Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
[Full-disclosure] how to bypass rouge machine detection techniques
From: Gaurav Kumar (gkvermagmail.com)
Date: Mon Jul 11 2005 - 04:59:21 CDT
There are several techniques available for detecting rouge (not being
a member of trusted domain) machines, such as active scanning, active
directory querying etc, but I guess most powerful being the one used
by epolicy orchestrator. Its agents (deployed on each subnet) checks
for L2 broadcasts like Arp broadcast etc. After detecting a broadcast,
it used the mac address and ip address to proceed further to detect
whether the machine is rouge or not.
I was wondering if this approach is foolproof and can be safely
deployed or if there is a way to bypass it?
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/