Re: Network sniffing on the wire - managed switches



Tom Yarrish wrote:
Hey all,
This may come off as somewhat of a newbie question, but it's one I've
been curious about.

When you are doing any sort of pen testing or sniffing on the wire,
how do you handle a managed switch scenario. If you're connected to a
switch on one port, how can you monitor the traffic on the the other
ports if you're not in a monitor mode? I've never understood how you
can sniff traffic other than the traffic from your machine to a
destination.

Thanks ahead of time,
Tom

check out "ARP Poisoning", can be done with software like Ettercap,
Cain.... and also "port mirroring" which is supported by any serious
switch manufacturer like CISCO or HP.


Thanks
-JV
www.pctechtips.org



Relevant Pages

  • RE: Network sniffing on the wire - managed switches
    ... That's what mirror mode or span mode (different switch vendors call it ... Network sniffing on the wire - managed switches ... switch on one port, how can you monitor the traffic on the the other ... ports if you're not in a monitor mode? ...
    (Security-Basics)
  • Re: Network sniffing on the wire - managed switches
    ... that you could flood the switch with MAC addresses, ... one port, how can you monitor the traffic on the the other ports if you're ... not in a monitor mode? ... first ARP poison the entire network to think you're the ...
    (Security-Basics)
  • Re: Network sniffing on the wire - managed switches
    ... that you could flood the switch with MAC addresses, ... arp table. ... one port, how can you monitor the traffic on the the other ports if you're ... not in a monitor mode? ...
    (Security-Basics)
  • Re: Running cable to wireless setup question:
    ... Can I get some sort of connector to connect the two ... an built in switch and all you need to do is to connect your second ... uplink port on the switch if it has one, ...
    (alt.internet.wireless)
  • Re: Cat 2924
    ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
    (comp.dcom.sys.cisco)

Quantcast