On a switched Ethernet network, traffic from other hosts can be sniffed by impersonating which type of network device?
ARP spoofing can make a host appear to be the default gateway/router by associating the router’s IP address with the attacker’s MAC address in victims’ ARP caches. Traffic that victims send through that gateway is then forwarded through the attacker, where it can be captured. Cisco documents that ARP cache poisoning can intercept traffic intended for other hosts on the subnet.
Community Discussion