RE: Sniffers, scanners and XP raw packet drivers

From: gwasson@icsalabs.com
Date: 12/13/01


From: gwasson@icsalabs.com
To: simon@derision.net
Date: Thu, 13 Dec 2001 14:18:01 -0500

Here are the docs from the ethereal web page. I was able to make it work
with XP Pro using the beta WinPCAP driver.

G.

If you are using Windows XP, read the next two paragraphs before proceeding
any further!!!
If you are using Windows XP, the current version of the WinPcap packet
driver will NOT work; you will have to use the 2.3 beta version. As it is a
beta version, it may have more bugs than the current version; please report
those bugs to winpcap@netgroup-serv.polito.it, so that they can try to fix
them for the final 2.3 release.

The 2.3 beta download is available from the WinPcap download page; it
appears after the 2.2 download. If you are using Windows XP, do not download
and install WinPcap 2.2, as it will not work. If you want to be able to
capture packets with Ethereal on Windows XP, you must download and install
the 2.3 beta version; note that it's a beta version, so if you install it,
the risk that you will encounter bugs is greater.

-----Original Message-----
From: Simon [mailto:simon@derision.net]
Sent: Thursday, December 13, 2001 7:51 AM
To: PenTest
Subject: Sniffers, scanners and XP raw packet drivers

Folks,

Anyone had any success getting Ethereal and other tools to work under
Windows XP Pro?
even if Winpcap installed:

  Ethereal won't find an interface,
  ISS can't find raw packet drivers for some of its scans are disabled
  Nmapnt can't find any suitable interfaces
  Foundstone fport won't resolve ports to process owners (although fscan
and superscan run fine)
  .... (the list goes on)

All these worked on my laptop nicely under Windows 2000? Does anyone
have a solution to this? I guess what I need is a raw packet capture
driver that works under winXP... Any ideas?

Aaarrrgggh,

Simon, CISSP

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Beryl options and nvidia
    ... >>> I have beryl running with nvidia prop. ... indication that the 1.0-9629 beta driver was the first driver to ... provide support for TFP, not that the support was incomplete. ... included) who would gladly help nVidia test beta versions of your ...
    (Fedora)
  • Re: Beta - Word
    ... Ok it is a system restore - just wanted to make sure. ... It has to be the driver - I uninstalled and reinstalled the driver and it ... I cannot tell you how happy I am that your advice to uninstall and install ... Beta software is 'test drive' level, ...
    (microsoft.public.word.docmanagement)
  • Re: Who can tell me where I can download the WDK?
    ... The latest LH Server Beta 3 WDK release is available on ... on the beta program, you just need your .NET passport to enroll. ... If you do not see Windows Logo Kit, ... Windows Driver Framework in the Available Connections list, ...
    (microsoft.public.development.device.drivers)
  • Re: Setting Pagefile to help with Userenv 1508
    ... Yes, you should be nervous about loading a Beta, especially given ... instructions on creating a custom printer driver mapping file: ... Windows 2000 Terminal Services server logs events ... but I do also notice some funky printer driver ...
    (microsoft.public.windows.terminal_services)
  • Re: redistribution
    ... The current beta license doesn't include redist rights because the intent of ... the beta is to not be a production product. ... Our plan for the production release of this driver is to offer free redist ...
    (microsoft.public.sqlserver.jdbcdriver)