if you are on a switched LAN it can be harder to sniff without a trace tho as a sniffer needs a way to fool the switch in to sending it packets (ARP poisoning). if you download ettercap and run it with -c you can check to see if there's anything obvious going on. this can take a while on a large network. (arpwatch is also good)
ettercap's main purpose is to sniff networks itself so this may help you to understand what a sniffer could be getting.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.