|
|||||||||||
|
Re: sniffer detection on switched based networks
From: Brett Harris <bsdbrett(at)yahoo.com.au>
Date: Wed Feb 05 2003 - 20:00:23 EST
arpwatch [ http://online.securityfocus.com/tools/142 ] keeps a database of IP/ARP pairings and generates logs or emails reporting any changes. That way if a machine running arpwatch is spoofed, the logs know about it. Since arpwatch is completely passive (only inspecting packets, not transmitting any), it won't clog your network up with any extra packets. Many operating systems can be told to ignore changes to their ARP cache, so attempting to spoof that machine fails, because it won't accept the new MAC address. ettercap [ http://ettercap.sourceforge.net/ ] is a program that makes arpspoofing mindlessly simple. Its worth checking out, just to see what wouldbe badguy's can use. Ettercap have forums on their page which sometimes deal with topics of detection/prevention etc. I'm not aware of much else that can be done to detect such attacks, particularly passively. Hope this was some help regards
Brett
> As we know sniffing on swithch based networks is not
http://movies.yahoo.com.au - Yahoo! Movies - What's on at your local cinema? Received on Thu Feb 6 12:58:04 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:09 EDT |
||||||||||
|
|||||||||||