Sniffing is the act of intercepting and analyzing traffic on a network. This module covers passive vs active sniffing, packet capture tools like Wireshark and tcpdump, ARP poisoning attacks, MAC address table overflow, DHCP starvation, and techniques for evading switched networks.
The CEHStudy app carries 10 flashcards for Module 8 across 2 sections — start with the basics (why switches stop naive sniffing), then work the switched-network attack methods section card by card.
Passive Sniffing: Simply listening to network traffic without sending packets. Works on hubs where all traffic is broadcast to every port. Cannot work on switches without additional attacks.
Active Sniffing: Injecting packets into the network to redirect traffic toward the attacker. Includes ARP poisoning, MAC flooding, and DHCP starvation attacks.
ARP Poisoning (ARP Spoofing): Sending fake ARP replies to associate the attacker's MAC address with the target's IP. Creates a Man-in-the-Middle position.
CAM Table Overflow: Flooding a switch's MAC address table until it enters "fail-open" mode, broadcasting all traffic like a hub. Tools: Macof, Cain & Abel.
DHCP Starvation: Creating fake DHCP requests with random MACs to exhaust the DHCP pool (DHCP exhaustion). Also called a DHCP starvation attack. Tools: Yersinia.
Wireshark: The world's most popular network protocol analyzer. GUI-based, supports hundreds of protocols, captures and displays packet-level data in real-time.
tcpdump: Command-line packet capture tool for Linux/Unix. Uses BPF (Berkeley Packet Filter) syntax for filtering captured packets.
How to Study This Module
Understand the difference between passive and active sniffing with examples
Know how ARP poisoning creates a Man-in-the-Middle position
Memorize how MAC flooding forces switches into hub-like behavior
Practice using Wireshark to analyze captured traffic
Frequently Asked Questions
What is the difference between hub and switch sniffing? On a hub, all traffic goes to every port — passive sniffing works easily. On a switch, traffic is sent only to the destination MAC, so active attacks (ARP poisoning, MAC flooding) are required.
How does ARP poisoning work? The attacker sends unsolicited fake ARP replies telling the gateway that the attacker's MAC is the target's IP. All traffic for the target now goes through the attacker's machine.
What is Network Sniffing and Traffic Analysis in Ethical Hacking?
Network Sniffing and Traffic Analysis is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers both the offensive techniques for intercepting traffic — ARP poisoning, MAC flooding, DHCP starvation — and the defensive skill of analyzing captured packets to identify threats, extract credentials and understand protocol behavior. The exam emphasizes Layer 2 attacks on switched networks, where hub-based sniffing is no longer trivial. Module 8 accounts for approximately 10% of CEH v13 exam questions.
Key Concepts in Sniffing and Traffic Analysis
ARP Poisoning & Man-in-the-Middle: ARP has no authentication — any host can claim to be any IP address. An attacker sends forged replies associating their MAC with the gateway's IP (or the target's IP), intercepting all traffic through their machine. Tools like Ettercap automate this with built-in MiTM capabilities: HTTP injection, credential capture, SSL stripping. Know how ARP cache tables make this possible on any flat LAN segment.
CAM Table Flooding (MAC Overflow): Switches maintain a MAC address table (CAM table) mapping MAC addresses to ports. Flooding it with millions of fake MACs overflows the table and pushes the switch into "fail-open" mode — forwarding all frames to all ports like a hub. Tools: Macof (Kali), Cain & Abel. Know that this is a temporary DoS enabling sniffing only while flooding continues; defense: port security with a maximum MAC limit per port.
DHCP Starvation Attack: The attacker floods the network with DHCP Discover requests using randomized MACs, exhausting the DHCP server's address pool, then runs a rogue DHCP server and becomes the gateway for all new clients — enabling sniffing and man-in-the-middle attacks. Tools: Yersinia, DHCPig. Distinguish this from simple DoS: the goal is traffic redirection, not denial of service. Defense: DHCP snooping on managed switches.
Credential Extraction from Traffic: Many protocols transmit credentials in cleartext or weakly protected: HTTP Basic Auth (base64-encoded = trivially decoded), FTP (cleartext username/password), Telnet (cleartext), SMTP/POP3 without STARTTLS, legacy SMB (NTLM hashes). Wireshark's "Follow TCP Stream" reconstructs entire conversations. Know which protocols are inherently insecure.
Common Exam Mistakes in Module 8
Assuming a plain sniffer works on a switched LAN: unlike a hub, a switch forwards each frame only to the destination MAC, so a passively attached NIC sees almost no one else's traffic. The exam expects the four ways around that: ARP poisoning (primary), MAC flooding, DHCP starvation, or legitimate port mirroring (SPAN).
Misreading how MAC flooding actually works: it is not "lots of packets slow the network down." The attack floods the switch's CAM table with thousands of fake MACs until it overflows; an exhausted table forces fail-open mode — every frame broadcast out all ports, like a hub — which is what makes passive capture possible.
Equating sniffing with reading packet contents: traffic analysis draws conclusions — who talks to whom, how often, how much — without decrypting the payload. Even fully encrypted traffic leaks this metadata, so "everything is encrypted" is not a complete answer to "can an analyst learn anything?"
Tools Used in Sniffing and Traffic Analysis
Capture and interception tooling the CEH v13 exam references for this domain, by job:
Wireshark: the GUI packet analyzer — 500+ protocol decoders, display filters and statistics panels
tcpdump: command-line capture on Linux/macOS using BPF syntax (tcpdump -i eth0 port 80), the standard answer for "CLI sniffer"
Bettercap: modular network attack and monitoring framework — ARP spoofing, MITM modules, session hijacking and traffic analysis in one toolkit
Cain & Abel: the Windows-side bundle: password recovery, network monitoring, and protocol analysis in a single product
Responder: LLMNR/NBT-NS/mDNS poisoner that harvests NTLMv2 hashes when poisoned name-resolution requests hit the wire
Yersinia: multi-protocol attack tool (DHCP, OSPF, VTP) — the DHCP-starvation answer on many exam questions
Maltego / NetworkMiner: the traffic-analysis pair — Maltego maps relationships between hosts, users and services; NetworkMiner extracts files, credentials and artifacts from a capture without reading conversation contents
Worked Example: Finding Cleartext Credentials on a Switched Floor
Your lab switch isolates every port by MAC address, so a simple mirror to your NIC sees only your own frames. You poison the ARP table instead: your host answers with a forged reply binding the router's IP to your MAC, and traffic between the victim workstation and the gateway now transits your machine. Capturing with tcpdump, you filter for clear-text protocols — HTTP, FTP, telnet — and find session cookies and passwords that never should have left the LAN unencrypted.
Where it stops working: once the victim uses HTTPS, your capture shows ciphertext only — the correct next moves are a downgrade attempt (SSL stripping) or pivoting to traffic analysis, where timing, volume and peer relationships still reveal who talks to what even under a valid TLS session.
How to Study Sniffing for the CEH v13 Exam
To study Module 8:
Know the three main switched-network attacks and their goals: ARP poisoning (redirect traffic), MAC flooding (force broadcast mode), DHCP starvation (become gateway) — the exam presents scenarios asking which attack is described
Learn Wireshark display filter syntax: filter by IP, port, protocol, HTTP method and TCP flags — practical questions ask you to pick the correct filter
Hands-on: set up a VirtualBox network with two VMs (attacker + victim) on a host-only adapter — Kali on attacker, Windows on victim. Perform ARP poisoning with Ettercap, capture HTTP login credentials in Wireshark, and document the attack chain from initiation to credential capture
Frequently Asked Questions About Sniffing and Traffic Analysis
How does ARP poisoning create a Man-in-the-Middle position?
ARP lets any host send an unsolicited reply claiming "IP X has MAC Y." The attacker sends two forged replies: (1) to the victim — "the gateway's IP is now MY MAC" — and (2) to the gateway — "the victim's IP is now MY MAC." Both update their ARP caches and route traffic through the attacker, which can pass it along (transparent MiTM) or modify it. Know why this works: (a) ARP has no authentication, (b) hosts accept unsolicited replies without verification, and (c) the ARP cache updates immediately, without waiting for the previous entry to expire.
What defensive measures prevent network sniffing on a LAN?
Primary defenses: (1) **Port Security** — limit MAC addresses per switch port, disabling the port on violation; (2) **Dynamic ARP Inspection (DAI)** — validates ARP packets against a DHCP snooping binding table, dropping spoofed replies; (3) **DHCP Snooping** — builds a trusted IP-MAC binding table from legitimate DHCP exchanges, blocking rogue servers; (4) **802.1X Port-Based Authentication** — requires device authentication before network access; (5) **Network Segmentation (VLANs)** — limits broadcast domain size so one attacker cannot see the whole network; (6) **Encryption (HTTPS, TLS)** — intercepted payloads are unreadable. No single defense is sufficient — defense in depth requires multiple layers.