Group policy and batch file help

Corif

Member
Jan 21, 2013
33
0
0
Hey everyone.

I'm in networking class in a high school and we are working to get a COMPTIA Networking+. I'm one of the students in the class that are far ahead so my teacher ask me if i can write a batch file that will poison the arp table of everyone in the room. We are doing this because we just talked about group policies and we want to apply the batch file to the policies and hope that it will run on the machines when they turn on. I have two question. Is this possible and can someone show me how to write a batch file that will poison the arp of all the machines? Help would be lovely
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
I don't have a clue why your teacher would want you to teach yourself how to write a bat file that poisons the arp cache and is executed through group policy. ARP cache poisoning is usually done maliciously (or by people that have been hired to pen test), and it's usually done with software that has been written specifically to broadcast gratuitous arp on the network.

But to answer your questions more directly, yes you can execute a batch file using a GPO, and yes you should be able to add an entry to the arp table with a batch file. you would want to use the arp command. I've never done this (because there's no good reason to), so YMMV...but in theory it should work as long as you've got admin credentials. details on the arp command below

> arp -?

Displays and modifies the IP-to-Physical address translation tables used by
address resolution protocol (ARP).

ARP -s inet_addr eth_addr [if_addr]
ARP -d inet_addr [if_addr]
ARP -a [inet_addr] [-N if_addr] [-v]

-a Displays current ARP entries by interrogating the current
protocol data. If inet_addr is specified, the IP and Physical
addresses for only the specified computer are displayed. If
more than one network interface uses ARP, entries for each ARP
table are displayed.
-g Same as -a.
-v Displays current ARP entries in verbose mode. All invalid
entries and entries on the loop-back interface will be shown.
inet_addr Specifies an internet address.
-N if_addr Displays the ARP entries for the network interface specified
by if_addr.
-d Deletes the host specified by inet_addr. inet_addr may be
wildcarded with * to delete all hosts.
-s Adds the host and associates the Internet address inet_addr
with the Physical address eth_addr. The Physical address is
given as 6 hexadecimal bytes separated by hyphens. The entry
is permanent.
eth_addr Specifies a physical address.
if_addr If present, this specifies the Internet address of the
interface whose address translation table should be modified.
If not present, the first applicable interface will be used.
Example:
> arp -s 157.55.85.212 00-aa-00-62-c6-09 .... Adds a static entry.
> arp -a .... Displays the arp table.
 

Udgnim

Diamond Member
Apr 16, 2008
3,665
112
106
logon script group policy directions

http://www.petri.co.il/setting-up-logon-script-through-gpo-windows-server-2008.htm

for creating batch file, use notepad save with .bat extension

use arp -s IP_Address Made_Up_MAC_Address and statically change the default gateway's MAC address on the student workstation MAC tables

you can also screw around with the host file too

http://social.technet.microsoft.com.../thread/d07a8aa2-a059-40ff-9e05-036a72f8adba/

echo 1.2.3.4 hostname.domain.com >> %windir%\system32\drivers\etc\hosts

do something like changing the school's domain name to resolve to Google's IP address and Google's domain name to resolve to the school's IP address
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |