LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-13-2002, 12:24 PM   #1
jad
LQ Newbie
 
Registered: Aug 2002
Location: lebanon
Distribution: Slack, RedHat,gentoo
Posts: 12

Rep: Reputation: 0
Question How to stop sniffers ??


my lan is full of people runin sniffers watching each other..
just wanted to ask how to stop them or just know who is running them..
:S
hope some one could give me a solution..
NOTE:most of the sniffin is sniffin on irc connections..
 
Old 08-13-2002, 01:00 PM   #2
A-dummy
Member
 
Registered: Jun 2002
Location: Kanpur,India
Distribution: RH-7.0 , 7.3
Posts: 130

Rep: Reputation: 15
I am not sure about this(read sometime back) but if you
send a fake echo message to broadcast with a non-existing
MAC address then only those ip's will response to it which are
in promiscous mode.....how to do it is beyond me ....
 
Old 08-13-2002, 01:12 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
using hunt or rain or nmap? btw, there's also neped.
 
Old 08-13-2002, 02:58 PM   #4
jad
LQ Newbie
 
Registered: Aug 2002
Location: lebanon
Distribution: Slack, RedHat,gentoo
Posts: 12

Original Poster
Rep: Reputation: 0
"While Neped cannot guarantee to discover the sniffer (a sniffer can be a non-Linux machine, a Linux running patched kernel that does not have this flaw or a Linux machine that has ARP disabled), it is useful addition to any security toolbox.??"
any way..
can u give me links ....
 
Old 08-13-2002, 06:23 PM   #5
tyler_durden
Member
 
Registered: May 2001
Posts: 125

Rep: Reputation: 15
there are a couple of ways to try to detect a sniffer. the couple i know of are:
1- send a ping with an non existant MAC but the ip of a host that you think is sniffing (or all the hosts). the sniffer host should reply
2 - (as mentioned) send a non existant MAC on a broadcast ip


there are a few more test, but i can remember.

unfortunaly, there is not guarentee that you can detect it. You can turn off icmp, which would prevent those. Or, you can have a cable that doesn't have the transmit cable hooked up.

the best solution (if you own the network) is to run a switched network. this is a lot safer then you can run something like arpwatch to detect arp spoofing and log bad MAC addresses to detect an mac table flood.
 
Old 08-13-2002, 08:24 PM   #6
tied2
Member
 
Registered: Jun 2002
Location: Florida
Distribution: Redhat, FreeBSD, FC 6
Posts: 220

Rep: Reputation: 30
I think the only way to stop sniffing is using a ssh connection or pgp or some encryption program. For e-mail I know yahoo supports this and I think hotmail does also. I think the next version of gaim is supposed to support encryption also. but the person you im must have the key.
Other than that don't do any thing you don't want sniffed. Or theres always dialup, they would have a hard time finding you.

___________________________________
Don't make me go back, I'd rather marry my ex-wife
 
Old 08-14-2002, 06:16 AM   #7
jad
LQ Newbie
 
Registered: Aug 2002
Location: lebanon
Distribution: Slack, RedHat,gentoo
Posts: 12

Original Poster
Rep: Reputation: 0
Switched lans can be sniffed using ettercap
 
Old 08-14-2002, 08:01 AM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Switched lans can be sniffed using ettercap

... THC also made a switched LAN sniffer (ages ago).
 
Old 08-14-2002, 09:08 AM   #9
tyler_durden
Member
 
Registered: May 2001
Posts: 125

Rep: Reputation: 15
Quote:
Switched lans can be sniffed using ettercap
the two ways to switch a switch are:
1- arp spoof as the gateway, then see all the traffic to the gateway
2- flood the MAC table in the switch which causes it to fail into open mode (like a hub)

the tools you mention use one of these two methods. these can be detected by looking for arp spoofing (arp watch) and looking for bad MACs on the network (ie your sniffer).

And as always, clear text protocols are BAD. But if you have to use irc, there isn't much else you can do.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How do I stop services from restarting after I stop them? M$ISBS Linux - Software 3 10-27-2005 08:13 PM
Ethereal and Kismet wireless sniffers difference powah Linux - Wireless Networking 1 10-08-2005 07:19 AM
IP Tables , sniffers covertops Linux - Newbie 6 03-21-2005 08:40 AM
Http Sniffers leninkoduru Linux - Security 2 01-31-2004 11:31 PM
how to detect sniffers porous Linux - Security 11 01-05-2004 09:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration