Score:0

Ubuntu tcdump and AlertLogic attack notifications "Device entering promiscuous mode detected on IP ADDRESS" problem

es flag

We've been getting notification from AlertLogic (AL) about our Ubuntu 20.04.5 LTS out of the box linux instance entering "Promiscuous mode". I have checked both linux network interfaces 'ip -d link' and they're set to 'promiscuity 0' as well as VMWare ESXI host configuration that's hosting the linux instance has all network interfaces :Promiscuous mode" set to Reject. The AL is stating:

Attack Summary

Discovery / Network Sniffing

Attack Detail:
Device entering Promiscuous mode on interface ethF

Hostname: DEVICE NAME
The local host at IP_ADDRESS has been detected entering promiscuous mode. When a device interface enters promiscuous mode it captures all packets traversing the network segment the device interface is connected to Thus any sensitive data (user names, passwords etc) traversing the network that is not being sent encrypted can be captured. Whilst this activity is associated with troubleshooting by administrators (using tools like
"tepdump" and "wireshark"), it can also be indicative of unauthorised activity and should be investigated.

There is absolutely no software that would enable this mode on network interfaces as this is an out of the box Ubuntu instance running some shell scripts that never touch tcdump or wireshark. However, I notic in /etc/passwd file a user:

tcpdump:x:REMOVED:REMOVED::/nonexistent:/usr/sbin/nologin

I have also checked only one user that has super user but never run this command. Does anyone know if Ubuntu uses tcpdump in the background, when and for what reason?

webcoder.co.uk avatar
es flag
I can now see in /var/log/syslog: Mar 27 09:01:54 device_name kernel: [1124505.425932] device eth1 entered promiscuous mode - why is it going into this mode by itself?
Score:0
es flag

I think the problem might have resolved itself and can't see any entries about entering promiscuous mode in /var/log/syslog after upgrading Ubuntu 20.04 LTS to 22.04 LTS but will keep checking and update if things change.

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.