★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/network_security_article-4551.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Network Security 3/5/2002 18:35

SwitchSniff

LinuxJournal
Posted By: Pete O'Hara
3/5/2002

For those who think switched Ethernet environments are sniff-proof, the author offers this warning. Switches may be difficult to sniff, but they are certainly not immune. As is clear from the above sections, one method of sniffing in a switched environment is using ARP spoofing, and the machine that will most probably be ARP spoofed is the gateway. One thing that can be done is to add the MAC address of the gateway permanently to your ARP cache. This can be done by giving the -s flag to the arp command. Read more about this on the arp man page. Alternatively, you could use the /etc/ethers file for placing the MAC addresses of the important machines to prevent spoofing of those machines.


Click here to go to this article.
U.S. to Curb Computer Access by Foreigners
Mar 7

Blinking Lights: The Newest Hack
Mar 7

Want To Back Up Your PC? Ask Disney's Permission
Mar 7

OpenSSH Local User Privilege Escalation Vulnerability
Mar 7

Hacking made easy
Mar 7

Wireless: In the Air Tonight
Mar 7

Drive-by hackings a myth?
Mar 7

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000