Mac flooding attack, unicast and sniffer

Hi all

happy new year to all members of support forums!

If I am not mistaken in a switched environment a crowd will see all unicast (addressed directly to her), broadcast (in the same VLAN) and multicast frames (when membership in the multicast group).

Now consider that I run a MAC flooding attack on the switch in question. It fills the entire MAC table (8,000, 16,000 entries, no matter). Now, host A wants to connect to B (both on the same switch, same VLAN). Host A has the host host b MAC address in its arp table. A sends the packet, it happens on the switch (he learn not the port that the host is turned on, because the cam table is full), but he'll find no MAC address of host B as well (I know, it may be present, but assume that it is not). So because the host has the MAC address of host B I know more of that host A sends a unicast frame on. So the switch inspects its CAM table looking for MAC of host B and "said" I don't know where host B is, so let me send the frame / packet to all ports. Even if he she will send to all ports, it's still a unicast. Now, my question is (if all the foregoing is correct). When I run a sniffer on host c (connected to the same switch, even VLAN) will be able to see the package? Or do I have to activate the "Promiscuous" inside Wireshark mode?

Thank you in advance!

BR

Adam

Hi Adam,.

But in the case of broadcast frames each host on the same VLAN saw, correct? Or should I always turn the promisc mode?

I guess you always ask the subject of sniffing and Wireshark. In this case, diffusion frames would be visible in Wireshark whatever the promisc mode setting.

So the frame comes with mac dest FF:FF:FF:FF:FF value and each host leans on the chassis, then the network layer and all hosts (but not the one with the IP address in question) drop the fames / package. OK, so I guess I'd still have active promisc

What you have described is a product of correct treatment of a broadcast frame including its load by the driver for the CARD and the driver of the intellectual property. However, Wireshark works at a fairly low level: it binds relatively close to the driver for the CARD. Each image that is received by a NETWORK card and handed over to the operating system for further processing is also copied in Wireshark. So even if the IP driver can know that the IP packet is for someone else, and he falls, Wireshark will nevertheless show the frame. The trick is in getting the NETWORK adapter to accept the framework in the first place. If the framework is to broadcast, the NETWORK adapter will accept it automatically. If the setting is unicast/multicast and you still want your NIC to accept it even if it is not planned for this particular NETWORK interface card, you must use promisc mode.

Please feel welcome to ask for more!

Best regards
Peter

Tags: Cisco Network

Similar Questions

Maybe you are looking for

  • Routing of analog triggers seizure through RTSI in MATLAB software

    Hello I want to trigger a framegrabber PCI-1424, when a certain threshold is reached to the analog input of my PCI-6259 DAQ card channel by using the corresponding toolboxes in MATLAB. Is it possible to get a software trigger located in the analog of

  • Can I have XP and Windows 8 in the computer?

    I have both windows xp and windows8 operating system in my system. If I can't do that is the best version of windows 7 or windows 8, as I put it on level of windows xp please answer me quickly and clearly Original title: windows xp for windows8

  • Do not re-Smartphones blackBerry my Torch 9800

    Finishing the installation of an application from Deloitte school my camera intend to reset but it never, because when 75%, it starts rebooting again, and so on. I don't know what to do. I intended to recharge the BB device software by using the BB d

  • Case of Smartphones Blackberry blackBerry for the curve

    It is beyond my understanding that there is no decent Holster for blackberry curve case. Yes blackberry offers one, but it shows a weird sense of ergonomics. My main objection to the closure of blackberry Holster case is the device is on the outside.

  • We cannot install Lightroom

    I bought the program, but I can not install. What should I do?