Re: Sniffer - Where to install

From: Andy H (andyh_at_dev.null)
Date: 06/02/03


Date: Mon, 02 Jun 2003 03:47:09 GMT


Not to debate which sniffer is better but wasn't his original question
about location of the sniffer?

You must choose wisely on the location. Think of what traffic do you want
to sniff - If it's the entire lan then you must plug into a switch that
will see all traffic you desire. You will also have to setup some port
mirroring in the switch to the port that you will connect the sniffer to,

Above being said barring any collection agents and such on the network.

"Sam Salhi [MSFT]" <samers@online.microsoft.com> wrote in
news:Ohu7SHJKDHA.1608@TK2MSFTNGP11.phx.gbl:

> Actually, it does way more than just that
> If I list what netmon will do, It will probably take too long but here
> is the tip of the iceberg
> get all traffic in or out
> filter by a specific IP or number of Ip's
> Filter by a specific protocol or number of protocols (http/smtp/ftp
> you name it) even unspecified protocols (proprietary)
> use experts to get correlate related packets
> programmatically capture specific packets
> and tons of other features.
>
>



Relevant Pages

  • Re: "Smart" Hubs
    ... >go for a switch that let's you monitor traffic on other ports. ... I think most managed switches let you do this. ... Note that both hubs and port cloning imply bandwidth limitations: ... sniffer on a single link. ...
    (freebsd-hackers)
  • Re: Sniffing a Switched Network
    ... Subject: Sniffing a Switched Network ... you have to mirror a port. ... and your mail server is in port 12 on your switch. ... you plug your sniffer into port 16. ...
    (Security-Basics)
  • Re: RE: sniffing packets on a switch
    ... I made use of arpspoof(guess is part of dsniff utility) to sniff the ... sniffing packets on a switch ... > received on a given port to another port. ... > specifically to the sniffer host. ...
    (Security-Basics)
  • RE: sniffing packets on a switch
    ... sniffing packets on a switch ... received on a given port to another port. ... specifically to the sniffer host. ...
    (Security-Basics)
  • RE: Outgoing Port Check
    ... run nmap on the inside. ... One the sniffer, limit the sniffing to the host ... Subject: Outgoing Port Check ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)