Wow -- deeply impressed by those nice descriptions from Kath and
Raven! If I were in the position (and appropriate location of the
world), I'd immediately hire you, Kath, to make your dreamjob come
true... :)

> On every network card there is a MAC address, which uniquely identifies the
> computer.  The switch will do a broadcast and poll the devices on each port
> for a list of MAC addresses of connected devices.

...not much left to add, and the networking cracks here certainly
already know:  it's this broadcasting technique of switches where
ARP spoofing can get its handle on (though some switches allow to
take precautions against it). For a short intro see

For those who want to play around with this (in their home LAN only,
of course!), there's the 'dsniff' collection of tools, which also
allows for interesting uses like network monitoring:

(also remotely related to the recent MRTG thread)


