Re: Sniffer - Where to install

From: Andy H (andyh_at_dev.null)
Date: 06/02/03


Date: Mon, 02 Jun 2003 06:10:01 GMT


How does that work Sam?
What gives it the ability to sniff everything on the network?

If traffic doesn't pass across the NIC then how does it gather the
information? Especially in a switched/segmented network where traffic isn't
repeated to each device.
The SMS version allows this?

Very curious. Never tried the netmon sniffer.

Thanks

A

"Sam Salhi [MSFT]" <samers@online.microsoft.com> wrote in
news:uVvijWMKDHA.1828@TK2MSFTNGP10.phx.gbl:

> I thought I gave that away when I specified the edge of the network,
> but you're absolutely correct,
> If a person wants to sniff some traffic, using the standard NETMON
> (not the one that is capable of sniffing entire network traffic) Then
> the sniffer should be located on the machine that will either act as a
> Client or a server of the service being requested.
> With that said, this isn't the case for the SMS version of NETMON,
> since any machine on the network with this version will be able to
> sniff everything going on the network.
>



Relevant Pages

  • Re: sniffing plaintext protocols
    ... You can sniff traffic between two or more hosts if you ... are on the same network. ... you would see all the packets to/from all the ...
    (Pen-Test)
  • Re: Sniffing on switched networks.
    ... zeebop wrote: ... > like ethereal to sniff traffic from other PC's on the same network? ... > hardware I could get to replace the current switch? ...
    (alt.computer.security)
  • Re: WWW-Authenticate error
    ... I tend to get that as a response every time I suggest a network ... and to see what the server sent/received. ... But I have no idea what a network sniff is or how to take one? ... A "client" may be your browser, ...
    (microsoft.public.security)
  • Re: Detecting Sniffers?
    ... Sniff Host A from Host B. Have Ethereal capture on Host ... Since Ettercap poisons the ARP tables, ... > sniffer on the network. ...
    (Security-Basics)
  • Re: kerbcrack and kerbsniff
    ... Note that switches do NOT defeat sniffing like this. ... it will sniff the kerbero activities on the network. ... > character, number, and special character. ...
    (microsoft.public.win2000.security)