Sniffing and Evasion

Basic Knowledge

Protocols Susceptible

ARP

IPv6

IPv6 Address Type Description
Unicast Addressed and intended for one host interface
Multicast Addressed for multiple host interfaces
Anycast Large number of hosts can receive; nearest host opens
IPv6 Scopes Description
Link local Applies only to hosts on the same subnet (Address block fe80::/10)
Site local Applies to hosts within the same organization (Address block FEC0::/10)
Global Includes everything

Wiretapping

Active and Passive Sniffing

MAC Flooding

ARP Poisoning

DHCP Starvation

Spoofing

Sniffing Tools

Devices To Evade

Evasion Techniques

Firewall Evasion

Honeypots