Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 27th, 2002, 10:26 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Sniffers: what are they and how to protect

Quote:
Introduction

Have you ever thought about how your computer talks with others on a network? Would you like to listen to, or “sniff”, the conversation? Network engineers, system administrators, security professionals and, unfortunately, crackers have long used a tool that allows them to do exactly that. This nifty utility, known as a sniffer, can be found in the arsenal of every network guru, where it’s likely used everyday for a variety of tasks. This article will offer a brief overview of sniffers, including what they do, how they work, why users need to be aware of them, and what users can do to protect themselves against the illegitimate use of sniffers.

Read the full story here:

http://online.securityfocus.com/infocus/1549


__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #2  
Old February 27th, 2002, 10:50 AM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,226
Default Re: Sniffers: what are they and how to protect

Surely - surely - there's a simple, tiny program that can tell you if your adaptor's in promiscuous mode or not?
__________________
My Novel
  #3  
Old February 27th, 2002, 04:06 PM
UNICRON's Avatar
UNICRON UNICRON is offline
Technical Expert
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: Sniffers: what are they and how to protect

http://www.securitysoftwaretech.com/antisniff/
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
  #4  
Old February 27th, 2002, 04:27 PM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,226
Default Re: Sniffers: what are they and how to protect

Quote:
http://www.securitysoftwaretech.com/antisniff/
Very much appreciated, Unicron - but the tag of $350 is about as attractive as a (insert your own image of something antisocial happening) in a crowded elevator.

Say, are you any good at detecting promiscuity? *Mwahahaha!
__________________
My Novel
  #5  
Old February 27th, 2002, 06:23 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,879
Default Re: Sniffers: what are they and how to protect

Brief synopsis for people:

It shouldn't matter, in many cases, if the network is sent through "routers" as the data is ONLY sent to one computer, unlike "hubs" which simply "scream" out the data (i.e. it is broadcast to everyone).

In the instance of a hub, a sniffer will work.

In most cases, many of the sniffers will NOT work on routered networks (unless, of course, they exploit some sort of not-yet-discovered vulnerability in how routers work - or use certain types of spoofing techniques).

On a side note, does anyone know of a tool to somehow discover if your network is on routers or on hubs or switches? (Given that many people do not have the physical access to the hardware, and *might* want to know such a thing.)
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #6  
Old February 27th, 2002, 07:19 PM
UNICRON's Avatar
UNICRON UNICRON is offline
Technical Expert
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: Sniffers: what are they and how to protect

well.....running a packet sniffer might give you some clues......

http://www.ethereal.com

PS a trace route normally will report all the routers between you and a target IP. Pay attention to the routers on your ISPs network.
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
  #7  
Old February 27th, 2002, 08:40 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,879
Default Re: Sniffers: what are they and how to protect

Quote:
well.....running a packet sniffer might give you some clues......

http://www.ethereal.com

PS a trace route normally will report all the routers between you and a target IP. Pay attention to the routers on your ISPs network.

I realize those are two good options - I was asking specficially for any programs that use some other method to determine if you are on a hubbed or routered network...(if there is any other way to determine such a thing)
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #8  
Old February 27th, 2002, 10:21 PM
UNICRON's Avatar
UNICRON UNICRON is offline
Technical Expert
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: Sniffers: what are they and how to protect

No packets not intended for your machine will reach you if a router is between you and other computers. I am unsure what network you are referring to. Is it an office network, or your ISP's network that your home computer is on? I would be amazed if your ISP has all its customers on a hub, that would be rather scary.

So, it there is traffic not bound for you, then there are some computers not isolated from you by a router. Now most networks aren't a single tier system, and employ many routers and switches ect. That is what the trace may discover.

Also MS systems generally anounce their arrival on *a network via netbios (port 139) so a sweep of that port over the network may bear fruit.

if you are looking for a tool to analyze a network, there are many, but most are enterprise level tools and are expensive. There are fewer tools designed for smaller applications since in that environment said tools are of limited use.
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
  #9  
Old February 28th, 2002, 05:55 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,879
Default Re: Sniffers: what are they and how to protect

Quote:
If you are looking for a tool to analyze a network, there are many, but most are enterprise level tools and are expensive. There are fewer tools designed for smaller applications since in that environment said tools are of limited use.


Do you happen to have any suggestions on enterprise level tools? That's what I was aiming my question at...sorry if I wasn't specific enough.
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:26 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums