Hi all,
My company has two DHCP Servers (Domain Controllers). One fine day, noticed that all of the wireless clients could not login (authenticate). After investigation, noticed that
the wireless LAN DHCP scope has run out.
e.g.
I did a reconciliation and noticed a lot of "inconsistencies" on DHCP Server A.
IP ADDRESS NAME UNIQUE ID
172.6.20.31 172.6.20.31 3130efc011033248873000
172.6.20.32 172.6.20.31 3130efc011033248871233100
172.6.20.33 172.6.20.31 3130efc0110332488712393200
172.6.20.34 172.6.20.31 3130efc0110332488712393300
172.6.20.35 172.6.20.31 3130efc0110332488712393400
I did a verify and the above entries shown up. I clicked on verify and subsequently went to address leases, did a refresh and can see these invalid entries. The name is the same as the IP addresses.
All the reminder DHCP IP entries are occupied by this long entries of 26 characters long.
Now I see inconsistencies in another DHCP Server. From time to time, I need to go in to delete this invalid entries.
Other DHCP scopes in both DHCP Server are experiencing this same symptoms.
Anyone experienced this before?
What I did:-
1. Booted both Servers in SAFE mode and performed full updated AV def scans // Results: No viruses found
2. Compact DHCP database on DHCP SERVER A, but still experienced same thing
Inconsistencies on the DHCP Servers is still around.
Anyone experienced this before?
This looks like a kind of DHCP attacks, else could be something keep on writing into registry, but could not be detected and when DHCP databases conpared against the registry entries, the records are thus updated into the DHCP database automatically becos' of comparison between DHCP Server and registries.
Rgds,
libroos
My company has two DHCP Servers (Domain Controllers). One fine day, noticed that all of the wireless clients could not login (authenticate). After investigation, noticed that
the wireless LAN DHCP scope has run out.
e.g.
I did a reconciliation and noticed a lot of "inconsistencies" on DHCP Server A.
IP ADDRESS NAME UNIQUE ID
172.6.20.31 172.6.20.31 3130efc011033248873000
172.6.20.32 172.6.20.31 3130efc011033248871233100
172.6.20.33 172.6.20.31 3130efc0110332488712393200
172.6.20.34 172.6.20.31 3130efc0110332488712393300
172.6.20.35 172.6.20.31 3130efc0110332488712393400
I did a verify and the above entries shown up. I clicked on verify and subsequently went to address leases, did a refresh and can see these invalid entries. The name is the same as the IP addresses.
All the reminder DHCP IP entries are occupied by this long entries of 26 characters long.
Now I see inconsistencies in another DHCP Server. From time to time, I need to go in to delete this invalid entries.
Other DHCP scopes in both DHCP Server are experiencing this same symptoms.
Anyone experienced this before?
What I did:-
1. Booted both Servers in SAFE mode and performed full updated AV def scans // Results: No viruses found
2. Compact DHCP database on DHCP SERVER A, but still experienced same thing
Inconsistencies on the DHCP Servers is still around.
Anyone experienced this before?
This looks like a kind of DHCP attacks, else could be something keep on writing into registry, but could not be detected and when DHCP databases conpared against the registry entries, the records are thus updated into the DHCP database automatically becos' of comparison between DHCP Server and registries.
Rgds,
libroos