Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Re[2]: Network ethernet sniffer
From: Ben <adept @ cep . yale . edu>
Date: Thu, 27 Jun 1996 11:45:08 -0400 (EDT)
To: Brian Murrell <Brian_Murrell @ bctel . net>
Cc: gunni @ if . is, firewalls @ GreatCircle . COM
In-reply-to: <199606271424 . HAA18193 @ mocha . bctel . net>

> Oh really.  I can have a machine on my network go out and find out which
> other adapters are in promiscuous mode??  I rather doubt it, but tell me
> more.  What if I have a card constructed to avoid this detection??

Assuming a not very cunning atacker, I believe arpwatch will be able to 
query the local network for items in promiscuous mode.  I say 'I believe' 
because I have my notes in a box somewhere...

If you have a card constructed to avoid noting that itis in promiscuous 
mode then of course it won't work.

Ben.
____
Ben Samman .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
  .
 samman @
 cs .
 yale .
 edu
"Si ce que dit Proust est vrai, a savoir que le bonheur est l'absence de
passion, alors je ne connaitrai jamais, le bonheur.  Car je suis habite
par la passion de la connaissance, de l'experience et de la creation."
				--Anias Nin




References:
Indexed By Date Previous: Re[2]: Network ethernet sniffer
From: Brian Murrell <Brian_Murrell @ bctel . net>
Next: Re: How good is "stateful inspection"? (fwd)
From: "Ronald L. Sharp" <rls @ neptune . att . com>
Indexed By Thread Previous: Re[2]: Network ethernet sniffer
From: Brian Murrell <Brian_Murrell @ bctel . net>
Next: Re: Network ethernet sniffer
From: gunni @ if . is (Gunnar Ingvi Thorisson)

Google
 
Search Internet Search www.greatcircle.com