Longjidin’s Kg Lengkong to Bukit Lada

UNIX / Linux / BSD LAN Monitoring Tools

Posted in Lan Monitoring by longjidin on December 20, 2008

NIX / Linux / BSD LAN Monitoring Tools

DOS/Windows LAN Monitoring Tools

Beware a false sense of security based on switches

  • A switch does not provide security by partitioning a LAN. The dsniff toolkit includes arpspoof, which uses ARP trickery to confuse hosts about the mappings between IP and MAC addresses. The attacker can get all datagrams sent to a sniffing host, which grabs copies and possibly modifies contents before sending them to the legitimate hardware addresses.
  • ALso be aware that some tools (dsniff, mailsnarf, webspy) understand application-layer protocols and make it easy to capture and analyze telnet and FTP logins and passwords, web traffic, mail, etc.

Wireless LAN/WAN Monitoring and Security

Here is a useful introduction to wireless networking and the security issues: http://en.wikipedia.org/wiki/802.11b

Note that wireless monitoring tools can be extremely dependent on chipset — make sure that your planned software and WLAN card will get along.

The Trifinite Group has information on wireless security, including RFIDiot and other RFID security tools and information: http://www.trifinite.org/

Tapping optical fibre no longer requires splicing. You can read the data by removing some of the sheath and gently bending the fibre in a bend coupler. You can supposedly buy them for a few hundred US$, even off eBay.

There are claims that optical taps have been found on police networks in the Netherlands and Germany, and the FBI investigated one discovered on Verizon’s network in the US.

For more see:

Tagged with:

Leave a Reply