Re: sniffer

From: chris@nospam.com
Date: 04/18/02


From: chris@nospam.com
Date: Wed, 17 Apr 2002 19:46:20 -0700

On Thu, 18 Apr 2002 00:49:57 +0200, "Grzesiek" <grzes@niepisz.pl>
wrote:

>Hi
>
>I am trying to secure my network against sniffers.
>I have a little OfficeConnect switch but someone told me that is not enough,
>and he can still sniffing my network with any "linux" program.
>Is it posssible ?
>I used my sniffing program under win2k and I received only my own packets.
>Have you ani ideas ?

There are a couple of approaches to sniffing in a switched
environment. The first would be a managed switch which can monitor
ports

There are programs to flood the switch with bogus mac addresses,
causing the switch table to overflow and flood all traffic to all
ports.

Another program can be used to put out bogus arp packets to redirect
ip traffic from the proper mac address to your machine, which then
forwards it to the proper mac address. Tricky, but can be done.

There are programs out there to detect if a machine has it's nic in
promiscious mode. Best bet would be to periodically run a sweep and
penalize anyone caught running a sniffer.

-Chris



Relevant Pages

  • RE: Sniffing
    ... > 1) On a Switched Network can Sniffers capture Network Traffic only for ... > the switch it is connected to switch or for all the switches on the ... Sniffers on a switched network can only capture ... > 2) Can Sniffing be detected using a Network Intrusion Detection System ...
    (Security-Basics)
  • RE: IP address conflicts
    ... If you get a network vendor like Network Hardware Resale ... >> It's amazing how money will appear out of thin air if certain oxen get ... the switch you are suggesting I cannibalise uses the EtherToken ... When dealing with a bureaucracy I have found the most effective method is ...
    (freebsd-questions)
  • Re: ConnectComputer Problem
    ... I'm a little confused by your network configuration. ... Switch2 --- SBS Server ... switch has internet access all the time, the second switch has the client ... NICs ...
    (microsoft.public.windows.server.sbs)
  • Re: Help with long term network problem
    ... Using a CNET network switch connected to a CNet Wireless G router Model ... Having the chart listing all of the computers is a great start. ... /all" shows only an Intel 2200BG WiFi connection - no Ethernet is apparent. ...
    (microsoft.public.windowsxp.network_web)
  • Re: LAN ip subnet is moving off from a bigger enterprise
    ... The host company runs Cisco ... Connect your switch to this ... At the CBO the network is 10.23.1.x and the gateway ... WS1 WS3 SBS HP4000 ...
    (microsoft.public.windows.server.sbs)