<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx</link><description>Overview Rogue DHCP servers are those DHCP servers that are misconfigured or unauthorized unknowingly or those that are configured with a malicious intent for network attacks. Either be the case the impact on clients that are serviced by the rogue DHCP</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3260963</link><pubDate>Fri, 03 Jul 2009 10:15:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260963</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;Usage:&lt;/p&gt;
&lt;p&gt; Double click on the tool or launch the excutable from the command prompt. &lt;/p&gt;
&lt;p&gt; The tool on startup will query the AD and populates the authorized DHCP server.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Subhash Badri&lt;/p&gt;
</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3261090</link><pubDate>Fri, 03 Jul 2009 18:27:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261090</guid><dc:creator>Derek Morr</dc:creator><description>&lt;p&gt;Thanks for this, it looks useful. Are there any plans to add IPv6 support?&lt;/p&gt;</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3261144</link><pubDate>Sat, 04 Jul 2009 04:55:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261144</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;Yes, there are plans to add IPv6 support as well, but not immediately.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Subhash Badri&lt;/p&gt;
</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3261520</link><pubDate>Mon, 06 Jul 2009 16:45:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261520</guid><dc:creator>bhagirathrajabhai</dc:creator><description>&lt;p&gt;So does this tool have the basic functionality of the &amp;quot;DHCP&amp;quot; snap in that comes in the &amp;quot;Adminpak&amp;quot; for Active Directory, or &lt;/p&gt;
&lt;p&gt;The tool can also find non-AD dchp servers? &lt;/p&gt;</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3261540</link><pubDate>Mon, 06 Jul 2009 17:53:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261540</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;Yes, this tool finds DHCP servers in the subnet which are not authorized by the AD (I hope this is what you meant by non-AD dhcp servers).&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Subhash Badri&lt;/p&gt;
</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3261669</link><pubDate>Mon, 06 Jul 2009 22:53:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261669</guid><dc:creator>zep73</dc:creator><description>&lt;p&gt;I got a number of rogue servers detected 1 message, what do I do now.&lt;/p&gt;
</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3261741</link><pubDate>Tue, 07 Jul 2009 04:21:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261741</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;It would have filled the &amp;quot;Discovered DHCP servers in the subnet&amp;quot; grid box with the DHCP server details. If the tool poped up a dialog for access permission for opening a port (First time), then there are chances that grid is not populated, please re-run the tool in that case. &lt;/p&gt;
&lt;p&gt;Once you get some details about the rogue dhcp server, find out if the discovered DHCP server is really a rogue in which case find out the server machine which is running the DHCP service and stop the DHCP service on that server. &lt;/p&gt;
&lt;p&gt;If this DHCP server for some reason is not a rogue (in test purposes) then click on the checkbox, which will tell the tool not to report this server as rogue in future discovers.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Subhash Badri&lt;/p&gt;
</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3262842</link><pubDate>Fri, 10 Jul 2009 23:41:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3262842</guid><dc:creator>Matt</dc:creator><description>&lt;p&gt;I am trying to run this on one of our servers, and we keep getting &amp;quot;Interface: 10.10.1.1:68 is used by DHCP client for DHCP operation and cannot be used by Rogue detection tool Configure the static IPv4 address for this interface, stop DHCP client and restart the application.&amp;quot;&lt;/p&gt;
&lt;p&gt;The server I am trying to run this on has a static IP, and the DHCP client turned off.&lt;/p&gt;</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3262909</link><pubDate>Sat, 11 Jul 2009 05:18:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3262909</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;Matt,&lt;/p&gt;
&lt;p&gt; Please run netstat -aon to see which process is having an exclusive lock on port 68. Generally it would be dhcp client.&lt;/p&gt;
&lt;p&gt; Dhcp client has a dependency on &amp;quot;WinHTTP Web Proxy Auto-Discovery Service&amp;quot;. If you just stop the dhcp client it is restarted becuase of the dependency. First you have to disable &amp;quot;WinHTTP Web Proxy Auto-Discovery Service&amp;quot; and then stop the dhcp client.&lt;/p&gt;
&lt;p&gt;steps:&lt;/p&gt;
&lt;p&gt;1. Open services.msc&lt;/p&gt;
&lt;p&gt;2. Right click on &amp;quot;WinHTTP Web Proxy Auto-Discovery Service&amp;quot;&lt;/p&gt;
&lt;p&gt;3. click on the properties, select the statu type as disabled and click OK.&lt;/p&gt;
&lt;p&gt;4. stop the dhcp service by right clicking on &amp;quot;DHCP client&amp;quot; and click stop in services.msc, else use &amp;quot;net stop dhcp&amp;quot;&lt;/p&gt;
&lt;p&gt;5. Run the tool and it should work fine.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Subhash Badri&lt;/p&gt;
</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3286254</link><pubDate>Mon, 12 Oct 2009 20:47:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3286254</guid><dc:creator>Steven</dc:creator><description>&lt;p&gt;Nice tool, it's even useful if you are not using Windows Server for DHCP, which is my case.&lt;/p&gt;</description></item><item><title>re: Rogue DHCP Server detection</title><link>http://blogs.technet.com/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx#3287916</link><pubDate>Tue, 20 Oct 2009 15:23:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3287916</guid><dc:creator>Scott</dc:creator><description>&lt;p&gt;Love this tool! As a feature request for future ones, it would be great to see the MAC of the rogue DHCP server. When we get one on our network it's usually an invalid network IP and it becomes difficult to find so we run it in conjunction with a network capture to find the MAC and then search our switches to find the intruding port. &lt;/p&gt;</description></item></channel></rss>