sniffing network
Results 1 to 8 of 8

Thread: sniffing network

  1. #1
    Member
    Join Date
    Aug 2004
    Posts
    95

    sniffing network

    When I am working in netowrk, how do they find my password. Is there any way they can sniff my password in windows network?

    I use winxp sp2, NTLM authentication enabled. Even is they sniff will they be able to decript the password.

    please clarify my doubts.

  2. #2
    AO übergeek phishphreek's Avatar
    Join Date
    Jan 2002
    Posts
    4,324
    Yes, it is possible to sniff and crack your password. There are plenty of tools out there to do this.

    LC5: http://www.atstake.com/products/lc/

    Cain and Abel: http://www.oxid.it/

    KerbCrack: http://ntsecurity.nu/toolbox/kerbcrack/

    They are just a few of the many that can break your password after captured.
    Quitmzilla is a firefox extension that gives you stats on how long you have quit smoking, how much money you\'ve saved, how much you haven\'t smoked and recent milestones. Very helpful for people who quit smoking and used to smoke at their computers... Helps out with the urges.

  3. #3
    Member
    Join Date
    Aug 2004
    Posts
    95
    Wonderful.

    Thank you, I have tried LC5, Kerbcrack & Kerbsniff. I will try cain&able.

    LC5 has the ability to sniff SMB if the network is broadcast network, it dose not work if it is switched network. I dont think Kerbcrack & Kerbsniff can be used to sniff all kinds of authentication e.g., ssl, https, ftp etc.,

    But going through the description of Cain&able it seems it has wider applicablity than the other two applications. Let me try out.

    Any way thank you very much.

  4. #4
    AO übergeek phishphreek's Avatar
    Join Date
    Jan 2002
    Posts
    4,324
    You can use those sniffers on a switched lan. You just have to use something like ettercap before to flood the arp tables. While using ettercap, you can use the other programs to sniff too.
    Quitmzilla is a firefox extension that gives you stats on how long you have quit smoking, how much money you\'ve saved, how much you haven\'t smoked and recent milestones. Very helpful for people who quit smoking and used to smoke at their computers... Helps out with the urges.

  5. #5
    Senior Member
    Join Date
    Jun 2004
    Posts
    379
    Why dont you just ethereal and sniff all the packets going in and our of the network you can fiter by mac address if you only want a sertin node.

  6. #6
    If want to get a really good sniffer, get Ethereal here at http://www.ethereal.com/download.html.

  7. #7
    Did someone said Pizza :) FanacooL's Avatar
    Join Date
    Oct 2004
    Location
    Karachi , Pakistan
    Posts
    466
    You can also try IRIS . I like the GUI interface of the software.
    One machine can do the work of fifty ordinary men. No machine can do the work of one extraordinary man!

  8. #8
    Member
    Join Date
    Aug 2004
    Posts
    95
    Thank you all.
    I will try all you said.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

 Security News

     Patches

       Security Trends

         How-To

           Buying Guides