Juha Laiho wrote:
>
> Ian Northeast <(E-Mail Removed)> said:
> >Yes, that is the problem, the switch doesn't send non broadcast packets
> >from machine A which are not destined for machine B to machine B.
> ...
> >If you used a hub instead it would indeed work as you expect.
>
> Of course, assuming that this is the OP's private home LAN (as he
> did say in the original posting), it should be possible to "collapse"
> the switch into a hub with certain attacks. After this, the snooping
> should succeed just fine (supposing that the switch collapses in
> a predictable manner, instead of crashing completely).
A bit of a drastic method of traffic snooping on the part of the
legitimate network administrator don't you think?
I'm not sure exactly what the OP is trying to do but I would be
surprised if there wasn't a better way to achieve it than that.
I once needed to capture all LAN traffic to and from a couple of
machines without using them, as I couldn't trust what they were
reporting themselves. The problem turned out to be dodgy daughter boards
that the NICs were plugged into. On this occasion I removed the problem
machines from the switch and put a hub in, and attached a sniffer to the
hub. Performance wasn't an issue as they weren't working properly in the
first place.
Regards, Ian