NullJack: An Open Approach for Undetectable Ethernet Port Scanning
摘要
Identifying active Ethernet ports is a critical step in physical security assessments and infrastructure audits. However, conventional detection methods typically involve connecting standard devices, which may generate logs, trigger monitoring alerts, or register MAC addresses—actions that compromise the stealth of the assessment, especially in secured or monitored environments. This highlights the need for a discreet, low-profile solution capable of passively identifying active ports without initiating full network communication. This paper introduces the design, implementation, and evaluation of NullJack, a custom hardware device developed to covertly detect active Ethernet ports in real-world network infrastructures. NullJack operates by interpreting voltage signals from initial handshake negotiations and provides visual feedback through an LED, all without engaging in data exchange or triggering MAC address registration. A thorough evaluation across various CISCO switches and cable types demonstrates the device’s ability to detect port status and link speed variations without activating PoE functions or leaving a digital footprint. Additionally, a security assessment was conducted at the University of Aveiro to validate the device’s efficiency in practical scenarios.