{"id":2894,"date":"2018-07-28T17:06:43","date_gmt":"2018-07-28T17:06:43","guid":{"rendered":"https:\/\/tst-amo.net.ua\/blog\/?p=2894"},"modified":"2020-01-17T11:25:51","modified_gmt":"2020-01-17T11:25:51","slug":"arpwatch","status":"publish","type":"post","link":"https:\/\/tst-amo.net.ua\/blog\/?p=2894","title":{"rendered":"arpwatch"},"content":{"rendered":"<p><b>arpwatch<\/b>\u00a0\u2014 \u0434\u0435\u043c\u043e\u043d, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 IP \u0438 MAC-\u0430\u0434\u0440\u0435\u0441\u0430\u043c\u0438, \u0438 \u043f\u0440\u0438 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0438 \u0430\u043d\u043e\u043c\u0430\u043b\u0438\u0439, \u0441\u043e\u043e\u0431\u0449\u0430\u044e\u0449\u0438\u0439 \u043e\u0431 \u044d\u0442\u043e\u043c \u0432 Syslog. \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043a\u0430\u043a \u043e\u0434\u0438\u043d \u0438\u0437 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u0431\u043e\u0440\u044c\u0431\u044b \u0441\u00a0ARP-spoofing&#8217;\u043e\u043c.<\/p>\n<p>\u0414\u0435\u043c\u043e\u043d \u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u0442\u00a0ARP-\u043e\u0442\u0432\u0435\u0442\u044b\u00a0\u043d\u0430\u00a0\u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435, \u043a \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u043e\u043d \u043f\u0440\u0438\u0432\u044f\u0437\u0430\u043d, \u0438 \u0437\u0430\u043f\u043e\u043c\u0438\u043d\u0430\u0435\u0442 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435\u00a0IP-\u0430\u0434\u0440\u0435\u0441\u043e\u0432\u00a0\u0438\u00a0MAC-\u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u041a\u0430\u043a \u0442\u043e\u043b\u044c\u043a\u043e \u043e\u043d \u0432\u0438\u0434\u0438\u0442, \u0447\u0442\u043e \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435 \u043d\u0430\u0440\u0443\u0448\u0435\u043d\u043e, \u0438\u043b\u0438 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u043d\u043e\u0432\u044b\u0445 \u0430\u0434\u0440\u0435\u0441\u043e\u0432 \u0432 \u0441\u0435\u0442\u0438, \u043e\u043d \u0441\u043e\u043e\u0431\u0449\u0430\u0435\u0442 \u043e\u0431 \u044d\u0442\u043e\u043c \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u0436\u0443\u0440\u043d\u0430\u043b (syslog).<\/p>\n<pre># yum install arpwatch<\/pre>\n<p>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0438\u0440\u0443\u0435\u043c:<\/p>\n<pre>$ cat \/etc\/sysconfig\/arpwatch\r\nOPTIONS=\"-i <span style=\"color: #ff0000;\">enp5s0<\/span> -f arp.dat -u arpwatch -e <span style=\"color: #ff0000;\">admin@example.com<\/span> -s 'root (Arpwatch)'\"<\/pre>\n<pre>$ sudo systemctl start arpwatch\r\n$ sudo systemctl enable arpwatch<\/pre>\n<pre>\/var\/lib\/arpwatch - default directory\r\n          arp.dat - ethernet\/ip address database\r\n   ethercodes.dat - vendor ethernet block list<\/pre>\n<p>\u041f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e, \u0434\u0435\u043c\u043e\u043d \u043f\u0438\u0448\u0435\u0442 \u043b\u043e\u0433\u0438 \u0432 \/var\/log\/messages, \u0447\u0442\u043e \u0431\u044b \u043d\u0435 \u043c\u0443\u0441\u043e\u0440\u0438\u0442\u044c \u0432 \u044d\u0442\u043e\u0442 \u0444\u0430\u0439\u043b \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u043c \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 \u043b\u043e\u0433. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u0444\u0430\u0439\u043b \u043b\u043e\u0433\u043e\u0432 \u0438 \u0444\u0430\u0439\u043b \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0434\u043b\u044f rsyslog<\/p>\n<pre># touch \/var\/log\/arpwatch.log\r\n\r\n# vi \/etc\/rsyslog.d\/arpwatch.conf\r\nif ( $programname startswith \"arpwatch\" ) then {\r\naction(type=\"omfile\" file=\"\/var\/log\/arpwatch.log\")\r\nstop\r\n}<\/pre>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c:<\/p>\n<pre># rsyslogd -N 1\r\n# systemctl restart rsyslog<\/pre>\n<p>\u0422\u0430\u043a \u043a\u0430\u043a \u0432 \u043f\u0435\u0440\u0432\u044b\u0445 \u0442\u0440\u0435\u0445 \u043e\u043a\u0442\u0435\u0442\u0430\u0445 \u041c\u0410\u0421-\u0430\u0434\u0440\u0435\u0441\u0430 \u043a\u043e\u0434\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f, \u043d\u0430\u043c \u0436\u0435\u043b\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u0438\u043c\u0435\u0442\u044c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u0443\u044e \u0431\u0430\u0437\u0443 \u041c\u0410\u0421\/\u041f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c. \u041e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u0431\u0430\u0437\u0443 MAC \u0430\u0434\u0440\u0435\u0441\u043e\u0432:<\/p>\n<pre># vi arpwatch_update_mac.sh\r\n\r\n#!\/bin\/bash\r\n# update_mac_addresses.sh\r\n# This script downloads the currect mac address data from the IEEE and parses it for nmap and arpwatch.\r\n# nmap-mac-prefixes is for nmap.\r\n# ethercodes.dat is arpwatch.\r\n\r\n# Download the current data\r\n\r\nwget <span style=\"color: #ff0000;\">http:\/\/standards-oui.ieee.org\/oui\/oui.txt<\/span>\r\n\r\n# Divide the data into Manufacturer and Address files\r\ncat oui.txt | grep '(base 16)' | cut -f3 &gt; mac.manufacturer\r\ncat oui.txt | grep '(base 16)' | cut -f1 -d' ' &gt; mac.address\r\n\r\n# Paste them back together for nmap data\r\npaste mac.address mac.manufacturer &gt; nmap-mac-prefixes\r\n\r\n# Parse the address data for arpwatch\r\ncat mac.address | perl -pe 's\/^(([^0].)|0(.))(([^0].)|0(.))(([^0].)|0(.))\/\\2\\3:\\5\\6:\\8\\9\/' &gt; tmp.address\r\ncat tmp.address | tr [A-Z] [a-z] &gt; mac.address\r\n\r\n# Paste the parsed data into the arpwatch file\r\npaste mac.address mac.manufacturer &gt; <span style=\"color: #ff0000;\">\/var\/lib\/arpwatch\/ethercodes.dat<\/span>\r\n\r\n# Clean up intermediary files\r\nrm tmp.address\r\nrm mac.address\r\nrm mac.manufacturer\r\nrm oui.txt<\/pre>\n<p>\u0414\u0435\u043b\u0430\u0435\u043c \u0444\u0430\u0439\u043b \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u043c \u0438 \u043f\u0440\u043e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u0432 cron \u0434\u043b\u044f \u0435\u0436\u0435\u043c\u0435\u0441\u044f\u0447\u043d\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f:<\/p>\n<pre># chmod +x arpwatch_update_mac.sh<\/pre>\n<pre># crontab -e\r\n@monthly\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \/home\/svm\/bin\/arpwatch_update_mac.sh<\/pre>\n<p class=\"rtejustify\"><strong>ARPWatch<\/strong>\u00a0\u0440\u0430\u0441\u0441\u044b\u043b\u0430\u0435\u0442 \u0447\u0435\u0442\u044b\u0440\u0435 \u0432\u0438\u0434\u0430 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0439.<\/p>\n<ul>\n<li><strong>new activity<\/strong>\u00a0&#8211; \u0441\u0432\u044f\u0437\u043a\u0430 ethernet\/ip-\u0430\u0434\u0440\u0435\u0441\u043e\u0432\u00a0\u0441\u043d\u043e\u0432\u0430 \u043f\u0440\u043e\u044f\u0432\u0438\u043b\u0430 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c\u00a0\u0441\u043f\u0443\u0441\u0442\u044f \u0448\u0435\u0441\u0442\u044c \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0438\u043b\u0438 \u0431\u043e\u043b\u044c\u0448\u0435<\/li>\n<li><strong>new station<\/strong>\u00a0&#8211; ethernet-\u0430\u0434\u0440\u0435\u0441 \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d \u0432\u043f\u0435\u0440\u0432\u044b\u0435<\/li>\n<li><strong>flip flop<\/strong>\u00a0&#8211; ethernet-\u0430\u0434\u0440\u0435\u0441 \u0438\u0437\u043c\u0435\u043d\u0438\u043b\u0441\u044f \u0441 \u043e\u0434\u043d\u043e\u0433\u043e \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u0430 \u043d\u0430 \u0434\u0440\u0443\u0433\u043e\u0439 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0439 \u0430\u0434\u0440\u0435\u0441<\/li>\n<li><strong>changed ethernet address<\/strong>\u00a0&#8211; \u0445\u043e\u0441\u0442 \u043f\u0435\u0440\u0435\u0448\u0451\u043b \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u043d\u043e\u0432\u043e\u0433\u043e ethernet-\u0430\u0434\u0440\u0435\u0441\u0430<\/li>\n<\/ul>\n<p><strong>ARPWatch<\/strong>\u00a0\u0442\u0430\u043a\u0436\u0435 \u043f\u0438\u0448\u0435\u0442 \u0441\u043e\u0431\u044b\u0442\u0438\u044f \u0432\u00a0<strong>messages\/syslog<\/strong>.<\/p>\n<p class=\"rtejustify\">\u0412\u00a0<strong>syslog<\/strong>\u00a0\u043c\u043e\u0433\u0443\u0442 \u043f\u0438\u0441\u0430\u0442\u044c\u0441\u044f \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0442\u0438\u043f\u044b \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0439:<\/p>\n<ul>\n<li class=\"rtejustify\"><strong>ethernet broadcast\u00a0<\/strong>\u00a0&#8211; MAC-\u0430\u0434\u0440\u0435\u0441 \u0445\u043e\u0441\u0442\u0430 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0448\u0438\u0440\u043e\u043a\u043e\u0432\u0435\u0449\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u043c.<\/li>\n<li class=\"rtejustify\"><strong>ip broadcast<\/strong>\u00a0&#8211; IP-\u0430\u0434\u0440\u0435\u0441 \u0445\u043e\u0441\u0442\u0430 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0448\u0438\u0440\u043e\u043a\u043e\u0432\u0435\u0449\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u043c.<\/li>\n<li class=\"rtejustify\"><strong>bogon<\/strong>\u00a0&#8211; \u0430\u0434\u0440\u0435\u0441 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u0435\u043b\u044f IP-\u043f\u0430\u043a\u0435\u0442\u0430 \u043d\u0435 \u0432\u0445\u043e\u0434\u0438\u0442 \u0432 \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u0443\u044e \u0441\u0435\u0442\u044c (directly connected network) \u0434\u043b\u044f \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430.<\/li>\n<li class=\"rtejustify\"><strong>ethernet broadcast<\/strong>\u00a0&#8211; MAC-\u0430\u0434\u0440\u0435\u0441 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u0435\u043b\u044f \u0441\u043e\u0441\u0442\u043e\u0438\u0442 \u0438\u0437 \u043e\u0434\u043d\u0438\u0445 \u043d\u0443\u043b\u0435\u0439 \u0438\u043b\u0438 \u043e\u0434\u043d\u0438\u0445 \u0435\u0434\u0438\u043d\u0438\u0446.<\/li>\n<li class=\"rtejustify\"><strong>ethernet mismatch<\/strong>\u00a0&#8211; MAC-\u0430\u0434\u0440\u0435\u0441 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u0435\u043b\u044f \u043f\u0430\u043a\u0435\u0442\u0430 \u043d\u0435 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 MAC-\u0430\u0434\u0440\u0435\u0441\u0443, \u0443\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u043c\u0443 \u0432\u043d\u0443\u0442\u0440\u0438 ARP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430.<\/li>\n<li class=\"rtejustify\"><strong>reused old ethernet address<\/strong>\u00a0&#8211; ethernet-\u0430\u0434\u0440\u0435\u0441 \u0438\u0437\u043c\u0435\u043d\u0438\u043b\u0441\u044f \u0441 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u0430 \u043d\u0430 \u0430\u0434\u0440\u0435\u0441, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0437\u0430\u043c\u0435\u0447\u0435\u043d \u0440\u0430\u043d\u0435\u0435, \u043d\u043e \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0447\u0442\u043e. (\u041f\u043e\u0445\u043e\u0436\u0435 \u043d\u0430 flip flop, \u043d\u043e \u0447\u0443\u0442\u044c-\u0447\u0443\u0442\u044c \u0434\u0440\u0443\u0433\u043e\u0435.)<\/li>\n<li class=\"rtejustify\"><strong>suppressed DECnet flip flop<\/strong>\u00a0&#8211; \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0435 &#8220;flip flop&#8221; \u043f\u043e\u0434\u0430\u0432\u043b\u0435\u043d\u043e \u0432 \u0441\u0432\u044f\u0437\u0438 \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e \u043a\u0430\u043a \u043c\u0438\u043d\u0438\u043c\u0443\u043c \u043e\u0434\u0438\u043d \u0438\u0437 \u0434\u0432\u0443\u0445 \u0430\u0434\u0440\u0435\u0441\u043e\u0432 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441\u043e\u043c DECnet.<\/li>\n<\/ul>\n<p>\u0415\u0441\u043b\u0438 \u0432 \u043b\u043e\u0433\u0430\u0445 \u043f\u043e\u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u044f \u0432\u0438\u0434\u0430<\/p>\n<pre>Aug 2 06:52:09 ring arpwatch: bogon 10.90.90.91 1c:af:f7:e1:b6:71\r\nAug 2 06:52:10 ring arpwatch: bogon 10.90.90.91 1c:af:f7:e1:b6:71\r\nAug 2 06:52:35 ring arpwatch: bogon 10.90.90.91 1c:af:f7:e1:b6:71\r\nAug 2 06:52:36 ring arpwatch: bogon 10.90.90.91 1c:af:f7:e1:b6:71\r\nAug 2 06:52:37 ring arpwatch: bogon 10.90.90.91 1c:af:f7:e1:b6:71<\/pre>\n<p>\u0433\u0434\u0435 10.90.90.91 &#8211; IP\u00a0 \u0438\u0437 \u0434\u0440\u0443\u0433\u043e\u0439 \u0441\u0435\u0442\u0438, \u043e\u0442\u043b\u0438\u0447\u043d\u043e\u0439 \u043e\u0442 \u0442\u043e\u0439, \u0447\u0442\u043e \u0441\u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043d\u0430 \u0441\u043b\u0443\u0448\u0430\u044e\u0449\u0438\u043c\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u043a\u043e\u043c\u0443\u043d\u0438\u043a\u0430\u0442\u043e\u0440\u0443), \u0442\u043e \u043c\u043e\u0436\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u044d\u0442\u0443 \u0441\u0435\u0442\u044c \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 <strong>\/etc\/sysconfig\/arpwatch<\/strong>, \u0447\u0442\u043e \u0431\u044b \u043d\u0435 \u043c\u0443\u0441\u043e\u0440\u0438\u043b\u043e \u0432 \u043b\u043e\u0433\u0430\u0445 \u0438 \u043f\u0435\u0440\u0435\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0438\u0441:<\/p>\n<pre>-n 10.90.90.0\/24<\/pre>\n<p>\u0418\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0438:<\/p>\n<ul>\n<li><a href=\"https:\/\/blog.trebacz.com\/2015\/12\/update-arpwatch-ethercodes-dat-file-ubuntu.html\">https:\/\/blog.trebacz.com\/2015\/12\/update-arpwatch-ethercodes-dat-file-ubuntu.html<\/a><\/li>\n<li><a href=\"http:\/\/muff.kiev.ua\/content\/arpwatch-sledim-za-novymi-ustroistvami-v-seti\">http:\/\/muff.kiev.ua\/content\/arpwatch-sledim-za-novymi-ustroistvami-v-seti<\/a><\/li>\n<\/ul>\n<div class=\"pdfprnt-buttons pdfprnt-buttons-post pdfprnt-bottom-right\"><a href=\"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=wpv2posts2894&print=pdf\" class=\"pdfprnt-button pdfprnt-button-pdf\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/tst-amo.net.ua\/blog\/wp-content\/plugins\/pdf-print\/images\/pdf.png\" alt=\"image_pdf\" title=\"View PDF\" \/><\/a><a href=\"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=wpv2posts2894&print=print\" class=\"pdfprnt-button pdfprnt-button-print\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/tst-amo.net.ua\/blog\/wp-content\/plugins\/pdf-print\/images\/print.png\" alt=\"image_print\" title=\"Print Content\" \/><\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>arpwatch\u00a0\u2014 \u0434\u0435\u043c\u043e\u043d, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 IP \u0438 MAC-\u0430\u0434\u0440\u0435\u0441\u0430\u043c\u0438, \u0438 \u043f\u0440\u0438 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0438 \u0430\u043d\u043e\u043c\u0430\u043b\u0438\u0439, \u0441\u043e\u043e\u0431\u0449\u0430\u044e\u0449\u0438\u0439 \u043e\u0431 \u044d\u0442\u043e\u043c \u0432 Syslog. \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043a\u0430\u043a \u043e\u0434\u0438\u043d \u0438\u0437 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u0431\u043e\u0440\u044c\u0431\u044b \u0441\u00a0ARP-spoofing&#8217;\u043e\u043c. \u0414\u0435\u043c\u043e\u043d \u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u0442\u00a0ARP-\u043e\u0442\u0432\u0435\u0442\u044b\u00a0\u043d\u0430\u00a0\u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435, \u043a \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u043e\u043d \u043f\u0440\u0438\u0432\u044f\u0437\u0430\u043d, \u0438 \u0437\u0430\u043f\u043e\u043c\u0438\u043d\u0430\u0435\u0442 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435\u00a0IP-\u0430\u0434\u0440\u0435\u0441\u043e\u0432\u00a0\u0438\u00a0MAC-\u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u041a\u0430\u043a \u0442\u043e\u043b\u044c\u043a\u043e \u043e\u043d \u0432\u0438\u0434\u0438\u0442, \u0447\u0442\u043e \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435 \u043d\u0430\u0440\u0443\u0448\u0435\u043d\u043e, \u0438\u043b\u0438 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u043d\u043e\u0432\u044b\u0445 \u0430\u0434\u0440\u0435\u0441\u043e\u0432 \u0432 \u0441\u0435\u0442\u0438, \u043e\u043d \u0441\u043e\u043e\u0431\u0449\u0430\u0435\u0442 \u043e\u0431 \u044d\u0442\u043e\u043c \u0432 &#8230;<\/p>\n<p><a href=\"https:\/\/tst-amo.net.ua\/blog\/?p=2894\" class=\"more-link\">Continue reading &lsquo;arpwatch&rsquo; &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[139,48,47,184],"tags":[],"class_list":["post-2894","post","type-post","status-publish","format-standard","hentry","category-arpwatch","category-centos","category-linux","category-rsyslog"],"_links":{"self":[{"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2894"}],"collection":[{"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2894"}],"version-history":[{"count":7,"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2894\/revisions"}],"predecessor-version":[{"id":4456,"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2894\/revisions\/4456"}],"wp:attachment":[{"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tst-amo.net.ua\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}