Results 1 to 7 of 7

Thread: sniffers detection tools

  1. #1
    Senior Member
    Join Date
    Dec 2002
    Posts
    144

    sniffers detection tools

    is there an open source sniffers detection tools?
    BlAcKiE
    GearBlitz

  2. #2
    Just a Virtualized Geek MrLinus's Avatar
    Join Date
    Sep 2001
    Location
    Redondo Beach, CA
    Posts
    7,323
    Lots of them. The following 3 sniffers are the most well known:

    TCPDump

    Ethereal

    Ettercap

    For IDS (detection) probably the most well-known is

    SNORT

    Prelude-IDS is a newer, hybrid IDS.
    Goodbye, Mittens (1992-2008). My pillow will be cold without your purring beside my head
    Extra! Extra! Get your FREE copy of Insight Newsletter||MsMittens' HomePage

  3. #3
    Senior Member Kite's Avatar
    Join Date
    Jan 2005
    Location
    Underground Bunker, somewhere in Antarctica
    Posts
    109
    i have Ethereal, it is a very easy program to use after setting it up.
    I know your type, you think "I'll just get me a costume, rip off the neighborhood kids". Next thing you know, you've got a jet shaped like a skull with lasers on the front!
    -The Monarch.

  4. #4
    Senior Member
    Join Date
    Dec 2002
    Posts
    144
    Originally posted here by MsMittens
    Lots of them. The following 3 sniffers are the most well known:

    TCPDump

    Ethereal

    Ettercap

    For IDS (detection) probably the most well-known is

    SNORT

    Prelude-IDS is a newer, hybrid IDS.
    i wanna detect someone is sniffing my network..
    is there such tools?
    BlAcKiE
    GearBlitz

  5. #5
    Just a Virtualized Geek MrLinus's Avatar
    Join Date
    Sep 2001
    Location
    Redondo Beach, CA
    Posts
    7,323
    Hrmm.. depends on how the person is sniffing. If they are doing active sniffing (involving arp poisoning) they'll be easy enough to see using simple packet sniffers I've identified above. If they are passively sniffing that can be harder but is possible to a degree. This PDF WhitePaper on Promiscuous NIC Detection can help.

    Tools like ArpMonitor, AntiSniff (no longer in production?) and a few others would be what you're looking for. Take a gander at SecurityFocus' Sniffer section
    Goodbye, Mittens (1992-2008). My pillow will be cold without your purring beside my head
    Extra! Extra! Get your FREE copy of Insight Newsletter||MsMittens' HomePage

  6. #6
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867
    Have a look at AntiSniff , I never used it, but it kind of looks like what your asking for.

    Cheers:


    /edit
    Sorry MsM, I thought AntiSniff was still available.....
    DjM

  7. #7
    Just a Virtualized Geek MrLinus's Avatar
    Join Date
    Sep 2001
    Location
    Redondo Beach, CA
    Posts
    7,323
    Ever since l0pht went to @Stake a lot of their former good tools went "bye-bye".
    Goodbye, Mittens (1992-2008). My pillow will be cold without your purring beside my head
    Extra! Extra! Get your FREE copy of Insight Newsletter||MsMittens' HomePage

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •