Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Frontend for TCPDUMP sniffer :)))
From: Guido Stepken <stepken @ edina . xnc . com>
Organization: F.S.S.
Date: Sat, 15 Nov 1997 06:51:01 +0100
To: Dan Stromberg <strombrg @ nis . acs . uci . edu>
Cc: firewalls @ greatcircle . com
References: <34475040 . 0 @ lps . tina . agr . st . com> <62jpvi$kqu @ dfw-ixnews1 . ix . netcom . com> <62lhun$pq8 @ knot . queensu . ca> <62lriv$kl9 @ nuhou . aloha . net> <62qke3$qbe @ knot . queensu . ca> <3460ac2c . 0 @ news1 . ibm . net> <Pine . SUN . 3 . 94 . 971106120443 . 26379C-100000 @ dfw . dfw . net> <Pine . BSF . 3 . 96 . 971108175621 . 1632B-100000 @ tasam . com> <645pus$o1$1 @ twin . wasatch . com> <199711142143 . NAA26787 @ bingy . acs . uci . edu>

Dan Stromberg wrote:
> 
> Where's the GUI for tcpdump?
> 
> In article <3468070E .
 2E70CC81 @
 edina .
 xnc .
 com> you write:
> <Bob Hauck wrote:
> <>
> <> In article <Pine .
 BSF .
 3 .
 96 .
 971108175621 .
 1632B-100000 @
 tasam .
 com>,
> <>         Security Adm <security @
 tasam .
 com> writes:
> <>
> <> > I am sorry but I had to through this in... for a skewl project I went to
> <> > the BVA(gov't vertan agency of some kind) an I got to work with a 30,000
> <> > dollar packet sniffer. Why the hell they spent 30 grand on it I don't
> <> > know, but this is where our money is going to.
> <>
> <> We have a "30,000 dollar packet sniffer", an HP Internet Advisor.
> <> There's more to it than just sniffing though.
> <>
> <> This particular box can decode just about every protocol known to
> <> man (TCP, IPX, SNA, AppleTalk, etc etc), it can speak most
> <> flavors of ethernet and things like V.35 and RS-232 as well. You
> <> can hook it directly to a T1 (built-in CSU/DSU) and decode frame
> <> relay packets, evaluate timing, etc.  The whole right-hand side
> <> of it is covered with jacks for plugging in various types of
> <> media.
> <>
> <> In short, it does a *lot* of things besides sniff packets.  This
> <> box is more of a general-purpose LAN and WAN evaluator tool. 99%
> <> of the time you don't need it, but the 1% is worth thousands of
> <> billable dollars <g>.
> <
> <Oh, TCPDUMP seems to be able to do more (there is a GUI even for it :))
> <, e.g. ISDN.
> <
> <regards, Guido Stepken

http://www.cs.uit.no/~sveinarr/XTcpdump/
http://ftp.sunet.se/ftp/pub/security/tools/net/tcpshow/

And, besides the new tcpdump versions, also have a look at the
uncocumented feature "-D" in older tcpdump versions. With it you can see
login passwords running across the screen :) They found this feature to
be too dangerous. I made my own new tcpdump version with ISDN and "-D"
and i love it.

It's free, it's better - its LINUX

Indexed By Date Previous: Re: Hijak detection
From: Jason Keimig <jkeimig @ idir . net>
Next: Re: Hijak detection
From: Jason Keimig <jkeimig @ idir . net>
Indexed By Thread Previous: What To Do ??
From: Dick_Wall @ stratus . com
Next: Firewalls-Digest V6 #541 -Reply
From: BRAD LOWE <LOWEB @ yankeegas . com>

Google
 
Search Internet Search www.greatcircle.com