Subject: Re: a remote user can check promiscuous mode
To: Matt Thomas <matt@3am-software.com>
From: Hubert Feyrer <feyrer@rfhs8012.fh-regensburg.de>
List: tech-net
Date: 12/10/1999 19:27:25
On Fri, 10 Dec 1999, Matt Thomas wrote:
> >http://www.l0pht.com/antisniff/tech-paper.html claims that a remote user
> >can examine that whether a interface of NetBSD machine is promiscuous
> >mode or not.
> >
> >Is this bug?
> 
> It is a bug.  The Ethernet drivers that exhibit such behavior should
> be fixed.

Why is it a bug? 

The only fix I see for this is to actually disable the NIC's filter, and
do it in software, thus slowing things down again.  Isn't that exactly
what the filter is for in the NIC?

(Note I don't claim to be an expert on this, just wondering... :-)


 - Hubert

-- 
NetBSD - Better for your uptime than Viagra