Penetration Testing mailing list archives

Re: Cain & Able man in the middle attack


From: Juan B <juanbabi () yahoo com>
Date: Wed, 12 Dec 2007 05:28:15 -0800 (PST)

You can do few things, adding static mac address is
problen to manage those lists,it will make you creazy
tryng to do it. you can do mac locking on the L2
switchs, you can also use arpwatch its for detacting
cards in promisc mode and of course use encrypted
protocols.

hope I helped,

Juan

--- James Bensley <jwbensley () gmail com> wrote:

I too have performed MITM attacks on my network with
Cain & Able. Also
having grabbed a few HTTP and FTP passwords seeing
that it was
successful I now need to secure my self against
these attacks but how
can I do this? Would static MAC mappings in my hosts
files do the
trick?

Thanks for your time
Bensley.


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE
today!

http://www.cenzic.com/downloads

------------------------------------------------------------------------





      ____________________________________________________________________________________
Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile.  Try it now.  http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ 


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: