Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 34 guests and 1 member online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Network Monitor
EH-Net
May 18, 2013, 07:48:23 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Network Monitor  (Read 13070 times)
0 Members and 1 Guest are viewing this topic.
nilo
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: January 11, 2011, 02:31:16 PM »

I am a network administrator. I would like to monitor all user laptops and computers connected to my network. I have installed a software to take desktop screen shots, but it is not able to install client program in vista laptop remotely without the knowledge of the user. Since I am the network administrator i have the domain admin user id and pwd, im able to install client program in some pcs on thro' domain admin pwd. Please help me out to monitor my network.

Thanks in advance,
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #1 on: January 11, 2011, 02:40:17 PM »

Is there a reason to take screen shots of the PC?

For network monitoring, I usually use the following:
Catci, BandwidthD and ntop for network graphs
syslog for firewalls, switches and routers.
tcpdump and wireshark for taffic captures.
arpwatch and port controls to limit what can be plugged into the network
tripwire (on the monitor box) for file integerty
nagios

I wouldn't mind putting a SIEM in place, or something else to look at netflow. Spiceworks looks to be pretty good too.
Logged

OSWP, Sec+
nilo
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: January 11, 2011, 02:48:20 PM »

I would like to get periodical screen shots.

More than that Is there a way to access the files in their systems(XP/VISTA)?
Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #3 on: January 11, 2011, 02:53:30 PM »

Spiceworks looks to be pretty good too.

It may have changed in the last 3 years or so, but last time I looked at Spiceworks it was doing targeted marketing based on what it saw in your environment which raised a red flag with me. I don't feel the need to share the intimate details of my internal network with a 3rd party.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #4 on: January 11, 2011, 03:06:44 PM »

I would like to get periodical screen shots.

More than that Is there a way to access the files in their systems(XP/VISTA)?

Why do you need to? Why do you need screen shots. That sounds more like abusing being an admin than actual administration to me. (Hint in 14 years I've never needed screens shots).

I guess so we can answer your question better, we should ask what it is you're trying to do and what management wants.
Logged

OSWP, Sec+
nilo
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #5 on: January 11, 2011, 03:15:53 PM »

There is no question of abusing. Management want periodicall screenshot of users to see how the user working.

They want to see their PC file contents also time to time, coz their users work mostly involved with network files rather than local drive files
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #6 on: January 11, 2011, 03:28:53 PM »

There is no question of abusing. Management want periodicall screenshot of users to see how the user working.

They want to see their PC file contents also time to time, coz their users work mostly involved with network files rather than local drive files

Hmmm.. in other words a kind of place that doesn't sound like it's worth working at. (My opinion).

So lets see... based on your questions.

Software install:
Only ways I can think of to install the software is via GPO, or you can announce that you need the boxes to install software.

Seeing drives:
You'll probably want to script it out. Look into Microsoft UNC. With the Domain admin account you can see unshared drives.
« Last Edit: January 11, 2011, 03:30:42 PM by chrisj » Logged

OSWP, Sec+
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #7 on: January 11, 2011, 03:46:44 PM »

You're also opening yourself up to legal battles if you do not have the right policies in place that are acknowledged by your co-workers. It sounds like you don't have these as you're trying to install software without the employee's knowledge.

Just know that any evidence you put forth in a court of law will likely not stand to the rule of evidence if the employee did not know his/her actions were being monitored. In the case of a wrongful termination suit, your company could be out some big money without any proof.
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #8 on: January 11, 2011, 04:11:58 PM »

I would highly recommend you tell management why you think it's a bad idea via email and print out the response you get and keep it in a safe place for a rainy day. Sounds like a disaster waiting to happen, and Ziggy is right, the company could be faced with some serious legal issues but don't think for a minute that they won't throw you under the bus if it comes to that. Actually, scratch that first sentence. You should probably just find another job. I could not work in an environment that oppressive. I have to wonder if the employees are aware.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #9 on: January 11, 2011, 04:42:34 PM »

Spiceworks looks to be pretty good too.

It may have changed in the last 3 years or so, but last time I looked at Spiceworks it was doing targeted marketing based on what it saw in your environment which raised a red flag with me. I don't feel the need to share the intimate details of my internal network with a 3rd party.

http://www.spiceworks.com/privacy/

Brought it up on twitter (follow someone else that uses it, and spiceworks themselves. That link was the end response from Spiceworks).
Logged

OSWP, Sec+
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #10 on: January 11, 2011, 04:46:18 PM »

Glad I'm not the only one that thinks nilo's job sucks.

Remember. Your job as an admin isn't to make your bosses happy, it's to keep the company running. Sometimes it is hard for them to know the difference. The get the CYA documentation is a good thing. Because when (not if, WHEN) a lawsuit happens they will be looking for a sacrifice, and chances are you'll be it.

Also keep those documents stored somewhere other than your office. Safety Deposit box, and don't let them know you've got copies.

Also, beware if the AUP isn't enforced across the board. We have that problem where I'm at. Some people are "Exempt from the AUP", while others have lost their jobs over it.

Seriously though, sit down with them and find a better way, or find a new job.
Logged

OSWP, Sec+
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 394



View Profile
« Reply #11 on: January 12, 2011, 10:59:32 AM »

I would have to agree with the above comments.  The more responses I see to the member questions though, the more leery I am to respond especially with any help.  Unless English is a second language, and if so please ignore this; the use of 'coz' and general grammatical/structural laziness leads me to assume someone younger than a network admin is behind the posting.  Sorry if English is your second language, and please do ignore my suspicions if that is the case.
Logged

"Bad.. Good?  I'm the guy with the gun"
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #12 on: January 12, 2011, 11:38:01 AM »

what about bandwidth monitor you can try use ProteMac Meter http://protemac.com/Meter/.It;s really nice prog)

Based on a quick look at your link. It looks to be a MAC only product.
Logged

OSWP, Sec+
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #13 on: January 12, 2011, 11:42:55 AM »

@g00d_4sh

I'm taking him as either a noob (fresh out of highschool, limited admin skills) or non-english speaker.

but a little leery enough to not give him more information on how to do what he's trying.
Logged

OSWP, Sec+
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« Reply #14 on: January 12, 2011, 12:12:39 PM »

Quote
I have installed a software to take desktop screen shots, but it is not able to install client program in vista laptop remotely without the knowledge of the user.

You guys are too nice, this guy is an <censured>!

Don't even reply to his emails. If you analyze his writting, he is almost certainly the same guy who wrote a few questionable posts on this forum in the last 2 months. Same patern: 1) create a new account, 2) post an unethical question, 3) once we realize it, he disapears.

Look around, we have seen this quite often recently...

And BTW, English is my second language (so sorry for the typos everywhere!), but I am mature enough not to write posts like this. So to me, a young "wanna be" black hat...
« Last Edit: January 12, 2011, 12:14:50 PM by H1t M0nk3y » Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.