RE: [Possible SPAM] - Re: [cisco-ttl] sniffing - Email found in subject

From: Serhat Uslay (serhat.uslay_at_zurich.com.au)
Date: Thu Mar 24 2005 - 01:15:09 EET


benim anladigim kadari ile port security arp broadcast'i engellemez.. O
belirtilen mac adresi broadcast almaga devam eder...
ARP attack leri onlemek icin port security ise yarar ama brodcast'i hala
gorursunuz..(???) bunu test etmem lazim lab'da..

Please respond to cisco-ttl_at_yahoogroups.com

To: <cisco-ttl_at_yahoogroups.com>
cc:
Subject: RE: [Possible SPAM] - Re: [cisco-ttl] sniffing - Email
found in subject

Selamlar,

Her port için tek tek mac adres girmek zorunda değilsiniz, hub veya switch
bağlı olmayan portlarda "port security" komutunu kullanırsanız

Her port için ilk gönderilen packetten mac adresini kendisi tutacaktır

Sniffing tabanlı saldırılar ve savunma yöntemleri için şu dökümanları
inceleyebilirsiniz:

http://www.packetwatch.net/documents/papers/layer2sniffing.pdf

http://www.packetwatch.net/documents/papers/snifferdetection.pdf

selamlar,

Enis Karaarslan

_____

From: Oguzhan Kayhan [mailto:oguzhan.kayhan_at_barmek.az]
Sent: Wednesday, March 23, 2005 7:48 AM
To: cisco-ttl_at_yahoogroups.com
Subject: RE: [Possible SPAM] - Re: [cisco-ttl] sniffing - Email found in
subject

Pardon..

Elimdeki bir demo yazilimdi. Sadece hangi ipleri duydugunu soyluyordu.

Baska bir program ile baktigimda duyduklarimin sadece netbios-ns udp
paketleri oldugunu gordum.

Destinationlari broadcast ipsi oldugu icin duymam dogal sanirim.

Peki soyle birsey sorayim. Arp sniffingi engelleyebilmek icin ne gibi bir
yontem izleyebilirim?

Her port icin arp bilgisini static olarak vermek biraz zahmetli bir cozum
olacak cunku.

Daha basit bir yontemi varmi?

Tesekkurler.

_____

From: Serhat Uslay [mailto:serhat.uslay_at_zurich.com.au]
Sent: Wednesday, March 23, 2005 3:32 AM
To: cisco-ttl_at_yahoogroups.com
Subject: [Possible SPAM] - Re: [cisco-ttl] sniffing - Email found in
subject

Selamlar,
Yani "port span" komutu yazmadan mi herhangi bir porttan diger trafigi
gorebiliyorsun ? Biraz acarmisin ?
Bu ancak 3 sekilde mumkun olabilir;
1) Eger network'de asimetrik routing varsa, yani switch gelen trafigi
nereye yollayacagini bilemiyorsa butun portlara yollar..
Icinde birden fazla NIC olan PC var mi? Varsa bunlardaki IP config bak..
2) Belki bir yerde switche hub baglanmistir ?
3) Multicasting traffik varsa ve switch bunu nereye yollayacagini
bilmiyorsa butun portlara yollar..

cevabini bekliyorum..

Serhat

Please respond to cisco-ttl_at_yahoogroups.com

To: <cisco-ttl_at_yahoogroups.com>
cc:
Subject: [cisco-ttl] sniffing

Selamlar.

Sirketimizde tum switchler cisco 2950.

Ancak su anki configim ile (default ayarlar ustunde herhangi bir
degisiklik yapmadim) bu switch ustunden diger portlari
sniffleyebiliyorum.

Bunu engellemek icin switchlerde configte neyi degistirmem lazim.

Bilgi verebilirseniz tesekkurler.

--------------------------------------------------------------------------

DISCLAIMER: By opening this e-mail you hereby acknowledge that all
information given in this e-mail by Barmek Azerbaijan Electricity Network
LLC and/or by companies which it owns, controls and/or is affiliated with
(altogether Barmek) is confidential and you agree that you will treat it
as confidential and will not disclose or release it to any third party or
not use it without the prior written consent of Barmek; and you agree that
any failure to fullfill above-mentioned requirements will create a serious
breach of ethics and law, and you will be responsible for all direct
and/or indirect damages/losses and any other consequences that Barmek will
encounter.

[Non-text portions of this message have been removed]

--

Bu listenin Cisco Systems ile herhangi bir baglantisi bulunmamaktadir.

Listede onerilen cozumlerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar.

Listeden cikmak için cisco-ttl-unsubscribe_at_yahoogroups.com adresine bir e-posta gönderebilirsiniz. Yahoo! Groups Links

---- This email is intended for the named recipient only. It may contain information which is confidential, commercially sensitive, or copyright. If you are not the intended recipient you must not reproduce or distribute any part of the email, disclose its contents, or take any action in reliance. If you have received this email in error, please contact the sender and delete the message. It is your responsibility to scan this email and any attachments for viruses and other defects. To the extent permitted by law, Zurich and its associates will not be liable for any loss or damage arising in any way from this communication including any file attachments. We may monitor email you send to us, either as a reply to this email or any email you send to us, to confirm our systems are protected and for compliance with company policies. Although we take reasonable precautions to protect the confidentiality of our email systems, we do not warrant the confidentiality or security of email or attachments we receive.

[Non-text portions of this message have been removed]

--

Bu listenin Cisco Systems ile herhangi bir baglantisi bulunmamaktadir.

Listede onerilen cozumlerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar.

Listeden cikmak için cisco-ttl-unsubscribe_at_yahoogroups.com adresine bir e-posta gönderebilirsiniz.

Yahoo! Groups Sponsor

ADVERTISEMENT click here < http://us.ard.yahoo.com/SIG=129a5fidv/M=298184.6191685.7192823.3001176/D=gr

oups/S=1705004726:HM/EXP=1111620715/A=2593423/R=0/SIG=11el9gslf/*http:/www.n etflix.com/Default?mqso=60190075>

< http://us.adserver.yahoo.com/l?M=298184.6191685.7192823.3001176/D=groups/S=

:HM/A=2593423/rand=823007709>

_____

Yahoo! Groups Links

* To visit your group on the web, go to: http://groups.yahoo.com/group/cisco-ttl/

* To unsubscribe from this group, send an email to: cisco-ttl-unsubscribe_at_yahoogroups.com <mailto:cisco-ttl-unsubscribe_at_yahoogroups.com?subject=Unsubscribe>

* Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service <http://docs.yahoo.com/info/terms/> .

[Non-text portions of this message have been removed]

--

Bu listenin Cisco Systems ile herhangi bir baglantisi bulunmamaktadir.

Listede onerilen cozumlerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar.

Listeden cikmak için cisco-ttl-unsubscribe_at_yahoogroups.com adresine bir e-posta gönderebilirsiniz.

Yahoo! Groups Sponsor

ADVERTISEMENT

< http://us.ard.yahoo.com/SIG=129ja8tbg/M=298184.6191685.7192823.3001176/D=gr

oups/S=1705004726:HM/EXP=1111643308/A=2593423/R=0/SIG=11el9gslf/*http:/www.n etflix.com/Default?mqso=60190075> click here

< http://us.adserver.yahoo.com/l?M=298184.6191685.7192823.3001176/D=groups/S=

:HM/A=2593423/rand=603032195>

_____

Yahoo! Groups Links

* To visit your group on the web, go to: http://groups.yahoo.com/group/cisco-ttl/

* To unsubscribe from this group, send an email to: cisco-ttl-unsubscribe_at_yahoogroups.com <mailto:cisco-ttl-unsubscribe_at_yahoogroups.com?subject=Unsubscribe>

* Your use of Yahoo! Groups is subject to the Yahoo! <http://docs.yahoo.com/info/terms/> Terms of Service.

[Non-text portions of this message have been removed]

--

Bu listenin Cisco Systems ile herhangi bir baglantisi bulunmamaktadir.

Listede onerilen cozumlerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar.

Listeden cikmak için cisco-ttl-unsubscribe_at_yahoogroups.com adresine bir e-posta gönderebilirsiniz. Yahoo! Groups Links

---- This email is intended for the named recipient only. It may contain information which is confidential, commercially sensitive, or copyright. If you are not the intended recipient you must not reproduce or distribute any part of the email, disclose its contents, or take any action in reliance. If you have received this email in error, please contact the sender and delete the message. It is your responsibility to scan this email and any attachments for viruses and other defects. To the extent permitted by law, Zurich and its associates will not be liable for any loss or damage arising in any way from this communication including any file attachments. We may monitor email you send to us, either as a reply to this email or any email you send to us, to confirm our systems are protected and for compliance with company policies. Although we take reasonable precautions to protect the confidentiality of our email systems, we do not warrant the confidentiality or security of email or attachments we receive.

[Non-text portions of this message have been removed]

--

Bu listenin Cisco Systems ile herhangi bir baglantisi bulunmamaktadir.

Listede onerilen cozumlerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar.

Listeden cikmak için cisco-ttl-unsubscribe_at_yahoogroups.com adresine bir e-posta gönderebilirsiniz. Yahoo! Groups Links

<*> To visit your group on the web, go to: http://groups.yahoo.com/group/cisco-ttl/

<*> To unsubscribe from this group, send an email to: cisco-ttl-unsubscribe_at_yahoogroups.com

<*> Your use of Yahoo! Groups is subject to: http://docs.yahoo.com/info/terms/



This archive was generated by hypermail 2.1.3 : Thu Mar 24 2005 - 01:15:23 EET