Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: packet logs
From: crow!rik () uunet UU NET (Rik Farrow)
Date: Mon, 22 Nov 93 16:37:47 MST


I have been playing with netstat, trying to see if it can detect something
unusual when a process is listening promiscously.  There is nothing I could
see.  However, when you use ifconfig, you WILL see the PROMISC flag:

crow% ifconfig le0
le0: flags=163<UP,BROADCAST,NOTRAILERS,RUNNING,PROMISC>
        inet 192.26.58.254 netmask ffffff00 broadcast 192.26.58.0
crow% []

So there is a way to see if someone (at least on Suns where the attacks have
been occurring) has a listening daemon set up.

rik () uworld com



  By Date           By Thread  

Current thread:
  • Re: packet logs Rik Farrow (Nov 22)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]