Hi,
I hope someone can help me out with this. I am
running
Wireshark from two different computers and getting the same results.
Basically
I am getting the following:
ARP/RARP Duplicate IP address configured
(192.168.10.222)
ARP/RARP Duplicate IP address configured
(192.168.10.220)
ARP/RARP Duplicate IP address configured
(192.168.10.208)
This is an example:
154,"16:58:24.071822","Dell_55:3b:5b","Dell_42:b5:3a","ARP","Who
has
192.168.10.40? Tell 192.168.10.222 (duplicate use of 192.168.10.200
detected!)"
These addresses are statically assigned and I
don’t
see how they could be duplicated. I read that this could be an ARP
attack
but I’m not sure what to look for.
How can I know whether it is an ARP attack and
trace the
computer that’s causing the problem.