[VOIPSEC] Actual Attacks
Stauffer Michael
stauffer_michael at bah.com
Sat Feb 26 16:02:57 CST 2005
Many switches support the ability to replicate all the traffic to
another port, see for example "port mirroring" for HP, Cisco, Foundry
Networks, ... switches.
This is true, but this "port spanning" "port mirroring" functionality has to be specifically configured. In an infrastructure where switch components are at least password protected at the priveleged level, sniffing other conversations is not that simple. There used to be gratuitous ARP tricks, and flooding with thousands of fake MACs to get the switch to basically "fail open", but switch manufacturers have added security mechanisms to thwart most of these. Now whether they are utilized or not, that's another matter, but in an infrastructure where at least basic layer 2 security mechanisms are in place, and where the components are password protected, etc, etc, it's really a pain to sniff switced traffic. In the lab, where I have control over the switches, it's really quite easy.
Mike Stauffer
More information about the Voipsec
mailing list