Penetration Testing mailing list archives

Re: [PEN-TEST] Spoofing switched networks


From: "shawn . moyer" <shawn () net-connect net>
Date: Tue, 6 Feb 2001 18:49:45 -0600

Sam Quigley wrote:

Because they can, sometimes, be made to fail open.  Then, everything
is on one big LAN, and standard switch sniffing methods can reveal
all the network traffic.

-sq

I know that Dug Song's macoffr tool and a few others will cause older
Nortel and some other older switches to "fail open" and more or less
behave like a hub once the mac table is full, but I haven't ever been
able to produce this across VLAN's (say across multiple Baystacks or
Catalysts). Do you have any docs on this?


--shawn

--
s h a w n   m o y e r
shawn () net-connect net


Current thread: