I am currently running Snort. I will examine its documentation to see if promiscuous mode is really necessary. In the meantime, am I correct in assuming the only threat is from local users? If so, currently all users are trusted so I shant panic just yet.

Snort uses promisc to capture the packets off the line and examine them. So this needs to be turned on in able to do some productive things :)
turning it off will disable snort actually.

Reminder for bill: sniffing via bpf requires the same privileges whether promisc. is set or not, so you always need to be root for sniffing data of the line, that is when the permissions is not tampered with :). Thanks #bsddocs (simon ;))

