Here's a nice writeup that explains why:
http://www.sans.org/newlook/resources/IDFAQ/switched_network.htm

Clay Fandre [clay at fandre.com] wrote:
> Dave Sherohman [esper at sherohman.org] wrote:
> > 2)  Use switches instead of hubs.  You can't sniff a packet that
> > doesn't reach your NIC.
> 
> This is totally false. There are many ways to sniff a switched network. arp poisoning and arp-cache flooding are the two most common. Just check out ettercap or dsniff. 
> 
> http://ettercap.sourceforge.net/
> http://www.monkey.org/~dugsong/dsniff/
> 
> 
> 
> 
> _______________________________________________
> tclug-list mailing list
> tclug-list at mn-linux.org
> https://mailman.mn-linux.org/mailman/listinfo/tclug-list