What I'm trying to do: I'm trying to sniff traffic past a switch (lab environment). I have read to to this I need to Flood the CAM/ARP tables in the switch putting it into 'hub' mode.
Problem: I am using Ettercap and HPing2 on Ubuntu and Backtrac. But they do not seem to have ARP flooding features. I have read about both and some reading on the net indicates that Ettercap can be used to ARP flood but for the life of me I cannot figure out how to get it to work.
This Question: Can Ettercap ARP flood? If so is there a special plugin that I have to get for it? If not, what other program can I use to do and ARP flood?
Thanks for the Help
PS: I realize I can just put a hub in the network instead of a switch but what fun would that be?
Cain and Abel (http://www.oxid.i. . .) looks like it would do what you need. Windows only though, as far as I know.
The latest version is faster and contains a lot of new features like APR (Arp Poison Routing) which enables sniffing on switched LANs and Man-in-the-Middle attacks. The sniffer in this version can also analyze encrypted protocols such as SSH-1 and HTTPS, and contains filters to capture credentials from a wide range of authentication mechanisms.