Re: switch jamming

From: Sebastian Jaenicke (tsa@jaenicke.org)
Date: 01/30/02


Date: Wed, 30 Jan 2002 23:13:14 +0100
From: Sebastian Jaenicke <tsa@jaenicke.org>
To: vuln-dev@securityfocus.com


Hi,

On Wed, Jan 30, 2002 at 10:05:08PM +0000, Jan wrote:
[..]
> how can i sniff upon a switched network segment ? a read some articles about "switch jamming" and "port mirroring" but up to know i didn't learn anything special at all.
> ca some of your guys out there help me ? (i'm sure some of you can but are you willing, too ?)
>

This can be achieved by flooding the switch with spoofed ARP packets until
its internal MAC table is filled up - most switches will then revert to
"hub mode" and therefore broadcast all traffic to the network where it
can easily be sniffed.

http://www.sans.org/newlook/resources/IDFAQ/switched_network.htm should
give you some (more accurate?) information.

Sebastian

-- 
Sebastian Jaenicke
whois pgpkey-18AC0BE4@whois.ripe.net|perl -ne's-^certif: +--&&print'
  "Object-oriented programming is an exceptionally bad idea which
   could only have originated in California." --Edsger Dijkstra  




Relevant Pages

  • Re: if_bridge interface confuses Windows Small Business Server 2000
    ... Don't worry about flooding the switch with VNC. ... over a 33.6 modem from my mac to a win2k3 server. ...
    (freebsd-questions)
  • Re: Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... If you have administrator rights on a switch you ... is an arp spoofing attack which, using spoofed arp packets, makes all ...
    (Security-Basics)
  • Re: Intermittent Connection to NLB Servers
    ... > We have them plugged into a hub to prevent flooding the switch. ... need the servers to talk to each other so I'm using unicast. ...
    (microsoft.public.windows.server.clustering)
  • [Full-disclosure] KArp update
    ... (for bi-directional MiM) ... Flooding the switch with random MAC addresses is ...
    (Full-Disclosure)
  • Re: Sniffing a Switched Network
    ... > Other ways, which may not be as safe technically, is to flood the switch ... > with spoofed arp packets thus making the switch lose track of who is who ... > start acting in a hub fashion. ... like and has detailed information on it, ...
    (Security-Basics)