RE: Serious Question--ARP SPOOF/IT Department 01-30-2014, 09:41 PM
#4
What you've done is classified under grey hat: they scan/attack first, then they offer help (not for free of course), this is illegal, even scanning ports, DNS, IPs in some countries is considered a crime, SO BE CAREFUL!!!
What I do advice you to do is to raise the question "How solid is our security against ARP Poisoning Attacks" and do a presentation about how this attack can be conducted (in theory only) but DO NOT show them anything in practice unless there is a signed contract that will protect you, believe me, some narrow minded admins that would cause you big problem because of that, just to show off, so don't trust anyone!
Again, you SHOULD raise the question, and present your findings in an indirect way, and never run a demo unless there is a signed contract that will protect you.
Thanks and good luck.
What I do advice you to do is to raise the question "How solid is our security against ARP Poisoning Attacks" and do a presentation about how this attack can be conducted (in theory only) but DO NOT show them anything in practice unless there is a signed contract that will protect you, believe me, some narrow minded admins that would cause you big problem because of that, just to show off, so don't trust anyone!
Again, you SHOULD raise the question, and present your findings in an indirect way, and never run a demo unless there is a signed contract that will protect you.
Thanks and good luck.
![[Image: wvBFmA5.png]](http://i.imgur.com/wvBFmA5.png)


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)