Re: Determining the presence of wireshark

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

On March 9, 2010 12:40, in comp.os.linux.networking, wrote:

Quoted text here. Click to load it

Note that this will present false positives if the NICs in question are
running with "user set" MAC addresses.

With "user set" MAC addresses, the NIC cannot use it's builtin comparison
logic to find frames addressed to the NIC. The OS NIC driver logic has to
match the MAC address on /all/ "on the wire" packets to the "user set" MAC
address, and extract those that match. This requires that the NIC run in
promiscuous mode, to permit the driver access to all the network traffic.

Lew Pitcher
Master Codewright & JOAT-in-training   | Registered Linux User #112576
Me: | Just Linux: /
----------      Slackware - Because I know what I'm doing.         ------

Site Timeline