Re: sniffer

From: Grzesiek (grzes@lanservice.com.pl)
Date: 04/18/02

  • Next message: chris@nospam.com: "Re: sniffer"

    From: "Grzesiek" <grzes@lanservice.com.pl>
    Date: Thu, 18 Apr 2002 09:43:24 +0200
    
    

    Thanks for your advice,
    but I should protct my network and my clients networks which are larger, and
    I can't be there everyday.
    Can I detect "flood" programs (large network traffic) ?
    Is it possible to set some options in managed switch to protect (VLAN,
    Spanning Tree) ?
    Is any software to protect servers or workstations ?

    Grzesiek

    > There are a couple of approaches to sniffing in a switched
    > environment. The first would be a managed switch which can monitor
    > ports
    >
    > There are programs to flood the switch with bogus mac addresses,
    > causing the switch table to overflow and flood all traffic to all
    > ports.
    >
    > Another program can be used to put out bogus arp packets to redirect
    > ip traffic from the proper mac address to your machine, which then
    > forwards it to the proper mac address. Tricky, but can be done.
    >
    > There are programs out there to detect if a machine has it's nic in
    > promiscious mode. Best bet would be to periodically run a sweep and
    > penalize anyone caught running a sniffer.
    >
    > -Chris



    Relevant Pages

    • Re: Apache Worm / ddos
      ... This is in response to how the worm floods. ... Being a network ... flood and grab a valid MX record in order to flood it with mail. ... > Udp flooding target ...
      (Incidents)
    • Re: Network Flood
      ... zeroes in the network monitoring results made me think of a hardware ... hardware causes except bad cabling. ... Boot another OS on the XP machine and see whether the flood ... Peter R. Fletcher wrote: ...
      (microsoft.public.windowsxp.network_web)
    • Re: How to block unauthorized network connections?
      ... For a managed switch you will also need a certificate server. ... Why go to that trouble and expense such a small 15 user network? ... the laptop is not on the domain in this case. ... have valid accounts to login to the SBS? ...
      (microsoft.public.windows.server.sbs)
    • Re: Network Flood
      ... zeroes in the network monitoring results made me think of a hardware ... hardware causes except bad cabling. ... Boot another OS on the XP machine and see whether the flood ... Repair reinstall of XP. ...
      (microsoft.public.windowsxp.network_web)
    • Re: How to block unauthorized network connections?
      ... I think the managed switch is the best solution overall. ... At least I know that SBS cannot do it ... You only have 15 users on the network. ... the laptop is not on the domain in this case. ...
      (microsoft.public.windows.server.sbs)