(E-Mail Removed) wrote:
> We are running win2k on all or workstations. Many of the
> developers and techs have local admin access to some of
> the workstations (it is necessary for their jobs). We have
> been running into problems with some employees installing
> packet sniffers (Ethereal, Sniffer Pro, Etherpeak) on
> their workstations and sniffing passwords off the LAN.
>
> Is there any kind of "anti-sniffer" software that will
> find computers running packet sniffers on a LAN?
Nothing that I'd want to bet my secure passwords on, no. You can do things
like use another packet sniffer to detect NICs that are in "promiscuous"
mode, which is a fair sign, but this isn't 100% reliable.
With respect, I don't think you have a technological problem that requires a
technological solution. You have a behavioural problem that requires a
behavioural solution.
If you have the sort of workplace culture that makes people believe its ok
to install sniffers and grab (and presumably, use) passwords from the
network then even if you found an anti-sniffer package that you felt WAS
good enough, these people would either work on defeating it or find another
way to screw around.
If you have an "acceptable use policy" then it should promise ritual
floggings.. er.. firings for people caught abusing the system in a serious
way. I'd suggest putting this into action.
If you don't have an AUP that allows you to control your own network then
this is 2004 calling, you need to get one. And then use it.
--
--
Rob Moir, Microsoft MVP for servers & security
Website -
http://www.robertmoir.co.uk
Virtual PC 2004 FAQ -
http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html
Kazaa - Software update services for your Viruses and Spyware.