Here's a nice writeup that explains why: http://www.sans.org/newlook/resources/IDFAQ/switched_network.htm Clay Fandre [clay at fandre.com] wrote: > Dave Sherohman [esper at sherohman.org] wrote: > > 2) Use switches instead of hubs. You can't sniff a packet that > > doesn't reach your NIC. > > This is totally false. There are many ways to sniff a switched network. arp poisoning and arp-cache flooding are the two most common. Just check out ettercap or dsniff. > > http://ettercap.sourceforge.net/ > http://www.monkey.org/~dugsong/dsniff/ > > > > > _______________________________________________ > tclug-list mailing list > tclug-list at mn-linux.org > https://mailman.mn-linux.org/mailman/listinfo/tclug-list