Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Ask them “honestly, what is the problem” – other than having an interface in promiscuous mode is a signature of a sniffer and security folks look for unauthorized sniffers?

0
Posted

Ask them “honestly, what is the problem” – other than having an interface in promiscuous mode is a signature of a sniffer and security folks look for unauthorized sniffers?

0

ntop needs promiscuous mode so that it sees the full range of traffic. Any similar product will do the same thing. If the security people think traffic on the wire is secure, they’re wrong! Face facts – just about every Windows user, except for 2K/XP Pro (and then only if TBTP have especially locked them down) can install the windows version of tcpdump… If it’s a checklist item, just gen up a form to “authorize” it, have the boss and VP/CIO sign it and give it to them.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123