North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: sniffer/promisc detector

  • From: Damian Gerow
  • Date: Fri Jan 16 18:54:40 2004

Thus spake Gerald ([email protected]) [16/01/04 18:32]:
> Subject says it all. Someone asked the other day here for sniffers. Any
> progress or suggestions for programs that detect cards in promisc mode or
> sniffing traffic?

There's an art to detecting promiscuous devices.[1]  A good starting point
is Google, and the phrase 'promiscuous detect'.  IIRC, L0pht once produced
something that claimed to detect all promiscuous devices on a network, I
never got it to work properly.

  - Damian

[1] general consensus is that most well-written OSes are near impossible to
detect, some older ones have various methods of detection, usually involving
either broadcast traffic or timing.