Great Circle Associates Firewalls
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: anti-sniffer warfare - Solution
From: Denis Golubev <dlg @ jet . msk . su>
Date: Mon, 02 Feb 1998 20:23:59 +0300
To: firewalls @ greatcircle . com
In-reply-to: Your message of "Mon, 02 Feb 1998 08:50:07 +0100." <199802020750 . IAA20213 @ julia . ksfw . eur . deuba . com>

> Hi folks,
> 
> 
> I found a very easy way to detect a sniffing computer from remote.
> 
> It's really simple:
> 
> How does an ethernetcard normally work? It takes a look at every
> (ethernet-)frame on the wire and looks for his ethernet-id or the
> broadcast-id. If found, it takes the frame and hands it to the
> next upper layer, f.e. the unix kernel.
> 
> If you craft a packet for a special host, with a *wrong* ethernet
> address, it won't reply - unless it's in promiscious mode!
> 
  Looks fine, but it hardly depend on OS/network interface card.  

[skip]
  
  RS/6000 box with NTX and AIX 4.1.4 doesn't send ARP replies at all 
when NTX is in promiscious mode. 
  Sun/Solaris box with le card has same behavior when le is in
promiscious mode and in normal operating mode. It doesn't replay to
ping with spoofed MAC address.

  So I may cath some of RS/6000 boxes when they are in promiscious mode,
but Suns successfully hide snooping mode from this remote probe.

> 
> 
> 
> Mit freundlichen Gruessen,
> 				Marc Heuse
> 
[skip]

Best regards,

Denis


---------------------------------
Denis Golubev, Moscow, Russia
Jet Infosystems Technical Staff
Phone: (+7 095) 973-48-48	E-mail: dlg @
 jet .
 msk .
 su
Fax:   (+7 095) 973-48-42




References:
Indexed By Date Previous: Firewall Reporting Software
From: Bill Gray <whg @ inel . gov>
Next: Re: Sniffer tools
From: Randy Grimshaw <rgrimsha @ mailbox . syr . edu>
Indexed By Thread Previous: anti-sniffer warfare - Solution
From: Marc Heuse <Marc . Heuse @ mail . DeuBa . COM>
Next: Re: anti-sniffer warfare - Solution
From: Eric Vyncke <evyncke @ cisco . com>

Google
 
Search Internet Search www.greatcircle.com