Firewall Wizards mailing list archives

Re: ifconfig down (was Re: Recording slow scans


From: Doug Hughes <doug () Eng Auburn EDU>
Date: Sat, 10 Oct 1998 11:39:24 -0500 (CDT)

On Thu, 8 Oct 1998, Rob Quinn wrote:

Btw, in the past people have often commented about attempts to cut the
transmit ethernet cable.  This is usually so that a host is "invisible"
to others at the ethernet level.

 On my Solaris2.6 boxs I can still snoop an interface when it's marked
down. Is ifconfig down sufficient to stop me from transmitting?

It will stop your machine from answering. That is, it won't answer
ARP requests or pings, or anything. However, I strongly suspect that
if you can read (snoop) then you could easily fashion a program that
could write raw packets out DLPI without a problem.


____________________________________________________________________________
Doug Hughes                                     Engineering Network Services
System/Net Admin                                Auburn University
                        doug () eng auburn edu



Current thread: