Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Good sniffer software

 
Thread Tools Search this Thread
Old 05-15-2004, 11:27 PM   #1
Default Good sniffer software


Could somebody recommend me some good
network "sniffer" software that could be used
to intercept data on the LAN where I am sysadm.

I would like to test security of our corporate
LAN (some 300 workstations, 25 servers)
which is entirely based on HP Procurve
switches (so, therefore there is no single
broadcast Ethernet domain). In short, I would
like to see if it is still possible that someone
installs some network equipment (PC+software)
and "sniff" data on the network.

Any pointer to software that could be used
for testing or any other related URL is
more than welcome.


Zorpetus
  Reply With Quote
Old 05-16-2004, 01:10 AM   #2
*Vanguard*
 
Posts: n/a
Default Re: Good sniffer software
Zorpetus said in news: m:
> Could somebody recommend me some good
> network "sniffer" software that could be used
> to intercept data on the LAN where I am sysadm.
>
> I would like to test security of our corporate
> LAN (some 300 workstations, 25 servers)
> which is entirely based on HP Procurve
> switches (so, therefore there is no single
> broadcast Ethernet domain). In short, I would
> like to see if it is still possible that someone
> installs some network equipment (PC+software)
> and "sniff" data on the network.
>
> Any pointer to software that could be used
> for testing or any other related URL is
> more than welcome.


Ethereal (http://www.ethereal.com/) had been suggested to me when I
asked about monitoring my traffic. Never got around to trying it,
though.

--
__________________________________________________ __________
*** Post replies to newsgroup. Share with others.
*** Email: domain = ".com" and append "=NEWS=" to Subject.
__________________________________________________ __________




*Vanguard*
  Reply With Quote
Old 05-16-2004, 11:20 PM   #3
Seraph
 
Posts: n/a
Default Re: Good sniffer software
On 2004-05-15 19:10:39 -0500, "*Vanguard*"
<no-> said:

> Zorpetus said in news: m:
>> Could somebody recommend me some good
>> network "sniffer" software that could be used
>> to intercept data on the LAN where I am sysadm.
>>
>> I would like to test security of our corporate
>> LAN (some 300 workstations, 25 servers)
>> which is entirely based on HP Procurve
>> switches (so, therefore there is no single
>> broadcast Ethernet domain). In short, I would
>> like to see if it is still possible that someone
>> installs some network equipment (PC+software)
>> and "sniff" data on the network.
>>
>> Any pointer to software that could be used
>> for testing or any other related URL is
>> more than welcome.

>
> Ethereal (http://www.ethereal.com/) had been suggested to me when I
> asked about monitoring my traffic. Never got around to trying it,
> though.


I'd say that Ethereal would be a very good choice, but I would also
look into ettercap. Ettercap has the ability to arp poison a switch and
intercept traffic even if there is not a single broadcast domain. I've
used both, and both are very good. Ettercap also has the ability to
detect other ettercap users on the network, so you can discover is
someone else is sniffing your network with that tool...
--
Seraph
www.geekgalore.com

You must be the change you wish to
see in the world." ~Mohandas Ghandi



Seraph
  Reply With Quote
Old 05-20-2004, 11:33 PM   #4
XC-88-1K-4
 
Posts: n/a
Default Re: Good sniffer software
Zorpetus wrote:

> Could somebody recommend me some good
> network "sniffer" software that could be used
> to intercept data on the LAN where I am sysadm.
>
> I would like to test security of our corporate
> LAN (some 300 workstations, 25 servers)
> which is entirely based on HP Procurve
> switches (so, therefore there is no single
> broadcast Ethernet domain). In short, I would
> like to see if it is still possible that someone
> installs some network equipment (PC+software)
> and "sniff" data on the network.
>
> Any pointer to software that could be used
> for testing or any other related URL is
> more than welcome.


You want Dsniff.
http://monkey.org/~dugsong/dsniff/

A bit of info..
====
In a nutshell, dsniff is the Swiss army knife of privacy invasion. The
package ships with a handful of powerful tools, including urlsnarf, webspy,
mailsnarf, and the dsniff tool. Urlsnarf grabs every URL that passes across
the wire and stores it for later examination. Webspy can grab URLs off the
wire and open the URL in your local browser window so you can follow along
and view what a remote user is seeing on his or her Web browser. Mailsnarf
is just as nasty as webspy?it can sniff SMTP-related packets off the wire
and reassemble entire email messages into a common format that popular mail
clients can read. The dsniff tool is one of the most powerful password
grabbers I've seen. It can snag passwords off the wire from many different
protocols, including FTP, Telnet, Web, POP3, IMAP, LDAP, Citrix ICA,
pcAnywhere, SMB, Oracle SQL*Net, and numerous others.

Even though the tools found in the dsniff package are written for UNIX
platforms, you still need to be aware that these tools exist because they
could be used against your Windows-based networks. Song's package is
incredibly powerful, whether used with good or bad intent. The tools point
out a well-known problem with networks in general: malicious users can
easily sniff clear text from packets to glean sensitive data. Although
blocking ARP redirects and monitoring ARP traffic and tables can help
protect against tools like arpredirect, those tactics are certainly not
cure-alls. They help prevent packets from becoming misdirected, but most
data still travels in clear text over your networks, which means localized
intruders can glean sensitive data with packet-sniffing tools. To better
protect your data, you must encrypt it at some level before sending it out
on the wire, and you must use sniffer-detecting tools to help stop the
snoops.

The decision about which tactics to use for data protection depends on your
data and your organization, so I can't give you much more advice on the
matter. Just be aware that ARP poisoning and data sniffing are real
problems that you need to guard against. Until next time, have a great
week.



XC-88-1K-4
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zebra VirusCleaner is a good software. hely0123 Software 1 11-19-2007 07:26 AM
Sewing, Embroidery & SignMaking Software.. embsupply Software 0 08-14-2007 04:01 PM
=> Professional Software CAD CAM CFD GIS ! FTP-Download! UnlockSofts General Help Related Topics 2 07-17-2007 11:44 AM
Re: Good morning or good evening depending upon your location. I want to ask you the most important question of your life. Your joy or sorrow for all eternity depends upon your answer. The question is: Are you saved? It is not a question of how good Filthy Mcnasty DVD Video 0 04-25-2005 04:29 AM
image backup software Gaz A+ Certification 51 07-21-2004 09:58 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46