LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-06-2004, 11:56 PM   #1
Yohhan
LQ Newbie
 
Registered: Dec 2002
Posts: 28

Rep: Reputation: 15
Problems with packet sniffing in promiscuous mode


Hi,
I'm trying to run Snort in promiscious mode, however it's not working properly. I only see packets destined to and from the machine running snort, and not network traffic.
I've tried on both Fedora, Redhat, and Windows. On the Linux systems, I set the appropriate interface to promiscuous mode using: ifconfig eth0 promisc

The interface shows up in promiscuous mode, but when I run snort, or any other packet sniffer such as ethereal or tcpdump, I see only broadcasts and packets directed to the machine in question -- no other traffic. Can anyone give me some direction on this? I'm not sure what to try next. All machines are behind a $10 linksys 5 port hub.
 
Old 05-07-2004, 05:59 AM   #2
loop0
LQ Newbie
 
Registered: May 2004
Posts: 1

Rep: Reputation: 0
Hi Yohhan,

Is the Linksys device a switch? If so, only traffic destined for a certain computer's IP or broadcast will be seen by that computer.

You can monitor switched traffic by fooling the other computers & the switch; see http://monkey.org/~dugsong/dsniff/

~ loop0
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
wlan promiscuous mode paulr1984 Linux - Wireless Networking 0 05-13-2005 09:52 AM
Promiscuous Mode: Yes or No? AvatarofVirgo Linux - Security 3 02-22-2005 07:22 PM
Packet sniffing question. _TK_ Linux - Security 6 09-04-2003 09:14 AM
url packet sniffing? nibjb Linux - Networking 1 09-01-2003 09:34 PM
Setting up a sniffing environment to loot at packet transfered from my windows comp? Shurikn Linux - General 9 04-22-2003 02:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration