Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: sniffer detection on switched based networks

From: Brett Harris <bsdbrett(at)yahoo.com.au>
Date: Wed Feb 05 2003 - 20:00:23 EST


Hi Sangram,

arpwatch [ http://online.securityfocus.com/tools/142 ] keeps a database of IP/ARP pairings and generates logs or emails reporting any changes. That way if a machine running arpwatch is spoofed, the logs know about it.

Since arpwatch is completely passive (only inspecting packets, not transmitting any), it won't clog your network up with any extra packets.

Many operating systems can be told to ignore changes to their ARP cache, so attempting to spoof that machine fails, because it won't accept the new MAC address.

ettercap [ http://ettercap.sourceforge.net/ ] is a program that makes arpspoofing mindlessly simple. Its worth checking out, just to see what wouldbe badguy's can use. Ettercap have forums on their page which sometimes deal with topics of detection/prevention etc.

I'm not aware of much else that can be done to detect such attacks, particularly passively.

Hope this was some help

regards

Do you need help?X

Brett
bmh.youth-it.com

> As we know sniffing on swithch based networks is not

http://movies.yahoo.com.au - Yahoo! Movies - What's on at your local cinema? Received on Thu Feb 6 12:58:04 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:09 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library