Bradley Smith wrote:
> I used to do something very basic for this. There are several code
> snippets available to get interface values (i.e. cpm, ifstatus). I'd run
> these from cron, mail results to file, tail file with swatch and look for
> a lexical string indicating the interface was in prom (sp) mode.
> If the status code returned indicated a "sniffer," I'd mail the results to
> my pager and shut the interface down. You could get even more creative
> than this with netstats, reverse finger, etc..
This is fine for unix machines which you have administative control
over, but what about a rogue PC notebook running DataGlance or LANAlyzer
inserted into your Ethernet network somewhere on the wire? Also keep in
mind some NICs are custom built to not broadcast the fact that they are
in promiscuous mode. The only way to detect something like this would be
to physically check each interface connected to your network.