RE: arpspoofing

From: Lee Brotherston (lee.brotherston@uk.easynet.net)
Date: 02/08/02


From: Lee Brotherston <lee.brotherston@uk.easynet.net>
To: "'Erlend J. Leiknes'" <nookie@online.no>, pen-test@securityfocus.com
Date: Fri, 8 Feb 2002 17:33:44 -0000 


| Any other ways to sniff in a switched enviorment?

There are a couple of other ways to sniff traffic on a switched network
assuming you have physical access to network:

- Alot of switches these days have the option of configuring a mirror port.
This port get's duplicates of traffics from all other ports. So you can see
everything. This port does get the aggregate of the others remember, so it
will be high bandwidth.

- You could place a machine on the networks' uplink running in bridging
mode. Doing this you will only see traffic that is going over the uplink
however, as local traffic will be sent via the switch only, and will not
touch the uplink. And you have the downside of causing an outage when you
install/remove the machine.

Thanks

  Lee

-- 
Lee Brotherston  -  IP Security Manager, Easynet Ltd
http://www.easynet.net/         Phone: +44 20 7900 4444

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • RE: arpspoofing
    ... Not sure if this has been covered but a network tap could also be ... installed between the inbound or outbound traffic and the switch. ... This port get's duplicates of traffics from all other ports. ... This list is provided by the SecurityFocus Security Intelligence ...
    (Pen-Test)
  • Re: Single domain two IP subnets
    ... hardware or any of the complexities of "network hardward ... I never criticize anyone's typing as long as the words can ... Cisco ISL VLANS are history. ... Newer Cisco switches don't even support ISL ...
    (microsoft.public.win2000.dns)
  • Re: Statistical Anomaly Analysis?
    ... If you set up your model to account for each event type as a part of the ... the aggregation of traffics should smooth the ... > key, events that were 6-sigma outliers for a small network, and hence ... > likewise has an immense amount of variability; but its bulk statistics ...
    (Focus-IDS)
  • Re: new switching technologies
    ... mixed with stackable switches. ... i havent used these kit versions, but this is maybe the 5th or 6th iteration ... of a fix looking for a problem for L2 network resilience / load balancing. ... optimal one is what routing protocols were designed for and what they are ...
    (comp.dcom.lans.ethernet)
  • Re: SunRay 2FS MTU
    ... What type of switches and network cards are you using? ... Cisco 6509 with 100Mb modules running fiber to the SunRay MTRJ ports. ... Check that switches and Suns/Sun Ray are all using 100FDX (typically ... your switch needs to be able to buffer sufficent packets. ...
    (comp.sys.sun.admin)