Jump to content

A doubt on the Port Promiscuous?


GuzmanDiaz18

Recommended Posts

I have a question and I'm entering the world of Networking audit, I have a question, I installed OSSIM and configured one of the interfaces as promiscuous mode, it is now also the SWITCH must also have a configuration for Promiscuous Port, or only connect to the last port of the Switch.

:) Greetings from PERU

Link to comment
Share on other sites

If you want to sniff all traffic on a network then you need to either put a port on the switch into mirror mode, this means all traffic going over the switch also gets spat out of that port. Which physical port you can do it on depends on the switch, some have dedicated ports for it, some you can set it on any.

The other option is to drop the device in a key part of the network that all traffic flows over and have it bridge all traffic so it can see everything.

Link to comment
Share on other sites

A switch is smart and will only send traffic to a port if the destination device is on that port so you won't see the traffic. The only way you can see it is to use a hub or put yourself inline somehow to watch the device you want to monitor.

Link to comment
Share on other sites

If its not a high end switch with port mirroring(which is designed for this sort of thing), you need an inline lan tap or as mentioned a hub, sans going all MITM attack on someone. Only problem with a hub, is you then run into security issues giving everyone on the hub access to everyone else's data, and also cause broadcast storms, which, is why we today use switches to minimize bottlenecks and keep the network up.

MITM works fine over wireless, but not so well on wired networks, and really not the best way to get the data you're probably after. No ability for port mirroring, invest in high end lan taps.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...