An unusual way for your DHCP server to run out of dynamic IPs
utcc.utoronto.ca
utcc.utoronto.ca
That…ever get resolved?
Also, minor nitpick:
> Without that we would have been reduced to tracing through switch ARP tables (for switches smart enough to report that)
You'd only need your switch to have a viewable mac address table rather than an ARP table.
Could be some funnyman trying to reimplement ettercap.
It will make your dhcp server mad, too.
Not much to do about that if you're not using managed switches. With managed switches, maybe you can spend an unreasonable amount of effort to try to prevent it, or you can just deal with it if it happens. Probably the 'right' way is to give each port its own broadcast domain and subnet, then it's pretty hard to mess up the other clients.
The wikipedia page even has a bit about this.
https://en.wikipedia.org/wiki/Promiscuous_mode
>As promiscuous mode can be used in a malicious way to capture private data in transit on a network, computer security professionals might be interested in detecting network devices that are in promiscuous mode. In promiscuous mode, some software might send responses to frames even though they were addressed to another machine.
The most interesting thing I remember looking at was a tool called Neped. I can't find the source but it might be here: https://www.apostols.org/projects. As I recall, Neped would do things exactly like this article says — send an ping packet to the right IP address but wrong MAC address and see if it responds. I probably have the details wrong but that's the idea. It was some really clever stuff. I always wonder what old vulnerabilities like this we would rediscover if we put new computers on old networks (especially hubs).