Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 51 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow Toolsarrow Favorite Sniffer/Protocol Analyzer
EH-Net
May 22, 2013, 05:27:17 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Favorite Sniffer/Protocol Analyzer  (Read 12939 times)
0 Members and 1 Guest are viewing this topic.
shawn
Newbie
*
Offline Offline

Posts: 15



View Profile
« on: January 26, 2007, 09:53:17 AM »

I know alot of people will say ethereal/wireshark to this question because it is probably the best free analyzer you can get, but I was wondering what sniffers/network protocol analyzers some of you use and like.  I currently use wireshark and have some experience with Network Generals Sniffer Pro.  Anyone have any comments good or bad about any others out there free or commercial grade.  If so what do/dont you like about them.
Logged

CEH, CCNA, Security+
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #1 on: January 26, 2007, 10:32:05 AM »

I would highly not recommend the Fluke Network Tools and sniffers. They are very over priced and do not perform very well. I use Ethereal/WireShark & NetworkActiv PIAFCTM (www.NetworkActiv.com).

Just my thoughts...

Brian
AKA Slimjim100
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
Kev
Guest
« Reply #2 on: January 28, 2007, 12:07:36 PM »

It really depends on what I am after. As a general purpose sniffer wireshark is good. If I am trying to monitor packets for abnormalities, snort is my pick. If I want to be really nosy, Iris is great because I can actually see the email or website someone is viewing on another host on the network. If I am hacking a box and am in the command line, tcpdump is the way to go.
Logged
Cutaway
Jr. Member
**
Offline Offline

Posts: 96


Cutaway


View Profile WWW
« Reply #3 on: April 03, 2007, 07:30:20 PM »

Daniel Miessler pointed out his write-up about Tcpdump to the Security Catalyst Community http://community.securitycatalyst.com.  I thought you guys would like to know about it.  It is a quick primer on tcpdump.  Very nice introduction.

http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/action,post/topic,1012.0/num_replies,2/

Enjoy,
Cutaway
Logged

Go forth and do good things,
Cutaway
jimbob
Guest
« Reply #4 on: April 04, 2007, 04:19:15 AM »

There are a lot of sniffers and protocol analysers with specific functions.

  • Kismet for wifi
  • Bluetooth scanner for bluetooth
  • dsniff for nefarious activities such as password stealing

The list goes on but those are some of my favourites.

Jimbob
Logged
Negrita
Sr. Member
****
Offline Offline

Posts: 299



View Profile
« Reply #5 on: August 17, 2007, 05:24:01 PM »

I personally use Wireshark and Tcpdump at work.

However some of you may know that I work for a company that does DPI, and we have an entire department devoted to protocols analysis. The other day I was talking to some of the guys in that department and I was suprised to hear that they by far prefer to work with EtherPeek (which is now called OmniPeek).
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.057 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.