Forums: Req Help With Backtrack - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Req Help With Backtrack Need tut on Nessus & Ethereal

#1 User is offline   No Dice 

  • Master Sergeant
  • Icon
  • Group: Second Lieutenant
  • Posts: 645
  • Joined: 26-June 05

Posted 10 February 2006 - 09:34 AM

Would any one be so kind as to give a step by step tutorial for properly starting and running Nessus and Ethereal? Nessus is for scanning my local LAN and Id like to setup ethereal to sniff traffic on another PC on my LAN. I'd also like to be updated with the latest nessus downloads so if you could add that as well...

Me 192.168.1.100
BTrk 192.168.1.101

How do I tell ethereal to sniff 192.168.1.100? Im just curious to see if it captures my passwords and so on?

Thanks much..
0

#2 User is offline   webdevil 

  • General
  • Icon
  • Group: General
  • Posts: 931
  • Joined: 21-October 05

Posted 10 February 2006 - 06:45 PM

To sniff 192.168.1.100
you could just type in 'ip.addr eq 192.168.1.100' in the filter bar.
you can sniff almost all ftps,telnet and websites that transmit username/password without encryption i.e unlike Yahoo and Hotmail.
Ofcourse it shouldnt be on a lan using a switch. Then maybe you could poison it ... I mean ARP posioning.
0

#3 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 11 February 2006 - 01:31 AM

for nessus on backtrack, simply run nessus-start, and you will see a screen asking the server to connect and the username/password. By auditor, the host should be localhost, the username/password is auditor/auditor (if it doesn't work, try backtrack/backtrack). Then choose the plugins to run (suggestion: enable all but dangerous plugins) and start scanning.
To update nessus, simply run nessus-update-plugins or download the latest nessus version (should be 3.0).
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#4 User is offline   No Dice 

  • Master Sergeant
  • Icon
  • Group: Second Lieutenant
  • Posts: 645
  • Joined: 26-June 05

Posted 11 February 2006 - 05:42 AM

That cleared up any doubts that I had and appreciate the replies.. Im a typical Windows hero just trying to get by in a Linux world
0

#5 User is offline   RANGER 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 45
  • Joined: 24-December 05

Posted 12 February 2006 - 12:15 PM

For you to run nessus you have to start the nessus server "nessusd" first, you can also just type nessus and hit the "Tab" button twice and it will show you all the nessus command options there is, Now for sniffing another Ip when it's using switched ports you can use ethereal in a combination with "arpspoof" and "dnsspoof" to grab that traffic.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting