Topic: Sniffing in Swtiched network- Attack and Penetration

Hi All,

I am performing a pen test, following is the objective:
- Try and gain access to the cisco routers / switches in the network (total 5-6)
- Try and gain access to the application and passwords on different subnets

The problem is:
- Network is heavily segmented (more than 20 subnets in 3 different IP ranges- 10, 172 and 192 series). However they are all reachable/ accessible from my IP.
- Network uses switches
- Some of the applications are on different IP range, but reachable in two hops

I tried putting a sniffer on the network, including Ettercap to try and sniff the network for passwords etc.... but majority of the sniffers dont cross the first hop at the switch. So i am no where close to rest of the subnets/ip ranges. I tried using ettercap man in the middle attacks but, i guess it didnt work.

Can any one please guide me on using the right sniffer/ approach for this activity.

Thanks, fzy

Re: Sniffing in Swtiched network- Attack and Penetration

sounds like a typical vlan cisco 3 layer network. You can never sniff remotely its an IP impossibilty without having control of a remote node or routing.

Start of with CDP sniffing to identify model numbers. Then google for holes in specific IOSs.

Re: Sniffing in Swtiched network- Attack and Penetration

Try running ettercap and get as much information as you can about the network, plug into the other networks if possible.  Gather as much data as you can!  Then, go with what fat said by looking for some IOS weaknesses.  Most cisco routers (that I've worked with) tend to use telnet, which is easy to sniff, so you might wait for someone to log onto one of the routers.  If you are stuck in that segment, then it's going to be pretty hard to sniff anything without actually having physical access and messing around with stuff.  Sorry if this didn't help much, I tried! big_smile

Re: Sniffing in Swtiched network- Attack and Penetration

Something to keep in mind. If you are not doing an official pen test and this is a company or Edu facility expect to be detected.