    the developers pack isn't necessary as their is a pre-compiled binary version available.

    is you just want a sniffer to fool around with (ethereal is dead serious) try packetmon from anologX
    don't forget about ettercap for sniffing on switched networks, they have a windows version.

    what is the diference?

    I know I'm not the one who started this thread, but what is the difference between the two, ethereal and packetmon? And yes I would just be learning it for the time being. Thanks


    etherreal gives much more detailed information, breaking the entire packet down into its relevant fields (flags, protocol, etc.) for indepth analyasis. and has many advanced features. if your looking to optimize a network this is the tool.

    screen shots:


    packetmon is bare bones showing you the contents of the packet in ascii or binary.

    screen shot:


    they both have advanced filtering. They both can output to a file in csv format. They're both free.

    most of the time when i use a packet sniffer im interested in the ascii content and dont need all the related info.
    If your looking for a really robust one and cost is not an issue (that is if maybe your
    "specking" one out for a client or your company) then NAI's (network associates)
    SnifferPro is the industry's choice. It's not cheap though..Unless you pick up a copy from Ebay..

    Alittle history on SnifferPro..

    A few yrs back, Network General was the dominant vendor when it came to protocol analyzers.
    They had a product called network General Sniffer/ DOS based..The software back then ran for about 30,000 and each NIC you installed was proprietary and costed about 5-10k,,,
    (yea I know ridiculously expensive) but it was every major financial company's choice...

    I remember carrying one in subways of NY city fully loaded with every NIC (about 100K worth)

    Later on a company called (not sure of spelling) Cinconet had a reall nice GUI product
    called NetXray..It was nice GUI interface but not as robust as Network General Dueltsch Sniffer..

    Then NAI bought the two products and created SNifferPro..(Its an Awsome tool)
    Also its not as expensive as the DOS version was..and NIC cards are no longer

    Just a personal opinion..

    Ethereal is what I recommend if your looking for a free product....

    Analog X is a great little sniffer. I can't believe I forgot to mention it. Thanks Tedob1 for throwing that link up. I tried to reward you but the good ol' AP system wont have it.

    I agree that SnifferPro is the bomb. I love the dashboard display but the only problem is the pricetag. I had a copy at my last job and even then it was 27K for one license.

    27k for a license , It better give you a bj every morning for that price *off i go to figure out what makes the proggy worth so very much*
