• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Sniffers detected on my network - advise ....

frinkofox

Member
OK networking experts i will need all your ideas and i will
welcome any advise that could help me cope with the
situation.
And Here is the situation: I detected two stations which
have their lan-interfaces in promiscuous mode!!!
The first suspect answers icmp packets(echo requests) with mac addresses
beginning with 'FF...' as far as the ip is a match.
The second suspect answers all requests with whatever mac address the
packet has.

But i am not sure whether the stations are really running some sniffing-programs.
How can i be 100% sure that these stations are sniffing the network ?
because I've been told that sometimes even if the station is not running any sniffer
it could reply to a frame with false mac.

Some people told me that this could be a result from the code in the operating system, ?
the virtual mac filter or could have something to do with the vendor specific piece of hardware?

any ideas
thanks
 
as far as i know, if youre on a switched network, it wont matter, since packets only go to the port that requested it...unless they are also arp spoofing.
 
Why don't you go over to their desk after hours and check what software they are running? Turn the promiscious mode off and see if it turns back on.

If it does most likley they are doing it on purpose.

Replace said PC and see if the problem persist.

Reimage said PC and see if the problem persist.
 
I ran some tests in my lab and i found out
that a PC with two nics gives positive results
even if it is not running any sniffers !?

It could be a software bug or a hardware bug - i don't know
the first nic is Cnet and the other is Realtek , ......but the pc tests
positive only from the Realtek nic ?!? what nonsense !?


So I can't be really sure that those PCs are really sniffing the network.

what do you think?



 
Back
Top