fake network address....


 
Thread Tools Search this Thread
Top Forums UNIX for Dummies Questions & Answers fake network address....
# 1  
Old 07-28-2010
fake network address....

Good morning!

Why would having a fake network device be useful?

Thanks in advance
Bigben
 
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. IP Networking

Network address translation

How would one approach the problem of determining the NAT tables of a router without knowing the userid and password. The only password holder died. I know the internal ip address of the router is 192.168.2.1, and also ports 80 or 8080 and 3389 are open. (5 Replies)
Discussion started by: jgt
5 Replies

2. IP Networking

Partitioning a network address. Urgent help please

Hi, I am trying to figure out a way to partition the departmental IP network address block to create a staff and a student subnet. Each of these will be identified by its own network address and netmask. It is university policy that you must be economical with the IP addresses. That is, the... (0 Replies)
Discussion started by: bawse.c
0 Replies

3. Shell Programming and Scripting

Shell script to give broadcast and network address

Hello, I am running a post script in autoyast where I am trying to set the broadcast and network address. I have the ip address and netmask already (reading from a file).. I saw the post from fpmurphy but it is using ksh which isn't an option in autoyast. Thanks in advance! (3 Replies)
Discussion started by: bloodclot
3 Replies

4. IP Networking

What is a fake network device?

Thanks in advance! Ben (1 Reply)
Discussion started by: bigben1220
1 Replies

5. IP Networking

Maximum IP Address Configured on Intel Network Adapter

Hi All, Sorry if this is not the correct forum to answer. But hope somebody can help me... For these two types of network adapter: Intel(R) PRO/1000 MT Server Adapter Intel(R) PRO/1000 MT Dual Port Network Adapter How many IP addresses can be configured on it at the same time? System... (3 Replies)
Discussion started by: wilsonSurya
3 Replies

6. Shell Programming and Scripting

network and broadcast address

Hi Suppose You have two computers. One named kenny which has an IP address of 192.168.0.7. kenny lives on a subnet with a subnet mask of 255.255.255.240. The second computer is called zathras, which has an IP address of 192.168.0.17, zathras lives on a network with the same subnet mask. i)... (4 Replies)
Discussion started by: scofiled83
4 Replies

7. IP Networking

Obtaining IP address from both my network interface

HI folks, I am developing a software which one of the module is to interchange the ip address of another active network interface's when making a socket connection. I would like to know whether there is any function call that would enable me to retrieve the ip address that is obtained by a... (2 Replies)
Discussion started by: citiz3n
2 Replies

8. AIX

NETWORK IP ADDRESS on HACMP

Hi, I try to understand how to configure my ethernet network in a hacmp cluster. I have 2 nodes, 3 lan port on each node, and 1 service ip to cluster. I don't have any serial o iscsi heartbeat. Do you suggest me a possibile ip address configuration? I've many error whene I verify it from hacmp... (3 Replies)
Discussion started by: hacmp
3 Replies

9. HP-UX

Connecting To An External Network Using A logical (PACKAGE) IP Address

Hie everyone, I am currently facing a problem whereby I can not connect to an external network from a package ip address on a HP-UX cluster. Below is the illustration: Primary Server IP Address : n.n.n.202 Secondary Server IP Address : n.n.n.212 Package IP Address : n.n.n.211 ... (1 Reply)
Discussion started by: cchilenga
1 Replies

10. UNIX for Dummies Questions & Answers

network address and broadcast address?

say I have a IP address which is 10.0.0.12, and subnet mask is 255.255.255.240, what is the network address and what is the broadcast address which host lives on? And could you explain how to get the answer? thanx in advance! (7 Replies)
Discussion started by: pnxi
7 Replies
Login or Register to Ask a Question
FAKE(8) 						      System Manager's Manual							   FAKE(8)

NAME
fake - IP address takeover tool SYNOPSIS
fake [remove] IP_ADDRESS DESCRIPTION
The fake utility enables the switching in of a backup server by bringing up an additional interface and using ARP spoofing to take over IP_ADDRESS. Variants of the script have been used extensively at Zip World (http://www.zipworld.com.au/) for backing up mail, web and proxy servers. Although this system has been shown to work you are well advised to test the system thoroughly before putting it into production. Please read the documents in /usr/share/doc/fake/ for an explanation of how fake works and for a discussion of issues surrounding its use. OPTIONS
remove Stop the takeover of an IP address. Without this option, fake starts the takeover of an IP address. GLOBAL CONFIGURATION FILE
The global configuration file is in /etc/fake/.fakerc. The settings there are overridden by those in ${HOME}/.fakerc. Here is a sample configuration file. ############################################################ # Set up basic environment for fake # Variables are set as bash variables # i.e. <VARIABLE>=<value> # # Must set: # ARP_DELAY: Delay in seconds between gratuitous ARP # PID_DIR: Directory where PID files are kept # INSTANCE_CONFIG_DIR: Directory where specific # configuration files for an IP address takeover are kept # CLEAR_ROUTERS_FILE: New line delimited list of routers to rsh # to and execute "clear arp-cache" # FAKE_RSH: Programme to use to "rsh" to another machine # to obtain macaddress by running ifconfig # # PATH can be set here to ensure that send_arp is in the # path ############################################################ FAKE_HOME="/etc/fake" #PATH=/sbin:/usr/sbin:/bin:/usr/bin ARP_DELAY=1 CLEAR_ROUTERS_FILE="$FAKE_HOME/clear_routers" PID_DIR="/var/run" INSTANCE_CONFIG_DIR="$FAKE_HOME/instance_config" #Only needed if you wish to send gratuitous ARP #advertising the "real" mac address when turning fake off #FAKE_RSH=ssh INSTANCE CONFIGURATION
To configure an instance of fake, create /etc/fake/instance_config/<IP-address-to-take-over>.cfg with the following format: SPOOF_IP=<IP-address-to-take-over> The SPOOF_IP variable must contain the same IP address as appears in the name of the file. This is checked at run time. IFCONFIG=TRUE|FALSE SPOOF_NETMASK=<netmask-of-network-that-IP-address-to-take-over-is-on> TARGET_INTERFACE=<interface-to-bring-up> If the IFCONFIG variable is set to TRUE, the address specified by SPOOF_IP will be brought up on the interface specified by TARGET_INTER- FACE; SPOOF_NETMASK and TARGET_INTERFACE must also be defined. For obvious reasons it is very important that the TARGET_INTERFACEs of running instances of fake all be different from one another. Optionally if you wish to rsh to the main server and advertise the "real" MAC address when turning fake off then set the following; FOREIGN_INTERFACE=<interface-on-foreign-host-with-MAC-address-to-use> FOREIGN_ARP=<number-of-ARPs-to-send-with-real-MAC-address> To use this last feature in an automated fashion you will need to be able to $FAKE_RSH to $SPOOF_IP from the host that fake runs on without manual authentication. With rsh this is typically achived using .rhosts; with ssh an RSH key with an empty passphrase can be employed. Here is an example of /etc/fake/instance_config/203.12.97.7.cfg: SPOOF_IP=203.12.97.7 IFCONFIG=TRUE SPOOF_NETMASK=255.255.255.0 TARGET_INTERFACE=eth0:2 FOREIGN_INTERFACE=eth0 FOREIGN_ARP=5 ACTIVATION
To activate fake, run: fake <IP-address-to-take-over> & Logs will be made to the local0.notice syslog facility. On startup you should see messages in the syslog; running ifconfig should show the new interface; running route should show a route for the spoofed IP address on the new interface (which is needed so the machine that fake is running on can communicate correctly to this IP address); and running tcpdump -i <interface> arp should show the gratuitous ARP packets. DEACTIVATION
To deactivate, run: fake remove <IP-address-to-take-over> As of version 1.1.2 the fake process can be sent a SIGTERM or SIGHUP to effect the removal. On removal you should see a message in the syslog; ifconfig should show that the new interface has been removed; route should show that the new route has been removed; and tcpdump should show that the gratuitous ARP has stopped. Note: Activating fake multiple times with the same arguments has the same effect as activating it once. Similarly, deactivating fake mul- tiple times with the same arguments has the same effect as deactivating it once. FILES
/etc/fake/.fakerc /etc/fake/clear_routers /etc/fake/instance_config/<IP-address>.cfg /var/run/fake.<IP-address>.pid AUTHOR
Horms <horms@verge.net.au> 9 June 2004 FAKE(8)