• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 762
  • Last Modified:

Sniffing telnet session on a switch

Hi

Is it true that you cannot sniff telnet sessions on a switch. For example if I want to sniff the telnet session I make from my Laptop to the cisco router. If my laptop that is going to make a telnet session to cisco session is connected to port 1 on switch the cisco router is connected to port 2 on the switch and my sniffing laptop is connected to port 3, then if the laptop is going to make a telnet session to router can my sniffing laptop capture the traffic in between them ? Or say if I am connected to completely different switch but still on the same network what will be the behavior then ?
0
kamal73
Asked:
kamal73
  • 2
2 Solutions
 
LucFEMEA Server EngineerCommented:
Hi kamal73,

A switch doesn't replicate the information to all ports, so you won't be able to sniff the data that way. To be able to sniff it, you'll have to exchange the switch for a hub, which is nothing more or less than a multi-port repeater, so all data will be send to all ports.

Greetings,

LucF
0
 
Pete LongTechnical ConsultantCommented:
LucF is correct

Telnet is about as secure as an open window (without SSH) but there are some exeptions to the rule

you CAN sniff an interface with third party software - and some are designed to solely monitor switch ports

see http://www.eeye.com/html/Products/Iris/Download.html  this will sniff and decode anything
telnet traffic, Email traffic - even what web pages particular clients are using.
this is legal though it could be abused - above all, if your going to use this product in a work enviroment you need to inform your employees before you deploy it, as it has certain privicy implications.

Pete
0
 
kamal73Author Commented:
I'm only going to use it on a Lab network, how can one tell if it is being used on their network ?
0
 
Pete LongTechnical ConsultantCommented:
:) well you cant, hence the need to inform people :)

ThanQ
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now