Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 34 guests and 1 member online
You are here:
Home
Resources
Tools
Network Monitor
EH-Net
May 18, 2013, 07:48:23 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tools
(Moderator:
don
) >
Network Monitor
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Network Monitor (Read 13070 times)
0 Members and 1 Guest are viewing this topic.
nilo
Newbie
Offline
Posts: 3
Network Monitor
«
on:
January 11, 2011, 02:31:16 PM »
I am a network administrator. I would like to monitor all user laptops and computers connected to my network. I have installed a software to take desktop screen shots, but it is not able to install client program in vista laptop remotely without the knowledge of the user. Since I am the network administrator i have the domain admin user id and pwd, im able to install client program in some pcs on thro' domain admin pwd. Please help me out to monitor my network.
Thanks in advance,
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #1 on:
January 11, 2011, 02:40:17 PM »
Is there a reason to take screen shots of the PC?
For network monitoring, I usually use the following:
Catci, BandwidthD and ntop for network graphs
syslog for firewalls, switches and routers.
tcpdump and wireshark for taffic captures.
arpwatch and port controls to limit what can be plugged into the network
tripwire (on the monitor box) for file integerty
nagios
I wouldn't mind putting a SIEM in place, or something else to look at netflow. Spiceworks looks to be pretty good too.
Logged
OSWP, Sec+
nilo
Newbie
Offline
Posts: 3
Re: Network Monitor
«
Reply #2 on:
January 11, 2011, 02:48:20 PM »
I would like to get periodical screen shots.
More than that Is there a way to access the files in their systems(XP/VISTA)?
Logged
tturner
Sr. Member
Offline
Posts: 432
Re: Network Monitor
«
Reply #3 on:
January 11, 2011, 02:53:30 PM »
Quote from: chrisj on January 11, 2011, 02:40:17 PM
Spiceworks looks to be pretty good too.
It may have changed in the last 3 years or so, but last time I looked at Spiceworks it was doing targeted marketing based on what it saw in your environment which raised a red flag with me. I don't feel the need to share the intimate details of my internal network with a 3rd party.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #4 on:
January 11, 2011, 03:06:44 PM »
Quote from: nilo on January 11, 2011, 02:48:20 PM
I would like to get periodical screen shots.
More than that Is there a way to access the files in their systems(XP/VISTA)?
Why do you need to? Why do you need screen shots. That sounds more like abusing being an admin than actual administration to me. (Hint in 14 years I've never needed screens shots).
I guess so we can answer your question better, we should ask what it is you're trying to do and what management wants.
Logged
OSWP, Sec+
nilo
Newbie
Offline
Posts: 3
Re: Network Monitor
«
Reply #5 on:
January 11, 2011, 03:15:53 PM »
There is no question of abusing. Management want periodicall screenshot of users to see how the user working.
They want to see their PC file contents also time to time, coz their users work mostly involved with network files rather than local drive files
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #6 on:
January 11, 2011, 03:28:53 PM »
Quote from: nilo on January 11, 2011, 03:15:53 PM
There is no question of abusing. Management want periodicall screenshot of users to see how the user working.
They want to see their PC file contents also time to time, coz their users work mostly involved with network files rather than local drive files
Hmmm.. in other words a kind of place that doesn't sound like it's worth working at. (My opinion).
So lets see... based on your questions.
Software install:
Only ways I can think of to install the software is via GPO, or you can announce that you need the boxes to install software.
Seeing drives:
You'll probably want to script it out. Look into Microsoft UNC. With the Domain admin account you can see unshared drives.
«
Last Edit: January 11, 2011, 03:30:42 PM by chrisj
»
Logged
OSWP, Sec+
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Network Monitor
«
Reply #7 on:
January 11, 2011, 03:46:44 PM »
You're also opening yourself up to legal battles if you do not have the right policies in place that are acknowledged by your co-workers. It sounds like you don't have these as you're trying to install software without the employee's knowledge.
Just know that any evidence you put forth in a court of law will likely not stand to the rule of evidence if the employee did not know his/her actions were being monitored. In the case of a wrongful termination suit, your company could be out some big money without any proof.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
tturner
Sr. Member
Offline
Posts: 432
Re: Network Monitor
«
Reply #8 on:
January 11, 2011, 04:11:58 PM »
I would highly recommend you tell management why you think it's a bad idea via email and print out the response you get and keep it in a safe place for a rainy day. Sounds like a disaster waiting to happen, and Ziggy is right, the company could be faced with some serious legal issues but don't think for a minute that they won't throw you under the bus if it comes to that. Actually, scratch that first sentence. You should probably just find another job. I could not work in an environment that oppressive. I have to wonder if the employees are aware.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #9 on:
January 11, 2011, 04:42:34 PM »
Quote from: tturner on January 11, 2011, 02:53:30 PM
Quote from: chrisj on January 11, 2011, 02:40:17 PM
Spiceworks looks to be pretty good too.
It may have changed in the last 3 years or so, but last time I looked at Spiceworks it was doing targeted marketing based on what it saw in your environment which raised a red flag with me. I don't feel the need to share the intimate details of my internal network with a 3rd party.
http://www.spiceworks.com/privacy/
Brought it up on twitter (follow someone else that uses it, and spiceworks themselves. That link was the end response from Spiceworks).
Logged
OSWP, Sec+
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #10 on:
January 11, 2011, 04:46:18 PM »
Glad I'm not the only one that thinks nilo's job sucks.
Remember. Your job as an admin isn't to make your bosses happy, it's to keep the company running. Sometimes it is hard for them to know the difference. The get the CYA documentation is a good thing. Because when (not if, WHEN) a lawsuit happens they will be looking for a sacrifice, and chances are you'll be it.
Also keep those documents stored somewhere other than your office. Safety Deposit box, and don't let them know you've got copies.
Also, beware if the AUP isn't enforced across the board. We have that problem where I'm at. Some people are "Exempt from the AUP", while others have lost their jobs over it.
Seriously though, sit down with them and find a better way, or find a new job.
Logged
OSWP, Sec+
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: Network Monitor
«
Reply #11 on:
January 12, 2011, 10:59:32 AM »
I would have to agree with the above comments. The more responses I see to the member questions though, the more leery I am to respond especially with any help. Unless English is a second language, and if so please ignore this; the use of 'coz' and general grammatical/structural laziness leads me to assume someone younger than a network admin is behind the posting. Sorry if English is your second language, and please do ignore my suspicions if that is the case.
Logged
"Bad.. Good? I'm the guy with the gun"
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #12 on:
January 12, 2011, 11:38:01 AM »
Quote from: Gere1 on January 12, 2011, 02:06:22 AM
what about bandwidth monitor you can try use ProteMac Meter
http://protemac.com/Meter/
.It;s really nice prog)
Based on a quick look at your link. It looks to be a MAC only product.
Logged
OSWP, Sec+
chrisj
Hero Member
Offline
Posts: 1163
Re: Network Monitor
«
Reply #13 on:
January 12, 2011, 11:42:55 AM »
@g00d_4sh
I'm taking him as either a noob (fresh out of highschool, limited admin skills) or non-english speaker.
but a little leery enough to not give him more information on how to do what he's trying.
Logged
OSWP, Sec+
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Network Monitor
«
Reply #14 on:
January 12, 2011, 12:12:39 PM »
Quote
I have installed a software to take desktop screen shots, but it is not able to install client program in vista laptop remotely without the knowledge of the user.
You guys are too nice, this guy is an <censured>!
Don't even reply to his emails. If you analyze his writting, he is almost certainly the same guy who wrote a few questionable posts on this forum in the last 2 months. Same patern: 1) create a new account, 2) post an unethical question, 3) once we realize it, he disapears.
Look around, we have seen this quite often recently...
And BTW, English is my second language (so sorry for the typos everywhere!), but I am mature enough not to write posts like this. So to me, a young "wanna be" black hat...
«
Last Edit: January 12, 2011, 12:14:50 PM by H1t M0nk3y
»
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.