy

    Re: Rouge PC

    Most are managed. its a medium sized network. We have a mix at the moment. Have a Linksys SRW2048 which is where I'll start from, when we get into the switch cabinets elsewhere we have 3COM 4400.

  7. #7
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Rouge PC

    I once had a problem like this and could not find the system. After a few weeks I found out that some one was bringing in their laptop from home, plugging it into the network to get updates.
    □ΞVΞ□

  8. #8
    Senior Member UltraMagnus's Avatar
    Join Date
    Aug 2005
    Posts
    1,025
    Thanks
    24
    Thanked
    7 times in 7 posts

    Re: Rouge PC

    why does it matter? really?

  9. #9
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Rouge PC

    becuase you need to know what is going on at all times. What if this system starting mass mailing due to a security issue and you didn't know where it was located to shut it down and pull it?
    □ΞVΞ□

  10. #10
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Rouge PC

    Quote Originally Posted by UltraMagnus View Post
    why does it matter? really?

    Because that unknown computer represents a major risk to the network security through virus or other malware, either accidentally or deliberately imported. It is also an export path for corporate data (which may or may not be an issue - it depends what other export controls are in place).
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  11. #11
    JagerBomber Mossy's Avatar
    Join Date
    Sep 2006
    Location
    0.0
    Posts
    2,618
    Thanks
    191
    Thanked
    173 times in 144 posts

    Re: Rouge PC

    it would be nice to know hte outcome good luck
    __________________
    Make it idiot proof and someone will make a better idiot.

    Error exists between Keyboard & Chair replace User and press Any Key!

    .... Where's the Any Key???


  12. #12
    Moderator chuckskull's Avatar
    Join Date
    Apr 2006
    Location
    The Frozen North
    Posts
    7,713
    Thanks
    950
    Thanked
    690 times in 463 posts
    • chuckskull's system
      • Motherboard:
      • Gigabyte Z77-D3H
      • CPU:
      • 3570k @ 4.7 - H100i
      • Memory:
      • 32GB XMS3 1600mhz
      • Storage:
      • 256GB Samsung 850 Pro + 3TB Seagate
      • Graphics card(s):
      • EVGA GTX 980Ti Classified
      • PSU:
      • Seasonic M12 700W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • Asus VG278HE
      • Internet:
      • FTTC

    Re: Rouge PC

    I've heard a few stories like this, one ending a room that had been closed up during building work and the PC's never removed.

    One solution I heard was to shut down all the other PC's remotely and go looking for one that was left on, obviously not possible on all networks/machines. If you have any kind of sleep/wake on lan, it should work.

  13. #13
    Senior Member Stringent's Avatar
    Join Date
    Jul 2003
    Location
    Neverland
    Posts
    5,227
    Thanks
    45
    Thanked
    155 times in 117 posts
    • Stringent's system
      • Motherboard:
      • Intel DQ57TM
      • CPU:
      • Intel i5 760
      • Memory:
      • 8GB
      • Storage:
      • 1TB
      • Graphics card(s):
      • NVIDIA Geforce 260GTX
      • PSU:
      • Corsair HX620
      • Case:
      • Coolermaster Centurion
      • Operating System:
      • Microsoft Windows 7 Ultimate x64
      • Monitor(s):
      • Dual Iiyama 24"
      • Internet:
      • Patchy

    Re: Rouge PC

    I'll need to find a laptop with a COM port so I can hook up to the switches. All the new ones don't have one! Also the Web interface on switches are useless for finding out such info.

    Have got the MAC address, and have set a reservation for it so it gets all the wrong IP info. If someone comes running up, I'll soon suss it.

  14. #14
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Rouge PC

    I once found a node and full patch panel that wasn't on the plans. Quite a shock I can tell you.

    can you not telnet to the switches?
    Last edited by Jay; 05-11-2007 at 05:17 PM.
    □ΞVΞ□

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •