LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-03-2003, 11:59 AM   #1
_TK_
Member
 
Registered: Feb 2001
Posts: 54

Rep: Reputation: 15
Packet sniffing question.


If someone is uploading files from the local network to an outside IP is there a way you can determine what files are being uploaded but sniffing the wire somehow?
 
Old 09-03-2003, 12:22 PM   #2
cyph3r7
Member
 
Registered: Apr 2003
Location: Silicon Valley East, Northern Virginia
Distribution: FreeBSD,Debian, RH, ok well most of em...
Posts: 238

Rep: Reputation: 30
sure put a sniffer between the host uploading and the exit point (router/firewall). You can see whats in 'em....sorta
 
Old 09-03-2003, 12:33 PM   #3
_TK_
Member
 
Registered: Feb 2001
Posts: 54

Original Poster
Rep: Reputation: 15
Ya I can use iptraf etc.. but i was wondering if there was a method to find specific file names to determine exactly what files are being uploaded.
 
Old 09-03-2003, 05:01 PM   #4
Khabi
Member
 
Registered: Aug 2003
Location: Arizona
Distribution: Gentoo
Posts: 142

Rep: Reputation: 15
well, using ethereal you can get a packet dump and see what they're uploading.
Code:
0000  00 00 03 04 00 00 00 03  6b b9 81 c0 00 00 08 00   ........ k.......
0010  45 10 00 3c 02 7f 40 00  40 06 3a 2b 7f 00 00 01   E..<..@. @.:+....
0020  7f 00 00 01 9d 42 00 15  78 97 9d 13 78 e7 1e f4   .....B.. x...x...
0030  50 18 7f ff c4 84 00 00  53 54 4f 52 20 2f 72 6f   P....... STOR /ro
0040  6f 74 2f 74 65 73 74 2e  67 7a 0d 0a               ot/test. gz..
also you'll see a line like this in main window of it.
Code:
no.  Time        Source   Destination   Protocol   Info
27   22.851634   Tux      Tux           FTP        Request: STOR /root/test.gz
This is assuming they're just using regular ftp and not sftp.
 
Old 09-04-2003, 04:47 AM   #5
aqoliveira
Member
 
Registered: Dec 2001
Location: Portugal
Distribution: /Red Hat/Fedora/Solaris
Posts: 622

Rep: Reputation: 30
Hi there

U can use ethereal but u must take into account that it will not work in a switched network try using other tools. Iḿ not gouing to mention those tools as i am not sure if I am allowed to in this forum

cheers
 
Old 09-04-2003, 08:04 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'm not going to mention those tools as i am not sure if I am allowed to in this forum
Go right ahead. Dsniff, Ettercap...
 
Old 09-04-2003, 09:14 AM   #7
aqoliveira
Member
 
Registered: Dec 2001
Location: Portugal
Distribution: /Red Hat/Fedora/Solaris
Posts: 622

Rep: Reputation: 30
Thanx dude was not sure I could....
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems with packet sniffing in promiscuous mode Yohhan Linux - Networking 1 05-07-2004 05:59 AM
could i ask a question about forwarding a packet mostafa_ezz Linux - Networking 0 02-07-2004 02:05 PM
url packet sniffing? nibjb Linux - Networking 1 09-01-2003 09:34 PM
sniffing question Di0de Linux - Networking 2 07-02-2003 08:39 PM
Setting up a sniffing environment to loot at packet transfered from my windows comp? Shurikn Linux - General 9 04-22-2003 02:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration