Managing Cisco Network Security, Second Edition

Sniffing, Interception, and Eavesdropping

Originally conceived as a legitimate network and traffic analysis tool, sniffing remains one of the most effective techniques in attacking a wireless network, whether it's to map the network as part of a target reconnaissance, to grab passwords, or to capture unencrypted data.

Defining Sniffing

Sniffing is the electronic form of eavesdropping on the communications that computers have across networks. In the original networks deployed, the equipment tying machines together allowed every machine on the network to see the traffic of others. These repeaters and hubs, while very successful for getting machines connected, allowed an attacker easy access to all traffic on the network by only needing to connect to one point to see the entire network's traffic.

Wireless networks function very similar to the original repeaters and hubs. Every communication across the wireless network is viewable to anyone who happens to be listening to the network. In fact, the person listening does not even need to be associated with the network to sniff!

Sample Sniffing Tools

The hacker has many tools available to attack and monitor your wireless network. A few of these tools are Ethereal and AiroPeek (www.wildpackets.com/products/airopeek) in Windows, and tcpdump or ngrep (http://ngrep.sourceforg.net) within a UNIX or Linux environment. These tools work well for sniffing both wired and wireless networks.

All of these software packages function by putting your network card in what is called promiscuous mode. When in this mode, every packet that goes past the interface is captured...

UNLIMITED FREE ACCESS TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Repeaters and Extenders
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.