Have a look at http://freshmeat.net/proje
It can check to see which clients on a lan have their network adapters set to promiscuous mode, ie those that may be sniffing
Main Topics
Browse All TopicsI want to find any one using sniffer in my network. Is there any open source tool available?.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Have a look at http://freshmeat.net/proje
It can check to see which clients on a lan have their network adapters set to promiscuous mode, ie those that may be sniffing
Business Accounts
Answer for Membership
by: jimmypwPosted on 2009-10-05 at 21:53:45ID: 25501976
Hi,
Your question depends on how sophisticated the suspected hacker is, I'll go through a few scenario's.
1)
S. The hacker is using a packet dumping tool such as ethereal or tcpdump.
A. There isn't anything you can do to prevent this particularly if they have their own kit. If you are using switch they can only see their own traffic and broadcasts. Consider a security switch that monitors MAC address changes.
2)
S. The hacker has physical access to a sensitive machine / networking equipment.
A. Physical access should always be restricted. If you are in control of this you can log and supervise users you are well within your right.
3)
S. A tool is being used to poison ARP tables of machines to redirect traffic.
A. This kind of attack is by far the most flexible from the perspective of the hacker but also the noisiest and easily detectable (arp responses with no requests). From here there are 2 routes either write your own script to monitor arp -an and scan for changes or (i believe) there is a module for snort.