Re: Network Penetration Test

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 01/09/03


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Wed, 8 Jan 2003 21:46:17 -0500


Some real-world attacks might involve installing a sniffer after the attack,
to continue collecting data.

At any rate, a switched network will NOT prevent sniffing. There are a
variety of trivial ways a hacker can sniff on a switched network.

"S. Pidgorny [MVP]" <slavickp@yahoo.com> wrote in message
news:O7z$03itCHA.2540@TK2MSFTNGP10...
> Most attacks nowadays involve proactive probes rather than network
sniffing.
> I might be terribly wrong though :(



Relevant Pages

  • Re: Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... You have to mirror all the traffic to one mirror port where your sniffer ... I've tried tcpdump on Redhat, ...
    (Security-Basics)
  • Re: Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... send spoofed arp packets will change the other host arp ... changed to other end (poisoned arp cache) there can be one 'pseudo' proxy ...
    (Security-Basics)
  • RE: Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... port monitoring) and running a packet capture program (ones that have ... I've tried tcpdump on Redhat, ...
    (Security-Basics)
  • Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... I seem to be getting conflicting information about sniffing network traffic ... Redhat box on a hub with the Redhat box sniffing all traffic to and from ...
    (Security-Basics)
  • RE: Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... Two ways to sniff a switched network: Using a spanport on a ... to the destination port. ...
    (Security-Basics)