ALL PASS, NO FAIL!

CEH v13 Module 8: Sniffing

Sniffing is the act of intercepting and analyzing traffic on a network. This module covers passive vs active sniffing, packet capture tools like Wireshark and tcpdump, ARP poisoning attacks, MAC address table overflow, DHCP starvation, and techniques for evading switched networks.

The CEHStudy app carries 10 flashcards for Module 8 across 2 sections — start with the basics (why switches stop naive sniffing), then work the switched-network attack methods section card by card.

Key Topics Covered

Important Terms & Concepts

Passive Sniffing: Simply listening to network traffic without sending packets. Works on hubs where all traffic is broadcast to every port. Cannot work on switches without additional attacks.
Active Sniffing: Injecting packets into the network to redirect traffic toward the attacker. Includes ARP poisoning, MAC flooding, and DHCP starvation attacks.
ARP Poisoning (ARP Spoofing): Sending fake ARP replies to associate the attacker's MAC address with the target's IP. Creates a Man-in-the-Middle position.
CAM Table Overflow: Flooding a switch's MAC address table until it enters "fail-open" mode, broadcasting all traffic like a hub. Tools: Macof, Cain & Abel.
DHCP Starvation: Creating fake DHCP requests with random MACs to exhaust the DHCP pool (DHCP exhaustion). Also called a DHCP starvation attack. Tools: Yersinia.
Wireshark: The world's most popular network protocol analyzer. GUI-based, supports hundreds of protocols, captures and displays packet-level data in real-time.
tcpdump: Command-line packet capture tool for Linux/Unix. Uses BPF (Berkeley Packet Filter) syntax for filtering captured packets.

How to Study This Module

Frequently Asked Questions

What is the difference between hub and switch sniffing?
On a hub, all traffic goes to every port — passive sniffing works easily. On a switch, traffic is sent only to the destination MAC, so active attacks (ARP poisoning, MAC flooding) are required.

How does ARP poisoning work?
The attacker sends unsolicited fake ARP replies telling the gateway that the attacker's MAC is the target's IP. All traffic for the target now goes through the attacker's machine.

Related Modules

What is Network Sniffing and Traffic Analysis in Ethical Hacking?

Network Sniffing and Traffic Analysis is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers both the offensive techniques for intercepting traffic — ARP poisoning, MAC flooding, DHCP starvation — and the defensive skill of analyzing captured packets to identify threats, extract credentials and understand protocol behavior. The exam emphasizes Layer 2 attacks on switched networks, where hub-based sniffing is no longer trivial. Module 8 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in Sniffing and Traffic Analysis

Common Exam Mistakes in Module 8

Assuming a plain sniffer works on a switched LAN: unlike a hub, a switch forwards each frame only to the destination MAC, so a passively attached NIC sees almost no one else's traffic. The exam expects the four ways around that: ARP poisoning (primary), MAC flooding, DHCP starvation, or legitimate port mirroring (SPAN).
Misreading how MAC flooding actually works: it is not "lots of packets slow the network down." The attack floods the switch's CAM table with thousands of fake MACs until it overflows; an exhausted table forces fail-open mode — every frame broadcast out all ports, like a hub — which is what makes passive capture possible.
Equating sniffing with reading packet contents: traffic analysis draws conclusions — who talks to whom, how often, how much — without decrypting the payload. Even fully encrypted traffic leaks this metadata, so "everything is encrypted" is not a complete answer to "can an analyst learn anything?"

Tools Used in Sniffing and Traffic Analysis

Capture and interception tooling the CEH v13 exam references for this domain, by job:

Worked Example: Finding Cleartext Credentials on a Switched Floor

Your lab switch isolates every port by MAC address, so a simple mirror to your NIC sees only your own frames. You poison the ARP table instead: your host answers with a forged reply binding the router's IP to your MAC, and traffic between the victim workstation and the gateway now transits your machine. Capturing with tcpdump, you filter for clear-text protocols — HTTP, FTP, telnet — and find session cookies and passwords that never should have left the LAN unencrypted.

Where it stops working: once the victim uses HTTPS, your capture shows ciphertext only — the correct next moves are a downgrade attempt (SSL stripping) or pivoting to traffic analysis, where timing, volume and peer relationships still reveal who talks to what even under a valid TLS session.

How to Study Sniffing for the CEH v13 Exam

To study Module 8:

  1. Know the three main switched-network attacks and their goals: ARP poisoning (redirect traffic), MAC flooding (force broadcast mode), DHCP starvation (become gateway) — the exam presents scenarios asking which attack is described
  2. Learn Wireshark display filter syntax: filter by IP, port, protocol, HTTP method and TCP flags — practical questions ask you to pick the correct filter
  3. Hands-on: set up a VirtualBox network with two VMs (attacker + victim) on a host-only adapter — Kali on attacker, Windows on victim. Perform ARP poisoning with Ettercap, capture HTTP login credentials in Wireshark, and document the attack chain from initiation to credential capture
  4. Review Module 11 (Session Hijacking) — how sniffed session tokens are exploited — and Module 6 (System Hacking) — how captured credentials enable lateral movement

Frequently Asked Questions About Sniffing and Traffic Analysis

How does ARP poisoning create a Man-in-the-Middle position?

ARP lets any host send an unsolicited reply claiming "IP X has MAC Y." The attacker sends two forged replies: (1) to the victim — "the gateway's IP is now MY MAC" — and (2) to the gateway — "the victim's IP is now MY MAC." Both update their ARP caches and route traffic through the attacker, which can pass it along (transparent MiTM) or modify it. Know why this works: (a) ARP has no authentication, (b) hosts accept unsolicited replies without verification, and (c) the ARP cache updates immediately, without waiting for the previous entry to expire.

What defensive measures prevent network sniffing on a LAN?

Primary defenses: (1) **Port Security** — limit MAC addresses per switch port, disabling the port on violation; (2) **Dynamic ARP Inspection (DAI)** — validates ARP packets against a DHCP snooping binding table, dropping spoofed replies; (3) **DHCP Snooping** — builds a trusted IP-MAC binding table from legitimate DHCP exchanges, blocking rogue servers; (4) **802.1X Port-Based Authentication** — requires device authentication before network access; (5) **Network Segmentation (VLANs)** — limits broadcast domain size so one attacker cannot see the whole network; (6) **Encryption (HTTPS, TLS)** — intercepted payloads are unreadable. No single defense is sufficient — defense in depth requires multiple layers.

Related CEH v13 Modules

Related Glossary Terms