Security Basics mailing list archives

Re: Network sniffing on the wire - managed switches


From: "Jorge L. Vazquez" <jlvazquez825 () gmail com>
Date: Mon, 29 Dec 2008 11:57:47 -0500

Tom Yarrish wrote:
Hey all,
This may come off as somewhat of a newbie question, but it's one I've
been curious about.

When you are doing any sort of pen testing or sniffing on the wire,
how do you handle a managed switch scenario.  If you're connected to a
switch on one port, how can you monitor the traffic on the the other
ports if you're not in a monitor mode?  I've never understood how you
can sniff traffic other than the traffic from your machine to a
destination.

Thanks ahead of time,
Tom

check out "ARP Poisoning", can be done with software like Ettercap,
Cain.... and also "port mirroring" which is supported by any serious
switch manufacturer like CISCO or HP.


Thanks
-JV
www.pctechtips.org


Current thread: