Re: How to sniff packets from afar?

From: Dug Song (dugsong@monkey.org)
Date: 11/09/01


Date: Thu, 8 Nov 2001 18:25:23 -0500
From: Dug Song <dugsong@monkey.org>
To: pen-test@securityfocus.com
Subject: Re: How to sniff packets from afar?
Message-ID: <20011108182523.P31718@naughty.monkey.org>

On Thu, Nov 08, 2001 at 03:40:00PM -0500, ET LoWNOISE wrote:

> You dont need to own the router, you can use your pc to become a
> routerthen spoof the routing protocols used to reroute the traffic
> to you and then sniffit.

besides route hijacking (oy), there's also RMON, which was designed
ages ago for exactly this purpose. that is, if you're lucky enough to
find an open device that supports the filter and capture groups, and
can tolerate potentially lossy sniffing:

        http://www.csu.edu.au/special/auugwww96/proceedings/wang/wang.html

perhaps Robert Graham would like to chime in here? :-)

-d.

---
http://www.monkey.org/~dugsong/

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • Re: faster scans? (nmap)
    ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: pen test help please asap
    ... > Machine A on client site makes a configurable encrypted OUTBOUND ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ettercap help
    ... Anyways have never tried Ettercap for VNC. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: CFM SQL injection
    ... You should better use union or alike get unauthorized data from the ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: ettercap help
    ... > I can get it to sniff telnet, ftp, pop, smb, but no vnc. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)