View Single Post
  #18 (permalink)  
Old 09-14-2005, 02:34 AM
Moe Trin
Guest
 
Posts: n/a
Default Re: Company network slowdown

In the Usenet newsgroup alt.internet.wireless, in article
<gjnci15ei80kbrlanvk0c5lc78974etjt9@4ax.com>, Jeff Liebermann wrote:

>Been there. HP LaserJet 4 with Jetdirect J2552 card. If I run out of
>paper, it floods the networks with garbage that was impossible to
>decode with Ethereal. That took me 6 months to find.


Don't know what your network looks like, but HP only has a handful of
OUI blocks:

[compton ~]$ zgrep -i Hewlett MACaddresses.gz | grep base | cut -d' '
-f1 | column
0001E6 000883 000E7F 00110A 001321 001560 0060B0
0001E7 000A57 000F20 001185 001438 00306E 0080A0
0004EA 000D9D 001083 001279 0014C2 0030C1 080009
[compton ~]$

That's straight out of the IEEE file. I'm at an R&D facility, and we're
super paranoid, so every host is 'registered' meaning we know MAC, IP,
user, location, which drop from which switch, serial and decal numbers,
and the date of last tetanus shot for everything that connects to our net.
If something starts squittering, I can ID the box in seconds. If the box
is unknown, I can ID the drop, and it's 50/50 if the security goons get
there before me or not.

Old guy

Reply With Quote