Vulnerability Development mailing list archives

Re: MiM Simultaneous close attack


From: "Korhan Kaya" <kkaya () prioriy1world com>
Date: Sat, 18 Aug 2001 01:55:50 +0300



Excuse my ignorance, but wouldn't a switched network be a remedy for this
attack?  Unless you are using some type of 'port mirroring' functionality
(at the switch) the attacking computer sitting in promiscuous mode would
only hear broadcast traffic.  Right? Or am I missing something?



Hi ,

In theory, you cannot do this in a switched-hub network.  In practice,
attacker can use numerous methots like Switch jamming , ARP Redirecting ,
ICMP Redirecting , Switch Jamming  listen network traffic in a switched-hub
envronment. (for more info : see
http://www.robertgraham.com/pubs/sniffing-faq.html ). Also attacker can
affect local host to trigger a network flood.

Regards

Korhan Kaya




Current thread: