Active sniffing
Active sniffing involves some sort of action done by a penetration tester, such as redirecting user traffic to another gateway for the purpose of monitoring and capturing the packets on the network. A penetration tester may perform an ARP cache-poisoning attack on a victim’s machine by modifying the IP-MAC entries in the ARP table.
Flooding bogus MAC addressing into a switch will cause a CAM Table overflow, causing the switch to flood all incoming traffic out of all other ports.
Also, installing a Rogue DHCP Sever on the network provides clients with a nonlegitimate default gateway and DNS Server. The victim's traffic will be redirected to potentially malicious websites, and their traffic may be intercepted.
The penetration ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access