Re: Tcpdump and 3des packets

From: Marc Soda (msoda@aspre.net)
Date: 09/24/01


Date: Mon, 24 Sep 2001 09:21:34 -0400 (EDT)
From: Marc Soda <msoda@aspre.net>
To: <focus-linux@securityfocus.com>
Subject: Re: Tcpdump and 3des packets
Message-ID: <Pine.LNX.4.33.0109240912490.1582-100000@localhost.localdomain>

On Fri, 21 Sep 2001, All Mail wrote:

> On Mon, 17 Sep 2001, Anthony Baxter wrote:
>
> >
> >
> > has anybody been able to use tcpdump to decrypt 3des packets, i am trying to
> > vpn between freeswan and vpn 1, i need to look at these packets but tcpdump
> > WILLNOT compile with crypto support
> >
> > mandrake 8.0
> >
> > this is my first posting, and i not even sure this is the right place to
> > post so please forgive me.
> >
> > What are my options are there other sniffers that can decode 3des ???
> >
> >
> > many thanks
> >
> > anthony
> >
>
> DES is a one way hash, as is 3DES. It cannot be "decrypted". The only
> way to guess DES/3DES keys is to brute force them.

Wrong. DES and 3DES are symmetric ciphers, they require a key to
decrypt the ciphertext. You are thinking of MD5, HMAC/SHA1, they are
one way digest algorithms.

Anthony,

There may be sniffers out there that will decrypt 3DES, but in all
cases you need the encryption/decryption key.

-- 

Marc Soda ASPRE, Inc. marc@aspre.net http://www.aspre.net/



Relevant Pages

  • Re: Tcpdump and 3des packets
    ... Subject: Tcpdump and 3des packets ... On Mon, 17 Sep 2001, Anthony Baxter wrote: ... > has anybody been able to use tcpdump to decrypt 3des packets, ...
    (Focus-Linux)
  • Re: Tcpdump and 3des packets
    ... Subject: Tcpdump and 3des packets ... not be very good symetric crypt would it? ... is unless you know the session key you can't decrypt it. ...
    (Focus-Linux)
  • Re: ntpd fails to synchronize on FreeBSD 6.3-STABLE
    ... 12 packets received by filter ... Then let the tcpdump go for about 15 minutes. ... Firewall on my router/gateway is disabled, ... # shutdown -r now ...
    (freebsd-stable)
  • Re: Should route, but doesnt
    ... > I bought the Netgear box last June. ... > Packets get from the RedHat 7.2 box to my LAN or to the Internet. ... You might find it useful to watch the packets with tcpdump, ... with the private subnets. ...
    (comp.os.linux.networking)
  • Re: Could Not open some sites from Windows Vista and Server 2008 when using FreeBSD as gw
    ... tcpdump: verbose output suppressed, use -v or -vv for full protocol decode ... 433 packets received by filter ... block rules also log the blocked packets -- in this case that should ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
    (freebsd-stable)