[Sunhelp] About snoop

John Lee johnlee at sc23.sc.mcel.mot.com
Mon Oct 16 05:21:16 CDT 2000


Erik,

Could you show me how to arp redirects for a host to my own machine ? If I
do arp redirects for a host A, Does it mean the host A will not receive the
packets which should destinate to it ?

Thanks.
John

-----Original Message-----
From: sunhelp-admin at sunhelp.org [mailto:sunhelp-admin at sunhelp.org]On
Behalf Of Erik Parker
Sent: Monday, October 16, 2000 3:50 PM
To: sunhelp at sunhelp.org
Subject: RE: [Sunhelp] About snoop



This is not actually accurate, there are ways to snoop/sniff switched
networks. Not that one would want to do this on their own production
network, however you can easily do arp redirects for a host to your own
machine to see those packets.

You can also flood switches with millions of mac addresses, which in some
cases, will drop the switch into a "hub" like mode.

These ideas can both be demonstrated by dsniff.

On Mon, 16 Oct 2000, John Lee wrote:

> Hello,
>
> Thanks for all your help. I know the limitation is due to the switched
> network not snoop tool.
> I really appreciate all your help.
>
> Regards.
> John
>
> -----Original Message-----
> From: sunhelp-admin at sunhelp.org [mailto:sunhelp-admin at sunhelp.org]On
> Behalf Of Martin Wedel sr
> Sent: Friday, October 13, 2000 2:22 PM
> To: sunhelp at sunhelp.org
> Subject: Re: [Sunhelp] About snoop
>
>
> The 'problem' doesn't lie within the sniffer. The whole idea behind
> switched networks is that traffic is directed only to the segment where
> the destination node is located, no more no less, save broadcast, ARP, etc
> etc. No sniffer can get past this, as it can't 'sniff' what it can't
> see.
>   If you are doing this for a legitimate reason, I suggest using a
> mirrored port on the switch for your NIDS/analyzer box.
>
> --
> Martin Wedel
> sun at minor-element.net
> http://www.minor-element.net/
>
> On Fri, 13 Oct 2000, John Lee wrote:





Erik Parker
Mind Security

An armed society, is a polite society.

_______________________________________________
SunHELP maillist  -  SunHELP at sunhelp.org
http://www.sunhelp.org/mailman/listinfo/sunhelp






More information about the SunHELP mailing list