Is promiscuous mode bad?

Siddhartha Jain sid at netmagicsolutions.com
Mon Aug 16 07:33:16 PDT 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

JJB wrote:

| Promiscuous mode can also be enabled on most hardware routers. A
| hardware router in front of a private network with promiscuous mode
| enabled allows public internet users to access (sniff) all the
| traffic passing through the router as well as insert packets. This
| is major security leak and one that spoofers look for.
|

I am curious, how do you do that? From what I understand, a promiscous
mode allows someone on the box to see all packets that hit the
interface. How does it allow an attacker (outside the box) to sniff
packets hitting that interface?

Thanks,

- --
Siddhartha Jain (CISSP)
Consulting Engineer
Netmagic Solutions Pvt Ltd
Bombay - 400063
Phone: +91-22-26850001 Ext.128
Fax  : +91-22-26850002
http://www.netmagicsolutions.com



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFBIMWrOGaxOP7knVwRAj1nAJ9Ae+5APNi4YgeSNwxMkrv7jwUbjQCeLftp
8BIhFJfN9b5S2xUTDctKcuI=
=bt2X
-----END PGP SIGNATURE-----


More information about the freebsd-questions mailing list