Page 1 of 1
Sniffing
Posted: Thu Feb 05, 2004 9:19 pm
by MK888
I am trying to setup a sniffer on my network. I am using a 3Com4400 switch. I cant find where to setup a port as a monitor port, so I can monitor all traffic on the switch. Anyone know how to do this on a 3com switch??? I can sort of monitor the health of the switch through the management software, But I really want an idea of packet count..
Posted: Fri Feb 06, 2004 2:51 pm
by TheManiacal1
well you have to remember that the nature of "switching" usualy prevents you from sniffing all traffic (w/ exception to broadcast traffic). what security expert laura chappell says to do is "hub out". find your suspect user(s), disconnect them from the switch, connect them to a hub (a non-switching hub), and sniff away. suggested packet analyzers include: NAI's Sniffer and WildPacket's EtherPeek.
Posted: Fri Feb 06, 2004 4:07 pm
by Pugsley
i dont know on the 3 com.. but i know on a cisco ist possible to turn one port into a brodcast port for sniffing.
Posted: Wed Feb 11, 2004 4:12 pm
by TheManiacal1
yeah, you can do that... depending on the particular model however. there is something known as a "man in the middle" attack which simulates hubbing a port out but i'm not familiar enough with it to explain how to do it.
Posted: Wed Feb 18, 2004 8:09 pm
by Magexx9
You are right about not being able to sniff on a switched networked, because not all the traffic is broadcasted.... BUT programs do exist to sniff network traffic on a switched network. For sniffing on a hub I recommend Ethereal, but for the switched network use Ettercap. Might be a pain to get going in windows but it is possible. It's all based on man in the middle attacks, which occur at the link layer. Hope I've helped, use google and do some reading.
Magexx9
PS. DO NOT, I REPEAT DO NOT run ettercap if you a directly connected to a cable modem... You might get a nasty phone call