Event ID 4199. Massive attack?

Discuss Windows Event Log events. What they mean, what they tell you about your machine's security ... and whatever questions else you have.

Moderator: alorbach

Event ID 4199. Massive attack?

Postby Vilya on Wed Nov 12, 2003 9:02 pm

Hi, All!

Twice we've encountered a problem in our C-class subnet. All servers and workstaions (platforms: WinNT 4 WS, WinNT 4 ES, Win2000 Ws, Win2000 AS, WinXP, Win2003 ES) were affected withe the following error:

Event Type: Error
Event Source: Tcpip
Event Category: None
Event ID: 4199
Date: <dd.mm.yyyy>
Time: <hh:mm:ss>
User: N/A
Computer: <NetBios_Name>
Description:
The system detected an address conflict for IP address <IP_Adress> with the system having network hardware address <Hardware_Adress>. Network operations on this system may be disrupted as a result.

* where
<dd.mm.yyyy> and <hh:mm:ss> - when it had happened (almost at the same time at all systems);
<NetBios_Name> - machine NetBios Name, e.g. SYS_VILYA;
<IP_Adress> - machine ip address, e.g. 10.1.12.12 - unique at every system
<Hardware_Adress> - 00-00-xx-00-00-00 - unique at every system, differed with xx

duration - a few seconds
result - network is down

Was it a hardware manfunction, an OS bug or an attack?
What is possible to do to investigate this event and prevent it in the future?

Several details about network:
no DHCP available, all IP addresses are static
Win2003 ES as PDC, Win2003 ES as BDC
several Intel Express 460T Standalone Switches
several 3Com SuperStack Switches
one Intel NetStructure 470T Switch
Vilya
New
 
Posts: 4
Joined: Wed Nov 12, 2003 8:03 pm
Location: Ukraine, Dniepropetrovsk

Re: Event ID 4199. Massive attack?

Postby Guest on Tue Dec 02, 2003 6:41 pm

Vilya wrote:The system detected an address conflict for IP address <IP_Adress> with the system having network hardware address <Hardware_Adress>. Network operations on this system may be disrupted as a result.

Coincidentally, I've been having this error msg appearing as a popup over the last few weeks (16, 17 & 29-Nov-03) and it's the first time I've seen it.
WinXP-Home, 2-station Wireless LAN in Adhoc Mode (the other computer was switched on during one 'attack', it was off for the other 2), ADSL using XP's firewall. My first thought was that someone was hacking into my LAN.

Learned any more about it?
Guest
 

:o(

Postby Vilya on Tue Dec 02, 2003 7:07 pm

Nope.
It happened twice, 11-th and 12-th of Nov.
Still have no idea what was it :o(
Vilya
New
 
Posts: 4
Joined: Wed Nov 12, 2003 8:03 pm
Location: Ukraine, Dniepropetrovsk

Re: :o(

Postby Guest on Tue Dec 02, 2003 7:52 pm

Vilya wrote:Nope.
It happened twice, 11-th and 12-th of Nov.
Still have no idea what was it :o(

I've just been to see my next door neighbours and they have an adhoc WLAN. They're students and have 3 laptops explicitly set on a different channel, different network name, but one of them has the same IP as my machine here.

What I suspect is happening is either (a) my WLAN card is losing track of which channel it's supposed to be set on and it's latching onto their network or (b) one of their WLAN cards is losing track of etc etc or (c) they're trying to, er, 'borrow' my bandwidth.

The reason that I'm not round there right now with an axe, is that I know for a fact that my card does occasionally 'wander'. At least once a week I'll hear a shout from my daughter's room, "Dad! I can't get on the network!" and I check my WLAN card and find that it's set on the default channel 1 and showing no throughput.

Hmmm...
Guest
 

Postby Guest on Tue Dec 02, 2003 8:03 pm

Write me via E-Mail :o)

vilya@pbcards.dp.ua
Guest
 

Postby Guest on Wed Dec 03, 2003 9:33 am

Anonymous wrote:Write me via E-Mail

Did you not get my email?
Guest
 

Postby therget on Thu Dec 18, 2003 4:57 pm

User avatar
therget
Frequent Poster
 
Posts: 79
Joined: Thu Dec 18, 2003 12:42 pm

Google Ads



Return to Windows Events

Who is online

Users browsing this forum: No registered users and 0 guests

cron