Vulnerability Development mailing list archives

Re: ethernet cards & promisc mode


From: scut () NB IN-BERLIN DE (Sebastian)
Date: Thu, 4 May 2000 22:01:53 +0200


On Thu, May 04, 2000 at 10:30:30AM -0400, Spears, Joseph L. wrote:

If it is such a big deal, buy a switch instead of a fancy card... then all
you get is broadcast traffic...

There are numerous methods to get ANY switch to forward data from other
segments into yours. I've yet not seen any networks that had strict static
ARP tables anywhere and a secure switch. Don't trust your switch, just take
a look at the various ARP relay tools (hunt, arptool, arpraw) or sniffers
that support ARP spoofing (dsniff + tools).

ciao,
scut / teso

--
- scut () nb in-berlin de - http://nb.in-berlin.de/scut/ --- you don't need a --
-- lot of people to be great, you need a few great to be the best ------------
http://3261000594/scut/pgp - 5453 AC95 1E02 FDA7 50D2 A42D 427E 6DEF 745A 8E07
-- data in VK/USA Mayfly experienced, awaiting transfer location, hi echelon -



Current thread: