Networking Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationNetworking Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old March 26th, 2004, 12:30 PM
JamieH JamieH is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Posts: 54 JamieH User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 2 m 28 sec
Reputation Power: 5
Question Switch sniffer

Hi all,

I have a LAN network completely hooked up via some switches. The switches route traffic to a certain port based on the MAC address in the traffic.

What I want to do it to sniffer the traffic on my LAN network. Is it possible to configure a switch in such a way that all traffic going thru the switch is copied to my "sniffer" port on the switch? Or do I need a sniffer or some hubs on the LAN to archieve this??

Thanks in advance
Jamie

Reply With Quote
  #2  
Old March 26th, 2004, 01:19 PM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
I seen a sniffer that claims it can go through switched networks yet Im not that convinced and I forgot the name.
On a cisco switch plug into a port with sniffer and enable port monitoring for all the ports. This is very intensive for the switch to do all ports but will work. Usualy you only monitor one port at a time. Port monitoring will have all traffic on one interface duplicate it under the monitoring port so you can unintrusively sniff. I know you can do this with just about every manageable switch not just cisco but their terminology is different.

Reply With Quote
  #3  
Old March 31st, 2004, 05:14 PM
blaqb0x blaqb0x is offline
blaqb0x
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Posts: 87 blaqb0x User rank is Sergeant (500 - 2000 Reputation Level)blaqb0x User rank is Sergeant (500 - 2000 Reputation Level)blaqb0x User rank is Sergeant (500 - 2000 Reputation Level)blaqb0x User rank is Sergeant (500 - 2000 Reputation Level)blaqb0x User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 12 h 16 m 20 sec
Reputation Power: 13
I heard a linux utility called "hunt" can sniff on a switched network. Also there was an article on this here

http://www.neworder.box.sk/newsread.php?newsid=10388

higher end hp procurve switch aslo have 'port monitoring'

Reply With Quote
  #4  
Old April 2nd, 2004, 02:35 AM
Roding Roding is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Posts: 5 Roding User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Send a message via MSN to Roding
There is a program called ettercap that you can use to sniff on a switched network.. it is not very easy to use but you can always try it... both Win and Linux

Reply With Quote
  #5  
Old April 2nd, 2004, 07:34 AM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
Thats the one I seen Ettercap. Could not remember the name hehe. still easier to put the switches in port monitoring as a full sniff of a network consisting of only 10 minutes could generate a 100 Meg file to sift through with say 50 PCs. its more productive to go after a certain device like all traffic hitting the server.

Reply With Quote
  #6  
Old April 3rd, 2004, 10:54 AM
JamieH JamieH is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Posts: 54 JamieH User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 2 m 28 sec
Reputation Power: 5
Sounds good that there is a utility which can sniff on a switched network.

Will see if I can find the program (I guess it is not capture program you run in Ethereal?) - and mail a message when I know how this program works

Thanks
Jamie

Last edited by JamieH : April 3rd, 2004 at 11:18 AM.

Reply With Quote
  #7  
Old April 5th, 2004, 03:23 AM
christo's Avatar
christo christo is offline
Introspective
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2001
Location: London, UK
Posts: 3,296 christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 3 Days 1 h 5 m 42 sec
Reputation Power: 101
Send a message via ICQ to christo Send a message via Yahoo to christo
dsniff

christo

Reply With Quote
  #8  
Old April 7th, 2004, 08:48 AM
dbasnett dbasnett is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Posts: 107 dbasnett User rank is Lance Corporal (50 - 100 Reputation Level)dbasnett User rank is Lance Corporal (50 - 100 Reputation Level)dbasnett User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 10 h 11 m 43 sec
Reputation Power: 5
Your original post was correct. To sniff a switched network you need a switch that is capable of mirroring traffic to one port.

If your switch is not capable of that you can sniff individual links by connecting a hub to a link, connect the original device and sniffer to the hub. But you will only see multicast, broadcast, and traffic to that device.

Reply With Quote
  #9  
Old April 7th, 2004, 09:05 AM
christo's Avatar
christo christo is offline
Introspective
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2001
Location: London, UK
Posts: 3,296 christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 3 Days 1 h 5 m 42 sec
Reputation Power: 101
Send a message via ICQ to christo Send a message via Yahoo to christo
only because switches keep an arp cache to map mac addresses to IP's. If you use a mac-spoofing based A/V, you'll probably figure out what you want.. It's harder, but nothing's impossible

christo

Reply With Quote
  #10  
Old April 7th, 2004, 09:10 AM
dbasnett dbasnett is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Posts: 107 dbasnett User rank is Lance Corporal (50 - 100 Reputation Level)dbasnett User rank is Lance Corporal (50 - 100 Reputation Level)dbasnett User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 10 h 11 m 43 sec
Reputation Power: 5
Layer 2 switches do NOT keep a mac to ip address table. They do keep track of which mac layer addresses are on each port.

Reply With Quote
  #11  
Old April 7th, 2004, 09:46 AM
christo's Avatar
christo christo is offline
Introspective
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2001
Location: London, UK
Posts: 3,296 christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 3 Days 1 h 5 m 42 sec
Reputation Power: 101
Send a message via ICQ to christo Send a message via Yahoo to christo
you're right - wasn't thinking there for a sec, but anyway...

christo

Reply With Quote
  #12  
Old April 7th, 2004, 09:49 AM
dbasnett dbasnett is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Posts: 107 dbasnett User rank is Lance Corporal (50 - 100 Reputation Level)dbasnett User rank is Lance Corporal (50 - 100 Reputation Level)dbasnett User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 10 h 11 m 43 sec
Reputation Power: 5
Was it Curly of the Three Stooges that said "I am trying to think but nothing happens". I know the feeling well.

Reply With Quote
  #13  
Old April 7th, 2004, 10:00 AM
christo's Avatar
christo christo is offline
Introspective
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2001
Location: London, UK
Posts: 3,296 christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level)christo User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 3 Days 1 h 5 m 42 sec
Reputation Power: 101
Send a message via ICQ to christo Send a message via Yahoo to christo
I have no idea who said that, but I'm feeling like that a lot today - wrestling with Swing layout managers and trying to case-harden an app with some inane exception handling...

*sigh

christo

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationNetworking Help > Switch sniffer


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump