Yes, it is not mirrored port. I expected to see traffic which show packets containing either source or destination IPs of my machine. However I can see traffic to and fro for almost all the nodes on my network, looks like ARP poisoning is happening, but how? Is there any worm, virus or malicious program doing it, we have updated Symantec antivirus, and I am also using antispywares like Spybot -S & D.
Main Topics
Browse All Topics





by: rcflyrPosted on 2009-06-25 at 23:12:50ID: 24718364
what are the IP's that you are seeing? Also, you are sniffing traffic on the port you access the network on, not a mirrored port correct?