LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-21-2009, 01:42 PM   #1
pablo1999
Member
 
Registered: Oct 2007
Posts: 33

Rep: Reputation: 15
Using WireShark to detect encryption method


Hello,

I'm trying to find out how to use WireShark to detect which encryption method is used between a windows client and windows server.

Can I use WireShark to look at the traffic from 2 computers and find out which encryption method is being in used?

If yes, how?

Thanks in advanced.
 
Old 08-21-2009, 03:11 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
it depends what traffic it sees, and if it's a protocol it can understand. Encryption like SSL is easy to "Detect" as SSL uses very well known handshaking process, and can be pulled apart to show what sort of cipher methods and such are being used. Obviously what can't be done is see the encrypted data... is that the sort of thing you mean? if you are pushing other encrypted data, then you can't magically know what a file might be encrypted with if it's not something agreed upon by both boxes.
 
Old 08-21-2009, 03:17 PM   #3
pablo1999
Member
 
Registered: Oct 2007
Posts: 33

Original Poster
Rep: Reputation: 15
I dont want to see the encrypted data. I just want to collect the traffic information that is encrypted from one host to another and figure out if its encrypted using AES, Blowfish, DES or other algorithm.

Last edited by pablo1999; 08-21-2009 at 03:29 PM.
 
Old 08-21-2009, 03:54 PM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well as above, it depends what communication protocol is being used to agree the algorithm over, if it is agreed.
 
Old 08-22-2009, 08:40 PM   #5
pablo1999
Member
 
Registered: Oct 2007
Posts: 33

Original Poster
Rep: Reputation: 15
So I can use WireShark to detect encryption methods like Encryption like
AES, Blowfish or DES ?

I yes, do you know of some document that explains on how to do this?

Thanks.
 
Old 08-23-2009, 01:42 AM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Just try it. Capture some traffic and see if it shows it in the traffic details. You'd need to see the start of the stream in just about all cases, if not absolutely all.
 
Old 08-24-2009, 12:53 PM   #7
pablo1999
Member
 
Registered: Oct 2007
Posts: 33

Original Poster
Rep: Reputation: 15
I ran wireshark and all the frames only show the following:

Protocols in frame: eth:ip:tcp:tds

I was expecting something more like the following:

Protocols in frame: eth:ip:tcp:tds
Cipher in frame: Blowfish

or

Protocols in frame: eth:ip:tcp
Cipher in frame: AES

Last edited by pablo1999; 08-25-2009 at 09:33 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Please help choose the best encryption method Akonbobot Linux - Security 5 05-07-2007 01:18 PM
Want to know method wireshark or tcpdump to capture packet? haxpor Programming 1 04-12-2007 01:08 AM
Determine what encryption method is used jonlake Linux - General 1 09-27-2006 12:28 AM
proxy url encryption method - ok? mymojo Programming 2 10-20-2003 04:16 AM
Mandrake 9.0 Wireless Works without encryption.. does not with encryption topcat Linux - Wireless Networking 3 05-04-2003 08:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration