Packet sniffing

Capturing and reading network traffic as it crosses a medium, used legitimately for troubleshooting and monitoring, and by attackers to collect credentials and data.

Packet sniffing is the capture of traffic from a network so that its headers and contents can be read. A wired network interface is placed in promiscuous mode so it keeps frames not addressed to it; a wireless interface in monitor mode captures frames from the air. The same technique serves defenders, in troubleshooting, protocol analysis and intrusion detection, and attackers, who use it to harvest anything sent in clear text. Sniffing is passive, so it leaves little trace.

What a sniffer can see depends on the medium and the equipment. On a hub or a shared wireless channel every station can see every frame. A switch normally limits each port to its own traffic, so an attacker first has to change that, for example through MAC flooding or ARP spoofing, the second of which turns passive capture into a man-in-the-middle attack. Physical access to cabling also matters: copper can be tapped more easily than fibre, although fibre is not immune. The main defence is encryption, replacing Telnet and FTP with SSH and TLS-protected protocols, so captured traffic is unreadable.

Exam relevance: a scenario in which credentials were captured from the network is likely to turn on a clear-text protocol. Candidates are expected to see that a switched network reduces sniffing but that encryption is what makes captured traffic unreadable.