3 ms·
Virtually no modern wired networks use hubs anymore, they're for the most part switched. Unlike wireless networks where packets are broadcast freely in to the a
by azim 16y ago
Virtually no modern wired networks use hubs anymore, they're for the most part switched. Unlike wireless networks where packets are broadcast freely in to the air, the switch checks the destination address and sends the packets only to the endpoint. There are some attacks like arp-spoofing and flooding which can defeat this, but they don't work well against modern enterprise-grade switches like you would find in a data center.
- petercooper 16y agoHave a bazillion karma points. I didn't realize that switching resolved that whole problem. This is why I continue to bring up stupid hypothetical situations on HN from time to time ;-)
- iuguy 16y agoSwitching doesn't resolve the problem completely. There are a range of complicated attacks that could be done, but can be detected in various ways in a well run NOC.
- petercooper 16y agoBut we're talking a lot more complicated and deliberate than running tcpdump or this Firefox plugin, right?
- iuguy 16y agoI guess if you really wanted to you could run a GUI tool like Cain (http://oxid.it/ http://oxid.it/), but most people doing this type of thing would use something like Scapy or at worst, Yersinia. So I'd agree, more complex definitely, significantly not as much perhaps (it depends on the type of attack as tool), as for deliberation I'd say about the same as the firefox plugin. If you do run tcpdump you do pick up broadcasts and such, one of our VPS instances actually sees a load of DNS traffic for our subnet, which we think is the other VPS instances.