shrockworks xterraparts
XOC Decal
Newest Members
Glim, ChossWrangler, Patman, ChargedX, Randy Howerton
10084 Registered Users
Recent Posts
ECXC 2024!
by Tom
23/04/24 04:27 PM
2002 Door Opening Trim
by OffroadX
01/04/24 08:32 PM
XOC Still Lives
by OffroadX
01/04/24 08:31 PM
Shout Box

Who's Online
0 registered (), 139 Guests and 0 Spiders online.
Key: Admin, Global Mod, Mod
Topic Options
Rate This Topic
#444760 - 12/12/05 06:10 PM Packet Sniffer needed
BurgPath Offline
Member

Registered: 25/05/02
Posts: 2146
Loc: Knoxville, Tn
I have an older one that only works pre Windows Xp, I'm running XP.

Anyone know of a shareware version that can give basic info? I just want to see where all my bandwidth is going.
_________________________
Kevin
- 2008.5 Titan SE 4x4
Burgy --- Nissan Offroad Association of the Southeast

Top
#444761 - 12/12/05 06:32 PM Re: Packet Sniffer needed
Anonymous
Unregistered


What about ethereal ? ethereal

Works great, but might be a bit overkill, If that doesn't work for you, let me know, I'll look in my library, I had some nice graphical ones that with charts, and bold lines and stuff that showed where everything was flowing, but I'm pretty sure its all linux. That what I used for all my network analysis, it would just be a matter of checking if there wouldn't be a windows version.

Top
#444762 - 12/12/05 06:43 PM Re: Packet Sniffer needed
Samueul Offline
Member

Registered: 10/04/01
Posts: 4114
Loc: Pittsburgh, PA. USA
What he ^ said.

Ethereal is really sweet.. If not, you can probably find somebody that has a copy of sms with network monitor....
_________________________
Must stay away from political/religious debates. Must stay away........

Top
#444763 - 13/12/05 09:42 AM Re: Packet Sniffer needed
Anonymous
Unregistered


Ethereal is the way to go. I use it at work all the time. The filtering can be a little tricky, but if you're doing just a general sniff it's a good program.

Top
#444764 - 13/12/05 08:33 PM Re: Packet Sniffer needed
BurgPath Offline
Member

Registered: 25/05/02
Posts: 2146
Loc: Knoxville, Tn
Nice, thanks.

Talks about how it doesn't work well with wireless nets and thats what I'm trying to look at, stuff on the wireless side.

I've tried to locate an option to do a 'spanning tree' or port mirror on my Linksys router so I can see all the traffic to and from the modem. No luck so far.
_________________________
Kevin
- 2008.5 Titan SE 4x4
Burgy --- Nissan Offroad Association of the Southeast

Top
#444765 - 14/12/05 08:43 AM Re: Packet Sniffer needed
Anonymous
Unregistered


Linksys routers aren't that advanced. If you have a hub plug the hub into the connection you want to monitor and hook up the monitoring computer to the hub, that's about all you can do.

You may or may not need crossover cables to do it. I can't remember if the Linksys is auto-switching or not.

I'd give it a sniff anyways. If someone is peaking around or you're looking for something specific it might be broadcast traffic.

Top
#444766 - 14/12/05 09:24 AM Re: Packet Sniffer needed
Anonymous
Unregistered


Black Ice Defender used to work really well, but I don't know about their XP version.

Top
#444767 - 14/12/05 07:09 PM Re: Packet Sniffer needed
BurgPath Offline
Member

Registered: 25/05/02
Posts: 2146
Loc: Knoxville, Tn
BID is a fire wall, isnt it?

King, good thought, I'll try that.
_________________________
Kevin
- 2008.5 Titan SE 4x4
Burgy --- Nissan Offroad Association of the Southeast

Top
#444768 - 14/12/05 07:37 PM Re: Packet Sniffer needed
Anonymous
Unregistered


hahahaha.... i thought it said:

Package Stiffener Needed. [Laughing]



[Too much XOC]

Top
#444769 - 14/12/05 08:03 PM Re: Packet Sniffer needed
Anonymous
Unregistered


I was running a capture of ethereal for fun as I hadn't done one on my laptop in a while and wanted to see if there would be something new. To generate traffic, I was still on this page, so I reloaded it but did not look at it, just my capture, and the first thing I saw was the www.viagra.com request, so I started thinking that I had something running that was pushing ads somewhere. Started doing all sort of test until I finally came back here and saw the picture. [Too much XOC]

Top
#444770 - 14/12/05 08:38 PM Re: Packet Sniffer needed
Anonymous
Unregistered


Quote:
Originally posted by BurgPath:
BID is a fire wall, isnt it?

King, good thought, I'll try that.
It used to have a sniffer built in, too.

I don't know what the current XP version does. It's probably been 5 years since I ran it; I'm just bored at work and needed to talk...

Top
#444771 - 14/12/05 09:09 PM Re: Packet Sniffer needed
Anonymous
Unregistered


I use Wildpackets at work

Top
#444772 - 15/12/05 11:39 AM Re: Packet Sniffer needed
Chris Mc Offline
Member

Registered: 16/11/00
Posts: 1535
Loc: St Charles, MO
Ethereal works quite well. The recent versions have marked improvements with some of the plugins now bundled. Make sure to disable all network protocols on the interface you are sniffing with, or your capture will be polluted with traffic you shouldn't be seeing.

You are confusing a couple network terms, however. Spanning-tree Protocol (STP) is a layer 2 network protocol used to identify and stop network loops by finding the loops and disabling network ports (blocking state) to stop them.
"Spanning" a port is a Cisco (CatOS) term used to mirror all the traffic from one port to another for network analysis. In Cisco IOS, it is done as follows:

The destination port (where you are connected with your sniffer) is FastEthernet0/1 and the source port (whose traffic you want to capture) is FastEthernet0/2.

Switch> enable
Switch# config term
Switch(config)# interface Fa0/1
Switch(config-if)# port monitor Fa0/2
Switch(config-if)# end

If you are using CatOS, it would go something like this:

The destination port (where you are connected with your sniffer) is 8/1 and the source port (whose traffic you want to capture) is 8/2.

Switch> enable
Switch> (enable) set span 8/2 8/1

You can also span an entire VLAN (ex. 510) this way:
Switch> enable
Switch> (enable) set span 510 8/1

With the default Linksys formware, you will not be able to do this. There is alternate Linux firmware available for some of the Linksys wireless routers (WRT54G series) that would give you options for doing this, but it not something that would be easy to explain. See sveasoft.com and openwrt.org for more info if this is what you have.

Top
#444773 - 24/12/05 08:10 AM Re: Packet Sniffer needed
Anonymous
Unregistered


Quote:
Originally posted by Chris Mc:

With the default Linksys formware, you will not be able to do this. There is alternate Linux firmware available for some of the Linksys wireless routers (WRT54G series) that would give you options for doing this, but it not something that would be easy to explain. See sveasoft.com and openwrt.org for more info if this is what you have.
I know this thread was a few days old - Just wanted to add my two cents on the SveaSoft Talisman Firmware *upgrade* for the Linksys WRT54G series - It's freakin SWEEET! I use the above and have added "Airsnort" to one of my meshed routers - Also, with a little work and research you can easily do a "home grown" setup...Heck...Why reinvent the wheel...There are premade *CD Linux Based* Intrusion/Penetration test tools like Phlack and Whax as well as a few others...Just Google stuff, hack away and....most importantly...Have PHUN!

Take Care,

Glenn

Top


Moderator:  Paul H 

shrockworks xterraparts
XOC Decal