LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-15-2006, 02:45 AM   #1
fakie_flip
Senior Member
 
Registered: Feb 2005
Location: San Antonio, Texas
Distribution: Gentoo Hardened using OpenRC not Systemd
Posts: 1,495

Rep: Reputation: 85
using dsniff to test the security of my lan


Using dsniff did not reveal my password when logging into mail.yahoo.com. I want to see what all the passwords are caught and how vulnerable my network really is. Any ideas why dsniff did not catch my password? This is what it put in the logs. msgsnarf is also not catching any of the logins from gaim. I am not using ssl (https), but I do notice the packets caught by dsniff say slogin. This probably means secure login. Any ideas how dsniff could get my passwords for gaim, gmail and yahoo mail? I am using the newest version.

Code:
-----------------
08/12/06 19:31:51 tcp my_ip_address.35398 -> l2.login.vip.mud.yahoo.com.80 (http)
GET /config/login_verify2?.slogin=my_email_address&.intl=us&.src=ym&.bypass=&.partner=&.done=http%3a//edit.yahoo.com/config/eval_profile%3f.done=http%3a//mail.yahoo.com%26.src=ym%26.intl=us%26.scrumb=0&pkg=&owd= HTTP/1.1
Host: login.yahoo.com

-----------------
08/12/06 19:51:52 tcp my_ip_address.34657 -> l2.login.vip.mud.yahoo.com.80 (http)
GET /config/login_verify2?.slogin=my_email_address&.intl=us&.src=ytc&.bypass=&.partner=&.done=http%3a//edit.yahoo.com/config/eval_profile%3f.done=http%3a//members.yahoo.com%26.src=ytc%26.intl=us%26.scrumb=0&pkg=&owd= HTTP/1.1
Host: login.yahoo.com
 
Old 08-15-2006, 11:46 AM   #2
live_dont_exist
Member
 
Registered: Aug 2004
Location: India
Distribution: Redhat 9.0,FC3,FC5,FC10
Posts: 257

Rep: Reputation: 30
Hmm... Are you sure you're doing this on your own system???
If its SSL traffic there's no sniffer in the world which is going to be able to catch it...I mean it might catch it...but you're going to have to crack..AHEM...decrypt SSL to make sense of it..

I dont know whether Gaim uses SSL.. Yahoo has as ecure login feature and Im sure even Gmail encrypts its connections. That said...I sure hope you're an admin who's just "TESTING" ... else you could be in trouble...if caught...

Cheers
Arvind
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Security test for linux (SSH) SlAiD Linux - Security 4 02-22-2005 11:23 AM
security in Mandrake 10 over LAN Kerr Linux - Security 4 06-18-2004 05:44 PM
please test my OrangeB Security Linux! gloomez Linux - Distributions 14 11-02-2003 01:44 PM
Firewall / Network Security Test Sites mrnikeswsh Linux - Security 1 08-28-2003 04:34 PM
interesting 'test your security' sites tobyl Linux - Security 7 08-10-2003 05:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration