What's new

Need support in finding spaming DHCPDISCOVER device

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

TheUntouchable

Regular Contributor
Hi guys!

I just checked my logs after updating to a new version of scribe and saw a lot of entries like that (every 5 minutes):

Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPDISCOVER(br0) 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPOFFER(br0) 192.168.1.80 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPDISCOVER(br0) 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPOFFER(br0) 192.168.1.80 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPDISCOVER(br0) 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPOFFER(br0) 192.168.1.80 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPDISCOVER(br0) 00:52:e0:9d:a5:1d
Feb 6 21:45:57 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPOFFER(br0) 192.168.1.80 00:52:e0:9d:a5:1d
Feb 6 21:45:58 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPDISCOVER(br0) 00:52:e0:9d:a5:1d
Feb 6 21:45:58 RT-AC88U-DDF0 dnsmasq-dhcp[385]: DHCPOFFER(br0) 192.168.1.80 00:52:e0:9d:a5:1d

I can't identify that mac address from my known devises and also couldn't find any vendor with that mac address. My computers ARP cache also doesn't know that mac.

Any hint how I can get rid of that device or know which device it is?

Thanks in advance.
 
I can't identify that mac address from my known devises and also couldn't find any vendor with that mac address.
If you dont find the culprit, you only have to put Hide DHCP / RA queries on YES, in Lan section-Dhcp server. Flooding will stop
 
That MAC is invalid, so either it's a virtual machine, or you have a device using a randomized MAC address for privacy purposes. I believe that's an iPhone feature, among others.
 
That MAC is invalid, so either it's a virtual machine, or you have a device using a randomized MAC address for privacy purposes. I believe that's an iPhone feature, among others.

Thanks Merlin for the hints. The randomizing MAC address feature is also present on windows 10 machines, as I don't own an iPhone :D But none of my devices have activated that. There is no way to see if the request is coming from WLAN or LAN right?
 
If you dont find the culprit, you only have to put Hide DHCP / RA queries on YES, in Lan section-Dhcp server. Flooding will stop
Thanks for you reply, but I really want to hunt that device down as when its coming from WLAN it should have the key for it and thats not good :D
 
Does it pop up on the Wireless Log page?
I'm afraid not. It doesn't take the IP address from the dhcpoffer, so it doesn't have a real connection, only makes dhcpdiscovers every 5 minutes..
 
Thanks Merlin for the hints. The randomizing MAC address feature is also present on windows 10 machines, as I don't own an iPhone :D But none of my devices have activated that. There is no way to see if the request is coming from WLAN or LAN right?

Simplest way is to manually reboot devices one at a time and see what pops up.
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top