I've heard something on this list sometime ago about an ideia of
monitoring the systems in the same bus with snmp. The idea was to check if
the interface was capturing an amount of packets above the normal amount,
but I dont know the details. Maybe the one who had the idea could give an
Antonio Paulo Salgado Forster
Operacoes em Redes - RNP
On Sat, 11 Apr 1998, Frank Willoughby wrote:
> Date: Sat, 11 Apr 1998 17:21:59 -0500
> From: Frank Willoughby <frankw @
> To: Junwen Lai <jwlai @
> Cc: firewalls @
> Subject: Re: How can I detect packet sniffer
> At 04:05 PM 4/11/98 +0800, Junwen Lai allegedly wrote:
> > I am a newer to firewalls, but I want to known how I can detect packet
> >sniffer in an Ethernet LAN, thanks all who would reply this letter.
> Unless you are on the same system as the sniffer, there is no way to detect
> a NIC card running in promiscuous mode on a LAN.
> Best Regards,
> The opinions of the author of this mail may not necessarily be
> representative of the opinions of Fortifed Networks, Inc.
> (c) Fortified Networks, Inc. - http://www.fortified.com/
> Home of the Free Internet Firewall Evaluation Checklist
> Expert (vendor-neutral) Computer and Network Security Solutions
> Phone: (317) 573-0800 Fax: (317) 573-0817