RE: Detecting Network Sniffers ???

From: Sutton, Nathan (nathan.sutton_at_hp.com)
Date: 05/26/04

  • Next message: Brecrost Jones: "RE: possibly compromised redhat 7.2 box"
    Date: Wed, 26 May 2004 09:36:23 +1000
    To: "Jonny Boy" <jonny@de21comp.net>, <security-basics@securityfocus.com>
    
    

    Hi Jonny,

    I am a network security person but not yet an expert in this field so
    you may wish to seek clarification on my point below.

    In sniffer must put the network card attached to the network in
    promiscuous mode. The presence of a network card in promiscuous mode is
    what you must be looking for. Some IDS's can actually detect this.

    Have a look at

    http://www.securiteam.com/unixfocus/Detecting_sniffers_on_your_network.h
    tml

    That will set you on the path to finding other ways of detecting
    sniffers on you network.

    Regards,

    Nathan Sutton (cissp)
    Security and Technology consultant
    Global Delivery
    Hewlett Packard Australia

    -----Original Message-----
    From: Jonny Boy [mailto:jonny@de21comp.net]
    Sent: Saturday, 22 May 2004 3:08 PM
    To: security-basics@securityfocus.com
    Subject: Detecting Network Sniffers ???

    Hello!

    Can somebody guide me on detecting a sniffer on my network. can i still
    detect a sniffer even if the computer running the sniffer has disabled
    the
    TCP/IP stack or decompiled it altogether from the kernel. can i somehow
    go
    onto the datalink layer and use 802.3 protocol to test for the presence
    of
    the sniffer.

    Thankyou.

    Jonny

    ------------------------------------------------------------------------

    ---
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
    off 
    any course! All of our class sizes are guaranteed to be 10 students or
    less 
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of
    in-the-field 
    pen testing experience in our state of the art hacking lab. Master the
    skills 
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
    any course! All of our class sizes are guaranteed to be 10 students or less 
    to facilitate one-on-one interaction with one of our expert instructors. 
    Attend a course taught by an expert instructor with years of in-the-field 
    pen testing experience in our state of the art hacking lab. Master the skills 
    of an Ethical Hacker to better assess the security of your organization. 
    Visit us at: 
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------
    

  • Next message: Brecrost Jones: "RE: possibly compromised redhat 7.2 box"

    Relevant Pages

    • Re: Firewall and IDS, (the second way).
      ... There's only two ways of detecting an IDS that I know. ... Look for the data stream from a remote sensor (sniffer) to wherever ... a network card usually discards ethernet ... This also isn't very useful for remote sniffer detection. ...
      (Vuln-Dev)
    • Re: Counter detect Network Sniffer
      ... > Is there any method to detect one using sniffer, ... Astaro Security Linux -- firewall with Spam/Virus Protection ... Protect your network with the comprehensive security solution that integrates ...
      (Focus-IDS)
    • Re: 802.11b coverage in industrial plants
      ... >>> typically allow operation of a handheld device such as a Wifi capable ... Define your security, with the IT, ... >>I went to a free class by Fluke on their new network sniffer. ...
      (sci.engr.control)
    • Re: packet sniffing help needed.
      ... In order to sniff traffic between the two victims, ... the sniffer on the same physical network. ... can take between the two to reliably try sniffing. ...
      (Security-Basics)
    • Re: [inbox] Re: Counter detect Network Sniffer
      ... > to communicate with the sniffing system. ... It is not difficult to devise a sniffer detection ... Protect your network against hackers, viruses, spam and other risks with Astaro ... Security Linux, the comprehensive security solution that combines six ...
      (Focus-IDS)