atom feed200 messages in org.freebsd.freebsd-securityRe: Detecting sniffers (was: Re: secu...
FromSent OnAttachments
88 earlier messages
Vincent PoyJul 28, 1997 5:57 pm 
Vincent PoyJul 28, 1997 6:01 pm 
Vincent PoyJul 28, 1997 6:01 pm 
Brian BuchananJul 28, 1997 6:19 pm 
Brian BuchananJul 28, 1997 6:24 pm 
Matthew N. DoddJul 28, 1997 6:41 pm 
Robert WatsonJul 28, 1997 6:59 pm 
Robert WatsonJul 28, 1997 7:00 pm 
Vincent PoyJul 28, 1997 7:01 pm 
Vincent PoyJul 28, 1997 7:04 pm 
Matthew N. DoddJul 28, 1997 7:19 pm 
John PreislerJul 28, 1997 7:31 pm 
Brian BuchananJul 28, 1997 7:52 pm 
John DowdalJul 28, 1997 8:29 pm 
Annelise AndersonJul 28, 1997 8:41 pm 
Nate WilliamsJul 28, 1997 9:09 pm 
Vincent PoyJul 28, 1997 9:12 pm 
Vincent PoyJul 28, 1997 9:15 pm 
Vincent PoyJul 28, 1997 9:19 pm 
Heikki SuonsivuJul 28, 1997 9:33 pm 
Jan KoumJul 28, 1997 9:39 pm 
Vincent PoyJul 28, 1997 9:49 pm 
Jordan K. HubbardJul 28, 1997 10:05 pm 
Vincent PoyJul 28, 1997 10:14 pm 
Gary PalmerJul 28, 1997 10:27 pm 
Gary PalmerJul 28, 1997 10:28 pm 
Vincent PoyJul 28, 1997 10:35 pm 
Vincent PoyJul 28, 1997 10:37 pm 
John-David ChildsJul 28, 1997 10:38 pm 
Gary PalmerJul 28, 1997 10:40 pm 
Vincent PoyJul 28, 1997 10:44 pm 
Gary PalmerJul 28, 1997 10:50 pm 
Vincent PoyJul 28, 1997 10:55 pm 
Jordan K. HubbardJul 28, 1997 10:59 pm 
Vincent PoyJul 28, 1997 11:01 pm 
Jordan K. HubbardJul 28, 1997 11:07 pm 
Jordan K. HubbardJul 28, 1997 11:11 pm 
Jordan K. HubbardJul 28, 1997 11:16 pm 
Sergei S. LaskavyJul 29, 1997 12:13 am 
John-David ChildsJul 29, 1997 2:09 am 
NarviJul 29, 1997 2:48 am 
Stephen D. SpencerJul 29, 1997 3:43 am 
Robert WatsonJul 29, 1997 5:32 am 
Adam ShostackJul 29, 1997 5:49 am 
Robert WatsonJul 29, 1997 6:39 am 
Nate WilliamsJul 29, 1997 7:19 am 
Rodney W. GrimesJul 29, 1997 8:58 am 
Warner LoshJul 29, 1997 9:25 am 
Warner LoshJul 29, 1997 9:34 am 
Christopher PetrilliJul 29, 1997 9:52 am 
Jim ShanklandJul 29, 1997 9:57 am 
John DowdalJul 29, 1997 10:50 am 
Poul-Henning KampJul 29, 1997 12:05 pm 
Bill PechterJul 29, 1997 12:29 pm 
Matthew HuntJul 29, 1997 12:37 pm 
Christopher PetrilliJul 29, 1997 12:43 pm 
[Mario1-]Jul 29, 1997 1:07 pm 
Garrett WollmanJul 29, 1997 1:07 pm 
[Mario1-]Jul 29, 1997 1:14 pm 
sth...@nethelp.noJul 29, 1997 1:39 pm 
Jordan K. HubbardJul 29, 1997 2:23 pm 
Vincent PoyJul 29, 1997 2:45 pm 
Vincent PoyJul 29, 1997 2:57 pm 
Vincent PoyJul 29, 1997 3:02 pm 
sth...@nethelp.noJul 29, 1997 3:30 pm 
Rocco LuciaJul 29, 1997 3:33 pm 
Vincent PoyJul 29, 1997 3:44 pm 
Aaron BornsteinJul 29, 1997 3:44 pm 
Vincent PoyJul 29, 1997 3:54 pm 
Vincent PoyJul 29, 1997 4:00 pm 
Jay D. NelsonJul 29, 1997 5:29 pm 
Adam ShostackJul 29, 1997 6:06 pm 
Gary SchrockJul 29, 1997 6:10 pm 
Adam ShostackJul 29, 1997 6:11 pm 
Michael SmithJul 29, 1997 6:54 pm 
Jay D. NelsonJul 29, 1997 7:58 pm 
Jay D. NelsonJul 29, 1997 8:10 pm 
Michael SmithJul 29, 1997 8:25 pm 
Marco MolteniJul 30, 1997 5:04 am 
James SengJul 30, 1997 5:31 am 
Alex G. BulushevJul 30, 1997 5:59 am 
Vincent PoyJul 30, 1997 6:45 am 
Robert WatsonJul 30, 1997 7:03 am 
Nate WilliamsJul 30, 1997 7:48 am 
Vincent PoyJul 30, 1997 7:54 am 
Nate WilliamsJul 30, 1997 8:06 am 
Nate WilliamsJul 30, 1997 8:13 am 
Vincent PoyJul 30, 1997 8:28 am 
Vincent PoyJul 30, 1997 8:33 am 
zoonieJul 30, 1997 9:09 am 
Poul-Henning KampJul 30, 1997 9:25 am 
Poul-Henning KampJul 30, 1997 9:31 am 
John-David ChildsJul 30, 1997 10:17 am 
Ian KallenJul 30, 1997 10:37 am 
Patrick GilbertJul 30, 1997 11:43 am 
Jay D. NelsonJul 30, 1997 1:52 pm 
[Mario1-]Jul 30, 1997 2:06 pm 
Jordan K. HubbardJul 30, 1997 3:53 pm 
Jordan K. HubbardJul 30, 1997 4:04 pm 
yossmanJul 30, 1997 4:20 pm 
12 later messages
Subject:Re: Detecting sniffers (was: Re: security hole in FreeBSD)
From:Christopher Petrilli (petr@amber.org)
Date:Jul 29, 1997 9:52:17 am
List:org.freebsd.freebsd-security

On Tue, 29 Jul 1997, Warner Losh wrote:

In message <Pine@cyrus.watson.org> Robert
Watson writes: : host. Promiscuous mode simply disables the filter. The only way to : prevent the packets from being sniffable is to prevent them from going on : the wire in question -- smart hubs (switches) do this, so are desirable.

Well, there is strong encryption. While it doesn't prevent sniff of the packets, per se, it generally leaves you with garbage and produces the same net effect.

I will note that there are a few people (ODS and Bay Networks included) who make what is called "secure Ethernet", which basically learns what MAC address is on each port, and scrambles frames that are not destined for that MAC. What usually happens is it replkaces the data paylode with alternating 0/1, and fixes the checksum. It works just fine :-) It's also generally cheaper than a switch.

Christopher