LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 04-20-2003, 11:55 PM   #1
Shurikn
LQ Newbie
 
Registered: Apr 2003
Posts: 7

Rep: Reputation: 0
Setting up a sniffing environment to loot at packet transfered from my windows comp?


Ok first of all I must say that I'm a total to linux, I installed it today to learn how it work since I will study it soon. Anyway I wanted to install a program on my computer today and it say I have to set up a sniffing environment to analyse the packet that my windows computer is sending and receiving with my linux box. My computers are connected to internet with a router. I don't know what I have to do so I don't know if you'd need more information..

Anyway if someone could assists me to do that and maybe to install the program that require this sniffing environment I'd really appreciate it.

you can contact me with ICQ (9607973) or MSN (shurik_n@hotmail.com)

I know it's kinda funny of posting a microsoft email but that's all I have for now ; )

Thanks a lot to those who would help
 
Old 04-20-2003, 11:59 PM   #2
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
try tcpdump

check this out

man tcpdump
 
Old 04-21-2003, 12:04 AM   #3
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
there is also sniff, snort, and nc
 
Old 04-21-2003, 12:11 AM   #4
Shurikn
LQ Newbie
 
Registered: Apr 2003
Posts: 7

Original Poster
Rep: Reputation: 0
hmm and that mean?
as I said I just started using linux
 
Old 04-21-2003, 12:38 AM   #5
Shurikn
LQ Newbie
 
Registered: Apr 2003
Posts: 7

Original Poster
Rep: Reputation: 0
Here is what the installation file says:

============================
Verifying your network setup
============================

You need to set up a sniffing environment. How to do that is
beyond the scope of this simple INSTALL file, but look around the
net; there are many guides.
To verify that your sniffing setup is correct, run the following command
on your would-be EX box WHILE playing DAoC:

tcpdump -n host <IP of your Windows Machine playing DAoC>

You should (hopefully) see two-way traffic, that is traffic both to AND
from your windows machine. If you don't, you don't have a sniffing
setup, and you should fix that first.



I hope it can help
I did the cmd they are saying and nothing happened so I guess I'd have to do something before trying to sniff my windows box..

Thanks for the help
 
Old 04-21-2003, 12:53 AM   #6
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
so where are you having problems

do you know the ip address that you are supposed to use?


please give more details of the problem

this is the command, with exception of the ip address may be incorrect



tcpdump -n host 192.168.0.1
 
Old 04-21-2003, 12:54 AM   #7
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
also you can run tcpdump like this to see traffic


tcpdump
 
Old 04-21-2003, 12:39 PM   #8
Shurikn
LQ Newbie
 
Registered: Apr 2003
Posts: 7

Original Poster
Rep: Reputation: 0
I'm having problem with when they say setup a sniffing, all I have to do is typing this command and let it run?
 
Old 04-21-2003, 12:47 PM   #9
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
thats right

it's pretty much fool proof if you have a nic and it's setup for your network.

It looks like they are wanting you to verify that it's just seeing packets from the machine.

typing this command...

tcpdump


will display the packet headers and if you know the ip address of the windows machine you can look for it in the output to verify that it's sending packets across the network.

if you install sniff you can use it to format the output of tcpdump like this


sniff -c -- -i eth0 > filename



the last part > filename will output it to the file "filename" so you can read the file later. If you want it to show on the screen leave it off, but it will be going too fast to read.


see the output of sniff -h for details
 
Old 04-22-2003, 02:21 PM   #10
Shurikn
LQ Newbie
 
Registered: Apr 2003
Posts: 7

Original Poster
Rep: Reputation: 0
ok I will try it

Thanks a lot!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to do: using a linux comp to act as router for a windows comp grimhammer Linux - Networking 8 02-10-2005 09:56 PM
Problems with packet sniffing in promiscuous mode Yohhan Linux - Networking 1 05-07-2004 05:59 AM
Packet sniffing question. _TK_ Linux - Security 6 09-04-2003 09:14 AM
url packet sniffing? nibjb Linux - Networking 1 09-01-2003 09:34 PM
How to change Packet to look like a Windows packet? TimeFade Linux - Networking 10 08-28-2003 08:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 10:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration