|
|||||||||||
|
Re: ARP Poisoning
From: ATD <simon(at)snosoft.com>
Date: Fri Nov 08 2002 - 16:16:28 EST Well, One easy way to ID this is to monitor for the ARP broadcast, or check for hosts doing this broadcast. For example... when using ettercap (one of those nice arp tools) ot does: Building host list for netmask 255.255.255.0, please wait... Sending 7 ARP request... <--- You can detect this. Another thing that you can do is to run checks for other systems doing arp poisoning, ettercap offers this feature as well: [cC] - check for other poisoner... So, one way to defend against this sniffing is to check for these poisoners every X minutes and notify the admin IF such a thing happens.
[Cerebrum Gateway]
ettercap 0.6.7 (c) 2002 ALoR & NaGA Your IP: xxx.xxx.xxx.xxx with MAC: 00:10:4B:C8:2A:4E on Iface: de0 Building host list for netmask 255.255.255.0, please wait... Sending 7 ARP request...
Resolving 5 hostnames...
Checking for poisoners... MAC of xxx.xxx.xxx.xxx and xxx.xxx.xxx.xxx are identical ! you got a poisoner!!! =o)
On Wed, 2002-11-06 at 23:27, Michael Ungar wrote:
-- -ATD- http://www.snosoft.com ------------------------------------------------------------- Secure Network Operations | Strategic Reconnaissance Team Cerebrum Project | cerebrum@snosoft.com -------------------------------------------------------------
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:20 EDT |
||||||||||
|
|||||||||||