network sniffing detection

network sniffing detection

Post by Ivan Cap » Tue, 14 Sep 1999 04:00:00



Is there any program that could detect network is being sniffed. It simply
comes to detecting promiscuous mode of the card, but how to do it? I have
heard that it is done with the right IP address but wrong MAC address.
Something similar has ben developed by <URL:"http://www.l0pht.com">, but for
Win32, Solaris and BSD platforms. Are there any Linux solutions.

--
  Your mouse has moved. Windows NT must be restarted for the change
  to take effect. Reboot now?  [ OK ]

 
 
 

network sniffing detection

Post by Jeff Keen » Tue, 14 Sep 1999 04:00:00


The only way you could detect the sniffer is if he injected packets
back on the wire.  Otherwise he is just recieving and invisible.


Quote:

>Is there any program that could detect network is being sniffed. It simply
>comes to detecting promiscuous mode of the card, but how to do it? I have
>heard that it is done with the right IP address but wrong MAC address.
>Something similar has ben developed by <URL:"http://www.l0pht.com">, but for
>Win32, Solaris and BSD platforms. Are there any Linux solutions.

>--
>  Your mouse has moved. Windows NT must be restarted for the change
>  to take effect. Reboot now?  [ OK ]


 
 
 

network sniffing detection

Post by Vilmos Sot » Wed, 15 Sep 1999 04:00:00



> Is there any program that could detect network is being sniffed. It simply
> comes to detecting promiscuous mode of the card, but how to do it? I have
> heard that it is done with the right IP address but wrong MAC address.
> Something similar has ben developed by <URL:"http://www.l0pht.com">, but for
> Win32, Solaris and BSD platforms. Are there any Linux solutions.

Hi,

There is a program called neped.c which does this. Look for this
filename on ftpsearch.

Vilmos

 
 
 

1. Can I sniff network packets over switched network ?

No -- the switch will only pass broadcast packets and unicast packets
addressed to the local MAC...

-Tom
--
Tom Eastep             \  Eastep's First Principle of Computing:
ICQ #60745924           \  "Any sane computer will tell you how it

Shoreline, Washington USA \___________________________________________

2. Help LPR setup

3. cannot open mouse: invalid arguement... HELP *sniff sniff*

4. Mail Surrogate

5. sniff sniff...I smell fire

6. PPP connection through a TribeLink 8

7. network sniffing for security

8. Recursive Mutex Problem

9. network sniffing

10. PD Software to sniff SNA packets on the network

11. looking for software to sniff network

12. Network sniffing

13. sniffing on my network