[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 08-31-2005, 04:55 PM   #1
SnowSurfer
Rear Admiral Lower Half
 
SnowSurfer's Avatar
 
Join Date: Jun 2002
Posts: 2,616
wireless packet sniffing ? (security related)

the wireless networks on my campus are unencrypted...so say some savy person sniffed wireless packets using etheral, how would they interpret them and make sense of them?

should this savy person save them as the top choice in the menu or what?

thanks a bundle
__________________
I have an athlon xp 2500+ ... aren't you glad you know that?
SnowSurfer is offline   Reply With Quote
Old 08-31-2005, 06:04 PM   #2
StonedWheat
Commander
 
StonedWheat's Avatar
 
Join Date: May 2000
Location: Bay Area, Ca
Posts: 1,268
Send a message via ICQ to StonedWheat Send a message via AIM to StonedWheat Send a message via MSN to StonedWheat
I use airopeek, so I don't know exactly how the ethereal interface and features are specifically. I would look at the data portion of each packet. In airopeek, you can filter packets by conversations. So if there is an option to filter the conversation between a machine and say, mail.yahoo.com, you could probably read a person's email being sent. Looking through every single packet can be very time consuming though.

Getting airopeek configured was such a pain! Let me know if ethereal is a lot easier to play with.
__________________
"Cynicism is knowing the price of everything and the value of nothing."

-Oscar Wilde
StonedWheat is offline   Reply With Quote
Old 08-31-2005, 07:46 PM   #3
ribitch
Rear Admiral Upper Half
 
ribitch's Avatar
 
Join Date: Sep 2001
Location: Michigan
Posts: 3,672
Send a message via AIM to ribitch
a wireless packet is actually larger than a ethernet packet, however ethereal has a decoder for them. Last I checked, it was part of the base application. you just need to look at the type of packet thats being transmitted to see what is going on.
__________________
http://ribitch.com/ipod.html
ribitch is offline   Reply With Quote
Old 08-31-2005, 09:19 PM   #4
SnowSurfer
Rear Admiral Lower Half
 
SnowSurfer's Avatar
 
Join Date: Jun 2002
Posts: 2,616
i have these different types of packets from what was sniffed today, arp,browse, dhcp, igmp, nbns, ssdp... any idea how to see what is what...?
SnowSurfer is offline   Reply With Quote
Old 09-01-2005, 05:52 AM   #5
Jeffbx
Fleet Admiral
 
Jeffbx's Avatar
 
Join Date: Mar 2000
Location: Michigan
Posts: 9,390
Send a message via MSN to Jeffbx
First you need to know exactly what you're looking for, then filter for that. Otherwise (as you've probably seen), you'll get too much garbage to wade through:

ARP = address resolution protocol
DHCP = dynamic host configuration protocol
IGMP = internet group management protocol
NBNS = NetBIOS Name Server (like WINS)
SSDP = Single service discovery protocol

All of these are just communication protocols that the machines use to see what's on the network. None of them contain any useful data, unless you happen to be troubleshooting a networking issue.

So what exactly are you looking for?
Jeffbx is offline   Reply With Quote
Old 09-01-2005, 11:10 AM   #6
ribitch
Rear Admiral Upper Half
 
ribitch's Avatar
 
Join Date: Sep 2001
Location: Michigan
Posts: 3,672
Send a message via AIM to ribitch
Quote:
Originally Posted by Jeffbx
So what exactly are you looking for?

packet pr0n
ribitch is offline   Reply With Quote
Old 09-01-2005, 07:27 PM   #7
SnowSurfer
Rear Admiral Lower Half
 
SnowSurfer's Avatar
 
Join Date: Jun 2002
Posts: 2,616
Quote:
Originally Posted by ribitch
packet pr0n

exactly i wanted to see what kind of nasty crap people were looking at
SnowSurfer is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 05:07 PM.