Is it ARP Spoofing?

asked 2022-03-20 05:57:27 +0000

1 despite i do nothing, arp request in every 2 minutes. or sometime arp storm happend.

2 It's very different between sender and target ip. it's different from the first number of ip. sender is me, xxx.yyy.xxx.yyy and target is yyy.zzz.yyy.zzz and i didn't see that ip with cmd command

i've looked up the relevant articles, but the sender of the arp and the target of arp had only the same triple number. like xxx.xxx.xxx.yyy and xxx.xxx.xxx.zzz

3 the source of each packet which request of strange ip is different from mine. router is different. ip is also different.

4 IO Graphics is strange. i turned on the internet page and did nothing, but the number of packets captured is very small, and sometimes it is recorded very much. like 5000 packets in 1 secs.

5 pop up blocked sound irregularly when i used to check packet with wireshark. i never heard like this sound(windows10 pop up block sound) before download and start this program. someone seems to be frolicking with a sound.

with these symptoms, is it ARP Spoofing? then what can i do to block and prevent it?

edit retag flag offensive close merge delete

Comments

Either it is an ARP storm or a loop. Could you share a trace with us?

Christian_R gravatar imageChristian_R ( 2022-03-20 20:53:48 +0000 )edit

i'm sorry for long text..

for example with a virtual ip, these arps float three times every two minutes.

sender is my PC and target's source is my PC's model. and that i don't know why they are so many different. between these two ip.

when it keep repeating, window 10 Popup block sounds irregular.

31434   3698.626158     Broadcast   ARP 42  Who has 157.25.157.25? Tell 102.30.10.42

31435   3699.084549     Broadcast   LOOP    60  Reply

31436   3699.144012     Broadcast   ARP 42  Who has 157.25.157.25? Tell 102.30.10.42

31442   3700.084574     Broadcast   LOOP    60  Reply

31448   3700.150427     Broadcast   ARP 42  Who has 157.25.157.25? Tell 102.30.10.42

sometime, arp request, reply float repeats per sec like this. sender is my router(or default gateway) and target is my phone, brother's phone.

even ...(more)

weird shark2135 gravatar imageweird shark2135 ( 2022-03-21 09:23:47 +0000 )edit