Phase3: Gaining Access Using Network Attacks

2008 Oct 18


Sniffing

Sniffing

A sniffer is a program that gathers network traffic. It is useful to attackers looking to acquire useful data and system administrators trying to diagnose problems. All network traffic can be stored for later analysys. This can include userIDs and passwords sent by telnet (unencrypted), DNS queries and responses, sensitive email, FTP passwords, shared files, print streams, and much more. All that is required is to place a network interface into promiscuous mode. An account on the network, by any means, is required.

Sniffer software
Name OS Comment
dsniff Unix freeware suite
ethereal Unix, Win NT/2000 freeware
sniffit Unix freeware
snort network-based intrusion detection
tcpdump Unix freeware
windump Win 9x, NT, 2000 freeware

2005-2008