atom feed200 messages in org.freebsd.freebsd-securityRe: Detecting sniffers (was: Re: secu...
FromSent OnAttachments
45 earlier messages
Robert WatsonJul 28, 1997 1:54 pm 
Nate WilliamsJul 28, 1997 2:00 pm 
Ollivier RobertJul 28, 1997 2:07 pm 
Matthew N. DoddJul 28, 1997 2:14 pm 
Karl DenningerJul 28, 1997 2:42 pm 
Vincent PoyJul 28, 1997 2:43 pm 
Vincent PoyJul 28, 1997 3:01 pm 
Vincent PoyJul 28, 1997 3:06 pm 
Jordan K. HubbardJul 28, 1997 3:10 pm 
Vincent PoyJul 28, 1997 3:25 pm 
Vincent PoyJul 28, 1997 3:28 pm 
Matthew N. DoddJul 28, 1997 3:30 pm 
Vincent PoyJul 28, 1997 3:30 pm 
Vincent PoyJul 28, 1997 3:44 pm 
Brian BuchananJul 28, 1997 4:06 pm 
Gary Clark IIJul 28, 1997 4:06 pm 
Vincent PoyJul 28, 1997 4:14 pm 
Vincent PoyJul 28, 1997 4:16 pm 
Vincent PoyJul 28, 1997 4:18 pm 
Matthew N. DoddJul 28, 1997 4:18 pm 
Vincent PoyJul 28, 1997 4:19 pm 
Vincent PoyJul 28, 1997 4:25 pm 
Vincent PoyJul 28, 1997 4:30 pm 
Brian BuchananJul 28, 1997 4:48 pm 
Jordan K. HubbardJul 28, 1997 4:59 pm 
Jordan K. HubbardJul 28, 1997 5:00 pm 
Vincent PoyJul 28, 1997 5:02 pm 
Brian BuchananJul 28, 1997 5:09 pm 
Vincent PoyJul 28, 1997 5:19 pm 
Vincent PoyJul 28, 1997 5:20 pm 
Gary PalmerJul 28, 1997 5:22 pm 
Vincent PoyJul 28, 1997 5:26 pm 
Vincent PoyJul 28, 1997 5:30 pm 
Gary PalmerJul 28, 1997 5:30 pm 
Brian BuchananJul 28, 1997 5:32 pm 
Gary PalmerJul 28, 1997 5:33 pm 
Vincent PoyJul 28, 1997 5:34 pm 
Gary PalmerJul 28, 1997 5:36 pm 
Vincent PoyJul 28, 1997 5:40 pm 
Gary PalmerJul 28, 1997 5:44 pm 
Gary PalmerJul 28, 1997 5:45 pm 
Vincent PoyJul 28, 1997 5:49 pm 
Gary PalmerJul 28, 1997 5:53 pm 
Vincent PoyJul 28, 1997 5:57 pm 
Vincent PoyJul 28, 1997 6:01 pm 
Vincent PoyJul 28, 1997 6:01 pm 
Brian BuchananJul 28, 1997 6:19 pm 
Brian BuchananJul 28, 1997 6:24 pm 
Matthew N. DoddJul 28, 1997 6:41 pm 
Robert WatsonJul 28, 1997 6:59 pm 
Robert WatsonJul 28, 1997 7:00 pm 
Vincent PoyJul 28, 1997 7:01 pm 
Vincent PoyJul 28, 1997 7:04 pm 
Matthew N. DoddJul 28, 1997 7:19 pm 
John PreislerJul 28, 1997 7:31 pm 
Brian BuchananJul 28, 1997 7:52 pm 
John DowdalJul 28, 1997 8:29 pm 
Annelise AndersonJul 28, 1997 8:41 pm 
Nate WilliamsJul 28, 1997 9:09 pm 
Vincent PoyJul 28, 1997 9:12 pm 
Vincent PoyJul 28, 1997 9:15 pm 
Vincent PoyJul 28, 1997 9:19 pm 
Heikki SuonsivuJul 28, 1997 9:33 pm 
Jan KoumJul 28, 1997 9:39 pm 
Vincent PoyJul 28, 1997 9:49 pm 
Jordan K. HubbardJul 28, 1997 10:05 pm 
Vincent PoyJul 28, 1997 10:14 pm 
Gary PalmerJul 28, 1997 10:27 pm 
Gary PalmerJul 28, 1997 10:28 pm 
Vincent PoyJul 28, 1997 10:35 pm 
Vincent PoyJul 28, 1997 10:37 pm 
John-David ChildsJul 28, 1997 10:38 pm 
Gary PalmerJul 28, 1997 10:40 pm 
Vincent PoyJul 28, 1997 10:44 pm 
Gary PalmerJul 28, 1997 10:50 pm 
Vincent PoyJul 28, 1997 10:55 pm 
Jordan K. HubbardJul 28, 1997 10:59 pm 
Vincent PoyJul 28, 1997 11:01 pm 
Jordan K. HubbardJul 28, 1997 11:07 pm 
Jordan K. HubbardJul 28, 1997 11:11 pm 
Jordan K. HubbardJul 28, 1997 11:16 pm 
Sergei S. LaskavyJul 29, 1997 12:13 am 
John-David ChildsJul 29, 1997 2:09 am 
NarviJul 29, 1997 2:48 am 
Stephen D. SpencerJul 29, 1997 3:43 am 
Robert WatsonJul 29, 1997 5:32 am 
Adam ShostackJul 29, 1997 5:49 am 
Robert WatsonJul 29, 1997 6:39 am 
Nate WilliamsJul 29, 1997 7:19 am 
Rodney W. GrimesJul 29, 1997 8:58 am 
Warner LoshJul 29, 1997 9:25 am 
Warner LoshJul 29, 1997 9:34 am 
Christopher PetrilliJul 29, 1997 9:52 am 
Jim ShanklandJul 29, 1997 9:57 am 
John DowdalJul 29, 1997 10:50 am 
Poul-Henning KampJul 29, 1997 12:05 pm 
Bill PechterJul 29, 1997 12:29 pm 
Matthew HuntJul 29, 1997 12:37 pm 
Christopher PetrilliJul 29, 1997 12:43 pm 
[Mario1-]Jul 29, 1997 1:07 pm 
55 later messages
Subject:Re: Detecting sniffers (was: Re: security hole in FreeBSD)
From:Robert Watson (rob@cyrus.watson.org)
Date:Jul 28, 1997 6:59:18 pm
List:org.freebsd.freebsd-security

On Mon, 28 Jul 1997, Brian Buchanan wrote:

On Mon, 28 Jul 1997, Nicole H. wrote:

Does anyone know of a good way to detect people "sniffing" on the network? IE a
program that will detect a machine running in promiscuous mode?

I was wondering the same thing when I read a clause prohibiting the use of network cards in promiscuous mode in the CMU network use policy. I asked some computer security people I knew about this and their response was that it is not possible to detect if a network card is in promiscious mode unless you have access to the machine it's in - i.e., that you can look at ifconfig on that machine.

As far as I know, there is no way to tell. The card has a filter on it that normal just doesn't provide the packets that aren't intended for the host. Promiscuous mode simply disables the filter. The only way to prevent the packets from being sniffable is to prevent them from going on the wire in question -- smart hubs (switches) do this, so are desirable. They also increase available bandwidth, as only the required traffic goes on a segment. They're also more expensive, although prices are really dropping.

Robert N Watson

Junior, Logic+Computation, Carnegie Mellon University http://www.cmu.edu/ Network Security Research, Trusted Information Systems http://www.tis.com/ Network Administrator, SafePort Network Services http://www.safeport.com/ rob@fledge.watson.org rwat@tis.com http://www.watson.org/~robert/