Re: Tcpdump and 3des packets

From: All Mail (allmail@jeff.ath.cx)
Date: 09/21/01


Date: Fri, 21 Sep 2001 09:32:34 -0400 (EDT)
From: All Mail <allmail@jeff.ath.cx>
To: <focus-linux@securityfocus.com>
Subject: Re: Tcpdump and 3des packets
Message-ID: <20010921093051.S7404-100000@jeff.ath.cx>

On Mon, 17 Sep 2001, Anthony Baxter wrote:

>
>
> has anybody been able to use tcpdump to decrypt 3des packets, i am trying to
> vpn between freeswan and vpn 1, i need to look at these packets but tcpdump
> WILLNOT compile with crypto support
>
> mandrake 8.0
>
> this is my first posting, and i not even sure this is the right place to
> post so please forgive me.
>
> What are my options are there other sniffers that can decode 3des ???
>
>
> many thanks
>
> anthony
>

DES is a one way hash, as is 3DES. It cannot be "decrypted". The only
way to guess DES/3DES keys is to brute force them.

Jeff



Relevant Pages

  • Re: Tcpdump and 3des packets
    ... Subject: Tcpdump and 3des packets ... DES and 3DES are symmetric ciphers, ... decrypt the ciphertext. ...
    (Focus-Linux)
  • Re: Tcpdump and 3des packets
    ... Subject: Tcpdump and 3des packets ... not be very good symetric crypt would it? ... is unless you know the session key you can't decrypt it. ...
    (Focus-Linux)
  • Re: ntpd fails to synchronize on FreeBSD 6.3-STABLE
    ... 12 packets received by filter ... Then let the tcpdump go for about 15 minutes. ... Firewall on my router/gateway is disabled, ... # shutdown -r now ...
    (freebsd-stable)
  • Re: flooding an embedded device with isic and tcpreplay causing different results
    ... You can try use -nn option at tcpdump too, ... now I wondering why the tcpreplay attack don't f*** up the SOHO. ... The tcpdump isn't complete because of "dropped by kernel" packets - ... listening on eth0, link-type EN10MB, capture size ...
    (Pen-Test)
  • Re: Should route, but doesnt
    ... > I bought the Netgear box last June. ... > Packets get from the RedHat 7.2 box to my LAN or to the Internet. ... You might find it useful to watch the packets with tcpdump, ... with the private subnets. ...
    (comp.os.linux.networking)