![](first1.gif)
![](prev1.gif)
![](next1.gif)
The Technique
-
Configure your logger, IDS probe, or sniffer with an active
Ethernet interface that has no IP address.
-
If the network you want the stealth-probe on is switched,
insert a hub at a strategic point and hang the probe off of the hub.
-
If you're really paranoid, use a "sniffing cable."
-
To use a stealth logger, you'll need a bogus static ARP entry
on each host that sends log datah
-
That's pretty much it. Thanks for coming!