[TOOL] PromiscDetect, Windows Based Promiscuous Mode Detector

From: support@securiteam.com
Date: 04/17/02


From: support@securiteam.com
To: list@securiteam.com
Date: Wed, 17 Apr 2002 15:31:58 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  PromiscDetect, Windows Based Promiscuous Mode Detector
------------------------------------------------------------------------

DETAILS

 <http://ntsecurity.nu/toolbox/promiscdetect/> PromiscDetect checks if
your network adapter(s) is running in promiscuous mode, which may be a
sign that you have a sniffer running on your computer.

Q: What would be the response for an adapter in "normal" mode?
A: It would be the filters Directed, Multicast, and Broadcast.

Q: When I double-click on the client file, a window comes up and
disappears immediately. What is wrong?
A: You must run the file from a Command Prompt.

Q: How reliable is this tool?
A: It is reliable as long as the attacker does not intercept and modify
things somewhere between the tool and the adapter. Look at it this way: if
the tool tells you that, the adapter is in promiscuous mode it probably is
- but if it does not you should not just assume that the adapter is not in
promiscuous mode.

Q: My adapter is in promiscuous mode but there is no sniffer in my
computer. What is wrong?
A: For example, VMWare puts your adapter in promiscuous mode even if you
are not running a sniffer.

ADDITIONAL INFORMATION

The tool can be downloaded from:
 <http://ntsecurity.nu/cgi-bin/download/promiscdetect.exe.pl>
http://ntsecurity.nu/cgi-bin/download/promiscdetect.exe.pl

The information has been provided by <mailto:arne.vidstrom@NTSECURITY.NU>
Arne Vidstrom.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Continuing wireless printer problems.
    ... following link was for ver 3.1 but ver 3.3 has the same functionality. ... That the Windows Logo Kit 1.0c has released. ... if the logo kit actually tests for promiscuous mode functionality. ... My ZD1211 USB adapter hangs when I try to go into Monitor Mode, Promiscuous, and says adapter busy. ...
    (alt.internet.wireless)
  • Re: put nic into promisquous mode
    ... Be aware that even if your adapter support promiscuous mode and set only if ... you have hub connected lan you'll receive all other host packets, ... >> Can anyone tell me how to configure a NIC or its NDIS ... > adapters are an example of an adapter that does not support promiscuous ...
    (microsoft.public.development.device.drivers)
  • RE: sniffer in promiscuous mode
    ... Subject: sniffer in promiscuous mode ... traffic from one port to another) so the port with the sniffer gets copies ... Is there something else I have to do to capture TCP packets? ...
    (Security-Basics)
  • Re: Detect a sniffer ?
    ... I heard once that a NIC in promiscuous mode has a hardware address of ... look it up in DHCP or in your documentation ... I also believe that the sniffer that comes with SMS has a ... > detect if a user is running a packet sniffer on my network? ...
    (microsoft.public.security)
  • Announcing PromiscDetect
    ... that checks if your network adapteris in promiscuous mode or not (that ... is, in most cases, if a sniffer is running on the computer or not). ... You can find other freeware security tools and more at our site: ...
    (NT-Bugtraq)

Quantcast