Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] sniffing in a switched network - arp spoofing using ettercap an

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Manu Garg <manugarg@xxxxxxxxx>
Date: Thu, 16 Jun 2005 19:31:25 -0400
Many of us know that sniffing is possible in a shared i.e.
non-switched ethernet environment. But only few of us know that
sniffing is also possible in a switched ethernet environment. One of
the reasons is that it's not that straighforward. But it's not
impossible or difficult. You can use man in the middle technique like
ARP spoofing to sniff in a switched environment.


This presentation is an attempt to explain how can somebody sniff in a
switched ethernet using ARP spoofing. Dsniff has existed for long as a
tool for various sniffing activities. But recently, tools like
EttercapNG have made it easier.


Link to my original post and presentation -
http://manugarg.freezope.org/2005/06/sniffing-in-switched-network-many-of.html

Presentation-
http://manugarg.freezope.org/notes/arp_spoofing

Please let me know your views on it.

enjoy!
manu
_________ 
Manu Garg
http://manugarg.freezope.org
"Truth will set you free!"