Re: Sniffing
From: Devilscrow Sr (devilscrow_at_gawab.com)
Date: 12/15/03
- Previous message: Agent 837: "Re: Web Filter software for linux"
- In reply to: Shah H (Comp): "Sniffing"
- Next in thread: Zachary Mutrux: "RE: Sniffing"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 16 Dec 2003 02:13:42 +0530 To: "Shah H (Comp)" <03004309@glam.ac.uk>
Hi,
Comments inline.....
Shah H (Comp) wrote:
>1) On a Switched Network can Sniffers capture Network Traffic only for
>the switch it is connected to switch or for all the switches on the
>network?
>
>
Yes you can capture traffic on your switch, but if you use conventional
sniffers then you would receive only what is sent to you, unless you are
using technologies like span / port mirror etc. The other way to sniff
on your switch would be to use tools like dsniff / ettercap etc. These
tools use cache poisoning techniques to get their way thru. To read more
.... google is you friend.
>2) Can Sniffing be detected using a Network Intrusion Detection System
>and if yes then are there any Sniffing ways which are not detected by
>NDIS?
>
>
Yes sinffing can be detected. Well evading detection would mean sniffing
with your adapter running normally (!= promiscuous)
-dev
---------------------------------------------------------------------------
----------------------------------------------------------------------------
- Previous message: Agent 837: "Re: Web Filter software for linux"
- In reply to: Shah H (Comp): "Sniffing"
- Next in thread: Zachary Mutrux: "RE: Sniffing"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|