IDS mailing list archives

Question about a feature of ntop


From: Thomas Kuehling <thomas.kuehling () teka-web de>
Date: Tue, 06 Sep 2005 16:51:52 +0200

Dear all,

as i read in an overwiev-paper (http://ntop.ethereal.com/ntop-overview.pdf) it should be possible to detect NICs in promiscuous mode. Is this correct and how does this work? I don't understand how ntop will detect this only by analyzing the traffic on a gateway for example and not on the local-machine where the NIC is in this mode?

Regards
Thomas Kuehling

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------


Current thread: