NYCPHP Meetup

NYPHP.org

[nycphp-talk] Basic security question

Mitch Pirtle mitchy at spacemonkeylabs.com
Wed Jul 14 17:17:17 EDT 2004


John Lacey wrote:

> Mitch Pirtle wrote:
>
>> The swiss-army knife of scanners seems to be NMAP, with Nessus good 
>> for purty reports and ethereal for snooping.  My favorite is 
>> ettercap, an evil tool that enables you to poison a switch, therefore 
>> seeing the rest of the traffic on that segment (that you weren't 
>> supposed to see).  I got a great security story about that if anyone 
>> is interested off-line.  ;)
>>
> ahh... poisoning the switch's ARP cache... now I see


Yep, and it is pretty rude as the only way to returnthe network to 
normal operations is to reset the switch.  Only use in emergency!

-- Mitch



More information about the talk mailing list