My PC is under ARP attack

Walenstein

Honorable
Jan 29, 2014
4
0
10,510
Hello,

My Laptop is the victim of ARP attacks that keep disconnecting my internet access from time to time. It is not regular; sometimes I am disconnected once a day, sometimes 3-4 times in 15 minutes. I reconnect using the 'Troubleshooting problems' button. I use XArp 2.2.2 to detect ARP attacks. Does anyone know how to get rid of this? It is really annoying to have to reconnect every time.

Network Devices:
Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
Qualcomm Atheros AR5BWB222 Wireless Network Adapter

I am using Windows 7 Ultimate, 64-bit

Thanks.
 
"I am using Windows 7 Ultimate, 64-bit"

That must be a pirated windows?

These pirated windows have built in back doors and trojans right from the get go.

Get a LEGAL Windows, format your PC with it and then update it and install decent internet protection program.

Viola. Fixed.

 

Walenstein

Honorable
Jan 29, 2014
4
0
10,510


Mine is a university network (I'm a student) and the ISP is the university itself. When the attack happens, I get the "there is a problem with the adapter" sort of message from the "Troubleshooting problems" button. XArp detects loads more attacks but only once in a while I lose the connection.
 
Ahh...university network. Some network management/user management devices do some things that look like an arp cache poisoning attack (because they are), that may be what you are seeing. Or, some of your fellow students may be attempting something. You really need to talk to your network admins - give them a list of IP addresses associated with the attacks, they can tell what those IPs are associated with.

When you loose Internet access, do you loose access to the local LAN too? When you do, what does the arp cache on your machine look like ("arp -a")?
 

Walenstein

Honorable
Jan 29, 2014
4
0
10,510


Here is the Troubleshooting report of the lastest disconnect, hope it helps somehow.

Diagnostics Information (Network Adapter)
Details about network adapter diagnosis:

Network adapter Wireless Network Connection driver information.

Description . . . . . . . . . . : Qualcomm Atheros AR5BWB222 Wireless Network Adapter
Manufacturer . . . . . . . . . : Qualcomm Atheros Communications Inc.
Provider . . . . . . . . . . . : Qualcomm Atheros Communications Inc.
Version . . . . . . . . . . . : 10.0.0.42
Inf File Name . . . . . . . . . : C:\Windows\INF\oem11.inf
Inf File Date . . . . . . . . . : Thursday, February 23, 2012 11:56:18 PM
Section Name . . . . . . . . . : ATHR_DEV_OS61_311711AD.ndi
Hardware ID . . . . . . . . . . : pci\ven_168c&dev_0034&subsys_662111ad
Instance Status Flags . . . . . : 0x180200a
Device Manager Status Code . . : 0
IfType . . . . . . . . . . . . : 71
Physical Media Type . . . . . . : 9



Diagnostics Information (Wireless Connectivity)
Details about wireless connectivity diagnosis:

Information for connection being diagnosed
Interface GUID: fac11c5a-8fb4-43f0-8791-037db75b71cc
Interface name: Qualcomm Atheros AR5BWB222 Wireless Network Adapter
Interface type: Native WiFi

Connection incident diagnosed
Auto Configuration ID: 1
Connection ID: 1

Connection status summary
Connection started at: 2014-01-29 14:14:54-469
Profile match: Success
Pre-Association: Success
Association: Success
Security and Authentication: Success

List of visible access point(s): 11 item(s) total, 11 item(s) displayed
BSSID BSS Type PHY Signal(dB) Chnl/freq SSID
-------------------------------------------------------------------------
02-26-66-9D-C2-9C Ad hoc g -83 6 HPJ310a.4AA280
84-38-35-40-FC-C0 Infra <unknown> -83 11 Abi's MacBook Air
00-1E-13-1C-53-74 Infra g -63 11 eduroam
00-1E-13-1C-53-73 Infra g -62 11 GuestNet
00-1E-13-1C-53-71 Infra g -65 11 (Unnamed Network)
00-1E-13-1C-53-72 Infra g -71 11 (Unnamed Network)
00-1E-13-1C-53-7D Infra a -71 5700000 (Unnamed Network)
00-1E-13-1C-53-7C Infra a -71 5700000 GuestNet
00-1E-13-1C-53-7B Infra a -71 5700000 eduroam
00-1E-13-1C-53-7E Infra a -71 5700000 (Unnamed Network)
F6-55-F9-AF-51-D6 Infra <unknown> -86 11 Connectify-me

Connection History

Information for Auto Configuration ID 1

List of visible networks: 6 item(s) total, 6 item(s) displayed
BSS Type PHY Security Signal(RSSI) Compatible SSID
------------------------------------------------------------------------------
Ad hoc g No 34 Yes HPJ310a.4AA280
Infra <unknown> No 34 Yes Abi's MacBook Air
Infra g Yes 72 Yes eduroam
Infra g No 76 Yes GuestNet
Infra g No 70 Yes (Unnamed Network)
Infra <unknown> Yes 28 Yes Connectify-me

List of preferred networks: 3 item(s)
Profile: arriva-wifi
SSID: arriva-wifi
SSID length: 11
Connection mode: Infra
Security: No
Set by group policy: No
Connect even if network is not broadcasting: No
Connectable: No
Reason: 0x00028002
Profile: eduroam
SSID: eduroam
SSID length: 7
Connection mode: Infra
Security: Yes
Set by group policy: No
Connect even if network is not broadcasting: No
Connectable: Yes
Profile: GURUNJA
SSID: GURUNJA
SSID length: 7
Connection mode: Infra
Security: Yes
Set by group policy: No
Connect even if network is not broadcasting: No
Connectable: No
Reason: 0x00028002

Information for Connection ID 1
Connection started at: 2014-01-29 14:14:54-469
Auto Configuration ID: 1
Profile: eduroam
SSID: eduroam
SSID length: 7
Connection mode: Infra
Security: Yes
Pre-Association and Association
Connectivity settings provided by hardware manufacturer (IHV): No
Security settings provided by hardware manufacturer (IHV): No
Profile matches network requirements: Success
Pre-association status: Success
Association status: Success
Last AP: 00-1e-13-1c-53-74
Security and Authentication
Configured security type: WPA2-802.1X
Configured encryption type: CCMP(AES)
802.1X protocol: Yes
Authentication mode: Machine or user
EAP type: Authentication not started
Number of 802.1X restarts: 4
Number of 802.1X failures: 0
802.1X status: Success
Key exchange initiated: Yes
Unicast key received: Yes
Multicast key received: Yes
Number of security packets received: 44
Number of security packets sent: 40
Security attempt status: Success
Connectivity
Packet statistics
Ndis Rx: 568098
Ndis Tx: 235572
Unicast decrypt success: 1474
Multicast decrypt success: 0
Unicast decrypt failure: 0
Multicast decrypt failure: 0
Rx success: 1505
Rx failure: 22731
Tx success: 868
Tx failure: 14
Tx retry: 68
Tx multiple retry: 2
Tx max lifetime exceeded: 0
Tx ACK failure: 20741
Roaming history: 0 item(s)




Diagnostics Information (Wireless Connectivity)
Details about wireless connectivity diagnosis:

For complete information about this session see the wireless connectivity information event.

Helper Class: Auto Configuration
Initialize status: Success

Information for connection being diagnosed
Interface GUID: fac11c5a-8fb4-43f0-8791-037db75b71cc
Interface name: Qualcomm Atheros AR5BWB222 Wireless Network Adapter
Interface type: Native WiFi

Result of diagnosis: There may be problem





 

Walenstein

Honorable
Jan 29, 2014
4
0
10,510
Small update: I disabled the wireless connection and activated the cable connection. ARP attacks reduced drastically, no more network disconnects registered from that moment onward.
 
I half-way suspect the disconnects are a problem with your adapter, or the interaction between the adapter and the (Cisco?) access points.

First update the drivers, it looks like the current driver version is .225 and you are at .42.
If you have access to another wi-fi adapter (other than the Qualcomm), give it a try.

Other than that, I'm about stumped.