RE: sniffer in promiscuous mode

From: d'Ambly, Jeff (jdambly@monster.com)
Date: 02/06/02


From: "d'Ambly, Jeff" <jdambly@monster.com>
To: "'Siddharta Govindaraj'" <govind@iiitb.ac.in>, security-basics@securityfocus.com
Date: Wed, 6 Feb 2002 11:43:51 -0500 

That is really strange, I have used ethereal for a long time now, I would
agree that your winpcap install is messed up, there is nothing special you
need to do to get tcp packets, oh and check your filters too, good luck.

-- Jeff d'Ambly
Network Engineer
http://www.monster.com
--------------------------------
Stay the patient course.
Of little worth is your ire.
The network is up.

 -----Original Message-----
From: Siddharta Govindaraj [mailto:govind@iiitb.ac.in]
Sent: Tuesday, February 05, 2002 10:04 AM
To: security-basics@securityfocus.com
Subject: sniffer in promiscuous mode

Hi,

I have a funny problem with the ethereal packet sniffer. It correctly
captures all packets entering or leaving my interface, but in promiscuous
mode, it only seems to capture ARP, NETBIOS, IPX, RIP and such protocols,
and never seems to get any UDP or TCP packets ! I have tried other sniffers,
and they all exhibit the same behaviour, so I dont think its a sniffer
problem. Is there something else I have to do to capture TCP packets ? Or
could it be something to do with Wincap ?

Thanks
Siddharta



Relevant Pages

  • RE: sniffer in promiscuous mode
    ... Are you in a switched environment? ... traffic from one port to another) so the port with the sniffer gets copies ... Subject: sniffer in promiscuous mode ... Is there something else I have to do to capture TCP packets? ...
    (Security-Basics)
  • RE: not able to sniff TCP packets
    ... In case your network is not switched, I would suggest that you check to see if your sniffer does turn on the "sniff" mode on the NIC so that you can see all traffic. ... I cant see TCP packets send by another computer to another ... computer.I only see is my tcp packets. ...
    (microsoft.public.win32.programmer.networks)
  • not able to sniff TCP packets
    ... when we sniff the network, ... using sniffer, I cant see TCP packets send by another computer to another ... computer.I only see is my tcp packets. ...
    (microsoft.public.win32.programmer.networks)
  • RE: That dont look good!
    ... > the capture stopped. ... there are entries in the firewall log ... >first and third times I had the sniffer going. ...
    (Focus-Linux)
  • Re: Can trojan bypass sniffer?
    ... a sniffer is designed to capture ALL traffic originating from within ... if the sniffer has been configured to only ... capture traffic of a certain protocol and the trojan in question is designed ... > frames for emails to make sure that I do not have ...
    (comp.security.firewalls)