NetStumbler.org Forums

Go Back   NetStumbler.org Forums > NetStumbler Community > NetStumbler
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 08-11-2001   #1 (permalink)
 
Posts: n/a
sniffers-prom-lucient

here is a question...
im running ethereal with winpcap installed
and im trying to view traffic on a switch
im using this
http://www.phenoelit.de/arpoc/
to intercet packets...
but when i run it all that happens is that the network
seems to come to a crawl...
and the only packets i can see are the
packets that the WCI program is sending out...
it on my own switch..
and i have configured the routes.txt
  Reply With Quote
Old 08-11-2001   #2 (permalink)
 
Posts: n/a
also...

also
the network dies for all the other computers
that are on the switch...
hmm
anyone know how to sniff in promiscous mode in 2000

...

  Reply With Quote
Old 08-23-2001   #3 (permalink)
 
Posts: n/a
name resolution on?

I had same problems with just a LAN and Linksys router to cable modem. I figured out turning off Network Name Resolution fixes this. Probly that when a packet is sent the program does a reverse DNS on the ip causeing you to hit your Internet DNS server hundreds of times hence brining the network to a crawl. Hope this helps.
  Reply With Quote
Old 08-27-2001   #4 (permalink)
 
Posts: n/a
ARP flooding...

That attack FLOODS the switch wih ARP packets. I'm not sure ho the whole thing works but in the end ALL of thepackets aparently ROUTE through the attackin machine. That in itself would certainly slow trafic as yor mahcine is NO going to be as good at swithcing packets as the dedicated hardware. Plus you've flooded the network with traffic causing the switch to fail in an unnatural way! This is "not cool". Some switches will fail into a HUB type mode as well and allow sniffing. Basically you're attacking the network and flooding it with unnecessary packets. The multiple DNS requests for each new hosts your sniffer sees will also allow that inerface to be easily found by simply pumping a few fake hosts out there to see whch interface queries the DNS server for them. You might want to be careful about doing that sort of thing as it's NOT something any network administrator is likely to find as benign....

Oh, packet sniffing on WIN2K is pretty easy. Look up Etherreal - they have a WIN32 version and the instrucitons will tell you where to go in order to find the packet sniffing library that's needed to go promiscous on NT. Note that on a switch, without the monkey business you've already been trying, that you will NOT see any packets but those destined for YOU. That's part of how a switch saves bandwidth and supposedly promotes security (cough)...
  Reply With Quote
Old 08-27-2001   #5 (permalink)
 
Posts: n/a
Umm duh?

The instructions located onhe site you linked tell you where to get the LIBPcap driver... http://netgroup-serv.polito.it/winpcap/

Ya' might want to read the instructions?
  Reply With Quote
Old 08-28-2001   #6 (permalink)
 
Posts: n/a
well here is more info i forgot to put in

I am using wincap. And i do have ethereal set to turn off
dns reverse lookups.
I also start the ethereal capture.
then i run wci
during the capture i can see packets but only from my own
machine.
Does wincap put the nic card into promiscous mode?
I thought that is what wincap was for?
I useing a 3com 8 port 10/100 full duplex switch
office connect.
linked via uplink port to a
ugate maxgate 3000 dsl router

  Reply With Quote
Old 08-29-2001   #7 (permalink)
 
Posts: n/a
Switch = Per Port Isolation

On a switch, you shouldn't expect to only see the following types of traffic:

- Packets from your computer
- Packets to your computer
- Broadcast packets (typically network maintenance type stuff in there)

You won't see any of the routine traffic of any other device on any other port (unless your machine is having a conversation directly with a device on another port). That's the nature of a switch.

-Toomer

  Reply With Quote
Old 08-29-2001   #8 (permalink)
 
Posts: n/a
Put switch port in "monitor" mode

Most switches support a "monitor" mode that allows all traffic (or traffice from specific ports) to be sent a specific port for sniffing. So, essentialy, this particular port becomes like a hub port.

If your switch has a management interface you can usually turn this feature on.

Charlie
  Reply With Quote
Old 08-29-2001   #9 (permalink)
 
Posts: n/a
you all seem to misunderstand

i know you cannot sniff on a switch normally
but read bellow
check this out...
http://www.phenoelit.de/arpoc/index.html
this should allow you to basically turn a switch into
a hub so that you can sniff packets
its called wci
  Reply With Quote
Old 08-30-2001   #10 (permalink)
 
Posts: n/a
may be more than that

It's been discussed in other threads but... The card you've got may NOT be capable of going fully promiscuous (sp?). Depending on what you read it's either a firmware issue or a driver issue. I'm no sure I've seen a post yet form someone with a LUCENT card who's been able to sniff more than their own traffic. If they did I believe they were using an older version of the firmware than what's currently available on the WEB site. I've heard that older versions enabled this ability but any time I've been given revision numbers or dates for the code it's been older than what I've found for download out there.

IF someone has the older code, and I know someone must, for the Lucent Gold cards please send it to me and I'll mirror it on my site for download. Um, after I confirm it works for this purpose though :-)

In short - it may not be (just) the switch that's causing problems but it may (also) be your card. Wireless vendors don't want you sniffing. The Prism based cards CAN be used for this but NOT in Windows since the drivers apparently prevent it. In Linux the ability has been restored with patches that are available. That means two cards and two OS unless a firmware revision that works for the Lucent can be found...
  Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 01:23 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.