Forums: What Is The Best Lan Sniffer? - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

What Is The Best Lan Sniffer? Passwords Sniffer

#1 User is offline   UnDeRTaKeR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 143
  • Joined: 30-November 03

Posted 18 March 2004 - 06:22 AM

Hello
I'm looking for a lan sniffer that can find out passwords out of the network...
Prefer me sniffers that you sure they work and you've tested it.. 10x
0

#2 User is offline   MsMittens 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 258
  • Joined: 15-March 04

Posted 18 March 2004 - 06:26 AM

Ettercap is amazingly good and very scary as to how much information it picks up. It's good in LAN setup but can be noisy (lots of ARP broadcasts). It does a MITM/Hijack as well as other "features".

Otherwise, old fashioned tcpdump does the trick for me. :)
0

#3 User is offline   SteveW 

  • Sergeant
  • Icon
  • Group: Specialist
  • Posts: 239
  • Joined: 01-July 03

Posted 18 March 2004 - 07:04 AM

Another oldie but a goodie is Cain and Able.
AKA SgtRush
0

#4 Guest_SyN/AcK_*

  • Group: Guests

Posted 18 March 2004 - 07:14 AM

I'm going to definitely agree with Cain and Abel. Especially if you are on a network with Windows machines, its great cuz it will sniff out the Lanman and NTLM hashes to be cracked.
0

#5 Guest_OneNight_*

  • Group: Guests

Posted 18 March 2004 - 09:14 AM

Small note for ppl on broadband.

Many ppl use the modem placed there by their isp to which the ethernet card connects. One of the most popular ones are the cybersurfr wave modems by motorola. Problem with using packet sniffers is that the modem does not act like a bridge.

Here is a slightly more technical explanation:
The CyberSurfr system does not operate like conventional CableModems.
It's not a bridge device. Motorola uses a propreiatary protocol to
connect each modem to the router in a method that's a lot like ATM's
concept of PVC's -- Private Virtual Circuits. Other people's data is
there but you can't see it because it's in their session with the CMTS,
not yours. Even if you found a way to see it, it's 40 bit encrypted,
which ain't great, but it's sure going to stop the average 15 year old
hacker.

The only traffic you will be able to see that's not SPECIFICALLY
destined to you is traffic broadcast by the CMTS to all subscribers
(usually an ARP broadcast). You CANNOT see traffic unicast or broadcast
from any other subscriber.


So you wont be sniffing anything useful. Of course its -possible- to bypass it but for ppl with an average know how its just not worth it.

Just keep this in mind if you dont get the desired results...
0

#6 User is offline   Pro21 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 230
  • Joined: 12-February 04

Posted 18 March 2004 - 09:52 AM

what is the OS where you want sniff ?

Windows => Ethereal is very good
Linux => I like Dsniff :)

Like say OneNight sniffing all packets is very difficult with the last network hardware who secure connexions in a network :P But it s work with some research and test ;)
0

#7 User is offline   setthesun 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 574
  • Joined: 13-February 04

Posted 18 March 2004 - 10:04 AM

For windows I like Eeye IRIS, with iris it's easy to sniff e-mail, web etc. with really good GUI

setthesun me = new setthesun();
0

#8 User is offline   muts 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 29
  • Joined: 09-January 04

Posted 19 March 2004 - 01:37 AM

Commview is my favorate.

Cain and able are "password sniffers" not a real sniffer.
0

#9 User is offline   Pro21 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 230
  • Joined: 12-February 04

Posted 19 March 2004 - 02:29 AM

yes iris is very easy to use and very good GUI interface :)
Great tool, it s true ;)
0

#10 User is offline   fuze 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 35
  • Joined: 26-February 04

Posted 22 March 2004 - 10:13 AM

i love ettercap :lol:, really great as MsMittens already said! (she always says good stuff :))
0

#11 User is offline   predx 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 108
  • Joined: 03-December 03

Posted 29 March 2004 - 05:24 AM

i use trying Eeye iris but latley been feeling that it isnt working as well as it should.
0

#12 User is offline   technoboy 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 120
  • Joined: 10-January 04

Posted 29 March 2004 - 10:02 AM

IRIS > *
0

#13 User is offline   Psychotec 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 83
  • Joined: 09-March 04

Posted 04 April 2004 - 06:11 AM

well, there are a lot of them, for example:

ps. i like Cain & Abel and its my favorite. Also ettercap is a good one too.

Analyzer

Description
Packet Analyzer for Windows NT. Takes snapshots of ethernet traffic; adjustable buffer and filter; output written to file and screen.



Buttsniff-0_9_3

Description
BUTTSniff plugin for Back Orifice. Updated version


Packet Sniffer 2

Description
Packet Sniffer 2.0 - Nice free packet sniffer for Win32.


Winsniffer 1.1

Description
Winsniffer is a packet sniffer for the Windows console designed to be effecient and flexible. Screenshot available here. This is a trial version. Homepage: http://winsniff.hypermart.net.


Also good programs for sniffers:


Rnbtname

Description
Rnbtname.exe does the reverse - it takes the mangle and converts it back into a NetBIOS name - perfect for sniffers.



Vpacket

Description
How to make your own sniffers for windows.


Enjoy the info :P and good luck with it
0

#14 User is offline   K0ZZM0 

  • Private
  • Icon
  • Group: Members
  • Posts: 1
  • Joined: 15-March 04

Posted 04 April 2004 - 09:00 AM

just a question for you guys...
maybe a dumb one but I was wondering if...
When you do some packet sniffing on a lan...
is it detectable...?
and how?
0

#15 User is offline   MsMittens 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 258
  • Joined: 15-March 04

Posted 04 April 2004 - 09:11 AM

Yes and no. Depends on the tool. Passive tools like TCPDump are pretty undetectible because they are just that. Passive. They listen like an eavesdropper on the phone.

Active tools like Ettercap, which do MITM techniques and use massive arp broadcasts, can be detected online (if used in their password collection state). So tools that actively go in search of hosts to monitor would be detectable. I can usually figure out ettercap usage (my students do play with it a lot in the wargames I run in class) by firing up tcpdump and watching for massive broadcast arp requests.
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting