* Clay Fandre <clay at fandre.com> [010817 12:51]: > Here's a nice writeup that explains why: > http://www.sans.org/newlook/resources/IDFAQ/switched_network.htm > > This is totally false. There are many ways to sniff a switched network. arp poisoning and arp-cache flooding are the two most common. Just check out ettercap or dsniff. Of course, if you statically assign adresses and dont auto-learn any your safe. :) -- Scott Dier <dieman at ringworld.org> <sdier at debian.org> http://www.ringworld.org/ #linuxos at irc.openprojects.net