Re: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618

From: Mitch Pirtle (mitchell.pirtle_at_verizon.net)
Date: 06/26/03

  • Next message: David Wallraff: "Re: AW: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 6 18"
    To: David Wallraff <wall0448@ece.umn.edu>
    Date: 26 Jun 2003 12:58:30 -0400
    
    

    On Wed, 2003-06-25 at 11:32, David Wallraff wrote:
    > why is it harder to sniff over a switced network? i understand it's
    > becasue of the switch (natch), but what makes it more difficult?

    <short_answer>
    Because when you fire up ettercap to look around, you now have to poison
    the switch* first.
    </short_answer>

    * Disclaimer: poisoning switches degrades network performance. After
    the switch has been poisoned, it will have to be initialized to return
    to normal. Please remember to clean up before you leave!

    ---------------------------------------------------------------------------
    Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
    The Gartner Group just put Neoteris in the top of its Magic Quadrant,
    while InStat has confirmed Neoteris as the leader in marketshare.
         
    Find out why, and see how you can get plug-n-play secure remote access in
    about an hour, with no client, server changes, or ongoing maintenance.
              
    Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
    ----------------------------------------------------------------------------


  • Next message: David Wallraff: "Re: AW: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 6 18"

    Relevant Pages

    • Re: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618
      ... >why is it harder to sniff over a switced network? ... Because a hub sends all traffic to all ports, a switch only sends traffic ... You'd be missing all the traffic on the other ports. ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
      (Security-Basics)
    • RE: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618
      ... a switched network will only ... out through the switch to collect packets sent to other ports. ... >> The Gartner Group just put Neoteris in the top of its Magic ... >> about an hour, with no client, server changes, or ongoing ...
      (Security-Basics)
    • Re: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618
      ... port, if it has one. ... That machine would then be able to see all traffic on the switch. ... > Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ... > about an hour, with no client, server changes, or ongoing maintenance. ...
      (Security-Basics)
    • Re: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618
      ... A *switch* otoh, ... keeps a list of what hardware addresses may be found at what port. ... >> Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ... >> about an hour, with no client, server changes, or ongoing maintenance. ...
      (Security-Basics)
    • RE: network segment range which NIDS can detect?
      ... the default action if it can't be sure of a specific port to ... True broadcast packets ... I installed snort NIDS at my linux which connected at switch and I ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
      (Security-Basics)