Re: hunt tool

From: Eric Hagen (eric_at_sandpile.net)
Date: 10/23/03

  • Next message: Kelly Martin: "Re: Kernel Bridge and Traffic Shaper"
    Date: Wed, 22 Oct 2003 18:58:47 -0500
    To: Jorge Garcia <anarkophobia@linuxmail.org>
    
    

    Hunt is a packet sniffer, much like Dsniff. It relies on Layer 2
    transmissions to intercept traffic. Except where you can spoof a DNS or
    an entire subnet or place yourself in the middle of the stream by
    sniffing from a router or broadcast network which is on the path the
    packets are traveling, it's really impossible to "sniff" traffic off a
    different subnet.

    Plus, anything exploit that would allow remote sniffing should (and
    hopefully would) be locked down as much as possible by the network
    administrator. As a result, sniffing telnet sessions off the Internet
    using hunt is neither practical nor usually even possible.

    Eric

    ---------------------------------------------------------------------------
    Visual & Easy-to-use are not words that you think of when talking about
    network analyzers. Are you sick of the three window text decodes? Download ClearSight Network's Analyzer and see a new network analysis tool that
    makes the complex - easy
    http://www.securityfocus.com/sponsor/ClearSightNetworks_security-basics_031021
    ----------------------------------------------------------------------------


  • Next message: Kelly Martin: "Re: Kernel Bridge and Traffic Shaper"

    Relevant Pages

    • Re: Locking down Snort
      ... Sniffing is done at the Link Layer and IP is at the ... Network Layer. ... > You didn't say whether you are using windows or linux Snort. ... > pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Re: Intrusion possible?
      ... >associates before you can actively attack that network. ... I leave my laptop running in my vehicle sniffing away merrily. ... mess after doing the capture took most of the next day. ... Jeff Liebermann jeffl@xxxxxxxxxxxxxxxxxxxxxx ...
      (alt.internet.wireless)
    • RE: A Solution for sniffing
      ... > Now i know there are hardware devices that you can plug into that will allow ... is likely seeing all the network traffic, ... > There ARE ways to detect sniffing, ... >> least is by switching from a hub type network ...
      (Security-Basics)
    • Re: Is SSH worth it??
      ... > On an internal network that is switched is it ... > worth going to SSH and SCP?????? ... > real threat is sniffing the traffic. ...
      (Security-Basics)
    • RE: Network scanning: Continued (newbie)
      ... Please see Confidentiality Notice before reading email. ... I don't think an ip address is required for sniffing. ... Subject: Network scanning: Continued ... Pretty much the same idea as mac filtering. ...
      (Security-Basics)