This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

how to counterscan a system capturing your packets

0

if wireshark cannot, what software can?

asked 16 May '12, 01:38

wiresharkhelpers's gravatar image

wiresharkhel...
309913
accept rate: 0%

edited 16 May '12, 01:39


One Answer:

1

You can't detect a sniffer if it is listening to traffic passively (on a switch mirror/span/monitor port or a TAP), as it will not interact with the network.

You may be able to detect hosts on your local network, that are running their interfaces in promiscuous mode (or using ARP tricks). Search google for: "detect a sniffer on network".

There are several papers that describe some methods, however they are all not very reliable.

Regards
Kurt

answered 16 May '12, 01:41

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 16 May '12, 01:45