Can't remove ARP Spoofing attck

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract: Can’t detect or remove a known ARP spoofing attack in on my network. I’ve enabled all security and firewall settings. Run full & startup scans. An ARP detection app still identifies and shows all of the ARP spoofing changes in real time. I have a small home network that is compromised by this attacker. Need help to remove it somehow.

Detailed description: Norton 360 Deluxe

Product & version number: Latest edition

OS details: Win 11 Home

What is the error message you are seeing? 1 Device on the network received a Norton popup that it detected ARP Spoofing but no fix or action was provided

If you have any supporting screenshots, please add them:

Hello @Edward_Walker

========== == ========== == ========== == ========== == ==========

AI sourced content may make mistakes

Hello @Edward_Walker
Care to share your progress
Thanks

I’ve been working through the list.

I installed a new WIFI router through a bridge mode on my ISP Modem and created a whole new locked down network

  • My Router doesn’t provide the granular view of DCHP client list and neither Modem or Router has Address Filtering

    I’ve scanned the suspect PC with Norton, Malwarebytes & ESET Scanner- nothing found. I did find a program called WinPcap and unistalled it.

    I cleared the ARP cache and connected to the WIFI, immediately shut the WIFI down and looked at the ARP cache, it showed 3 different MAC for the device, 2 were Static,1 of them is ff-ff-ff-ff-ff-ff-ff, so clearly the attacker is still there.

1 Like

AI sourced content may make mistakes

@Edward_Walker May we ask:

-What is the maker and full model of the ISP device you have? Who is your ISP? Just asking that question to gather some basic information about your hardware and its capabilities.

-Do you have WiFi enabled on BOTH devices or disabled on your ISP device and are using your router’s wifi?

-What is the maker and full model of your personal router?

SA

Hi SA

ISP is Rogers Canada, device is an Xfinity Easy Connect 6300 and is in Bridge Mode (no WIFI enabled)

New WIFI router is D-Link R36 BE3600 WIFI 7

AI sourced content may make mistakes

I was using XARP to monitor the spoofing but it now seems to have stopped working.

I also used RKill to a scan

Here is a screenshot of the ARP cache just after I connect the device to WIFI

The list of IP was twice a long the screen shot shows, probably 50-60 entries

I disconnected the WIFI connection on the device

type or paste code here

AI sourced content may make mistakes

AI sourced content may make mistakes

I did a ARP -a and then ARP -a with the WIFI on. Then the Norton VPN jump on. In the past few days the VPN wouldn’t connect, now it connects very quickly.
ARP -a no WIFI

ARP -a with WIFI & VPN on

  • Windows PC?
  • Laptop?
  • Android?
  • iPhone?
  • Another Windows computer?

To clarify there are 3 Win 11 PCs on the LAN, 1 laptop(on WIFI) received the Norton Spoofing alert and I installed Xarp on a different Win 11 laptop (on WIFI) with showed multiple network IP spoofing attacks, the most common attacks (IP addresses)were on the LT with Xarp, the Gateway and a Firestick. I’ve removed and reinstalled Xarp but it give me an error about no network interface and privileges.
Thank You for all of your advice and feedback

Hello @Edward_Walker

AI sourced content may make mistakes

Arp -a With WIFI & VPN

AI sourced content may make mistakes

I reinstalled Xarp and it seems to be running properly. I shows no attack activity. Given all the great input and evaluations from the Community I’m in agreement that any ARP spoofing attack has been mitigated and no longer a threat to the LAN.
Thank you all for sharing your great knowledge and input to resolve this situation.
I will continue to monitor the ARP in case someone is hiding :slight_smile:

1 Like

Hello @Edward_Walker

AI sourced content may make mistakes