Hot Downloads

Welcome, Guest
Username: Password: Remember me

TOPIC: Sniffing Switched Network

Sniffing Switched Network 13 years 6 months ago #274

Hello,

Does anybody know how to sniff a switched network?

I have a network of about 50 and sometimes I would like to see what is going through some workstations. I do not want to install a sniffer on each one. Or is there something like a client/server setup where I can host the main program on mine and just put a lightweight one on theirs?...

Thanks for the help.

SLM
The administrator has disabled public write access.

Sniffing Switched Network 13 years 6 months ago #276

O.k., thanks

They have ported it to 9x/NT/2K/XP. It requires cygwin and WinPcap.

I have not tried it yet but will very soon.

Thanks for the help
The administrator has disabled public write access.

Sniffing Switched Network 13 years 6 months ago #275

  • Chris
  • Chris's Avatar
  • Offline
  • Administrator
  • Posts: 1446
  • Thank you received: 13
  • Karma: 8
To sniff a switched network is one of the coolest things one can do I recon

Thank goodness there are people out there trying really hard to make our dreams come true, and two these are ALoR & NaGA who have produced 'Ettercap' and runs under Linux, but I think they have also managed to port a version to the Windows o/s.

Ettercap is a very powerful sniffer that uses various methods (like arp poissioning) to trick the switch and make it forward packets to the port that your sniffing PC is on.

You can download your copy from http://ettercap.sourceforge.net/

Cheers,
Chris Partsenidis.
Founder & Editor-in-Chief
www.Firewall.cx
The administrator has disabled public write access.

Sniffing Switched Network 13 years 5 months ago #277

Or u can span the switch ports for a limited period of time.

This can only be done with an managed switch.

Kind regards,

John Bruijntjes
"Los Angeles, year 2029. All stealth bombers are upgraded with neural processors, becoming fully unmanned. One of them, Skynet begins to learn at a geometric rate. It becomes self-aware at 2:14 a.m. eastern time, August 29.
The administrator has disabled public write access.

Sniffing Switched Network 13 years 4 months ago #278

  • tfs
  • tfs's Avatar
  • Offline
  • Expert Member
  • Posts: 521
  • Karma: 0
If you want to see what is going on some of the switches, you can also hook up a HUB (not a linksys hub, as it is actually a switch) and put all the workstations you wish to watch (as well as the workstation that has the protocol analyzer on it).

In my case, I used to put my SQL Server on one of the ports as well as the Protocol Analyzer and watched that way. This worked because the only networked traffic we had was from all the workstations to the SQL Server.

You don't want to do this all the time as it will slow down the network.
Thanks,

Tom
The administrator has disabled public write access.
Time to create page: 0.081 seconds

CCENT/CCNA

Cisco Routers

  • SSL WebVPN
  • Securing Routers
  • Policy Based Routing
  • Router on-a-Stick

VPN Security

  • Understand DMVPN
  • GRE/IPSec Configuration
  • Site-to-Site IPSec VPN
  • IPSec Modes

Cisco Help

  • VPN Client Windows 8
  • VPN Client Windows 7
  • CCP Display Problem
  • Cisco Support App.

Windows 2012

  • New Features
  • Licensing
  • Hyper-V / VDI
  • Install Hyper-V

Linux

  • File Permissions
  • Webmin
  • Groups - Users
  • Samba Setup