forum.vdsworld.com Forum Index forum.vdsworld.com
Visit VDSWORLD.com
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Port Sniffer

 
Post new topic   Reply to topic    forum.vdsworld.com Forum Index -> General Help
View previous topic :: View next topic  
Author Message
GregLand
Valued Contributor
Valued Contributor


Joined: 15 Jun 2004
Posts: 212
Location: FRANCE

PostPosted: Thu Nov 11, 2004 2:25 am    Post subject: Port Sniffer Reply with quote

Hello everybody Very Happy

I would like to know if it was possible to make a Sniffer for my LAN...
(It's a program which makes it possible to recover the data which are transmitted on a network ?). Preferably with freeware extension... Laughing

I don't know if it's possible and I don't know at all how to make.

Thanks a lot for your answer ! Wink

PS : Sorry for my poor English Confused
Back to top
View user's profile Send private message Visit poster's website
jules
Professional Member
Professional Member


Joined: 14 Sep 2001
Posts: 1043
Location: Cumbria, UK

PostPosted: Thu Nov 11, 2004 9:12 am    Post subject: Reply with quote

Network sniffers are all very expensive, which is probably a reflection of how complex they are to develop. Mostly they require special drivers to be installed. Drivers are hard to develop in any language, and certainly not possible in VDS. There are some that don't seem to require drivers, but can interface directly with certain makes of network card. In theory, you could write a VDS extension to do the same, which would allow you to display or analyze the results using VDS. But it would still be very hard.
_________________
The Tech Pro
www.tech-pro.net
Back to top
View user's profile Send private message Visit poster's website
GregLand
Valued Contributor
Valued Contributor


Joined: 15 Jun 2004
Posts: 212
Location: FRANCE

PostPosted: Thu Nov 11, 2004 12:30 pm    Post subject: Reply with quote

I understand... I understand... What a pity... Crying or Very sad

Thank-you anyway for your response... But if someone has an idea (even small), do not hesitate! Wink
Back to top
View user's profile Send private message Visit poster's website
FreezingFire
Admin Team


Joined: 23 Jun 2002
Posts: 3508

PostPosted: Thu Nov 11, 2004 4:25 pm    Post subject: Reply with quote

Are you talking about a packet sniffer?
_________________
FreezingFire
VDSWORLD.com
Site Admin Team
Back to top
View user's profile Send private message Visit poster's website
PGWARE
Web Host


Joined: 29 Dec 2001
Posts: 1566

PostPosted: Thu Nov 11, 2004 4:46 pm    Post subject: Reply with quote

Take a look at WinPcap: http://winpcap.polito.it/

It's a free network packet capture and analysis library; and you can include it with any programs you make.

It may be possible to use it with the vds dll load and unload commands but probably much more difficult. I would really suggest using VB or DELPHI when working with an extension this extensive.

It will require a lot of work either way even with this set of libraries.
Back to top
View user's profile Send private message
GregLand
Valued Contributor
Valued Contributor


Joined: 15 Jun 2004
Posts: 212
Location: FRANCE

PostPosted: Thu Nov 11, 2004 7:49 pm    Post subject: Reply with quote

Very good ! Thanks... Shocked
I'm going to try it !

If someone have an idea... no problem... it was going to be difficult for me... Confused
Back to top
View user's profile Send private message Visit poster's website
webdaddy
Contributor
Contributor


Joined: 14 Nov 2004
Posts: 151
Location: Raleigh NC

PostPosted: Fri Jul 22, 2005 1:47 pm    Post subject: Packet Sniffing Reply with quote

Another method that I am using is to use a binary compiled for windows of TCP dump and then analyze that with VDS. You can also hide a larger packet sniffer such as Ethereal to accomplish the same thing. As long as the output is consistant it can be analyzed by your VDS applicaton.

Awhile back I was looking at writing my own IDS and ran into the same issues the guys here are talking about. My solution was to use tcpdump (DOS command line) and use with runh command in VDS and use VDS to control it and then process the output in VDS. Worked like a champ.

_________________
K Wetzel
Programming - Technology - Communications
"The Home of the SLC Security Console"
SLC now available for Linux...
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
webdaddy
Contributor
Contributor


Joined: 14 Nov 2004
Posts: 151
Location: Raleigh NC

PostPosted: Sun Nov 20, 2005 8:09 am    Post subject: Also Reply with quote

I also did a sniffer in VDS using netcat and calling it from VDS and hiding it with RUNH. You have to make sure you have WinPCap installed to do it with netcat but it does work. Hope that helps. Depends on what you really are looking to capture. There are may ways to do it. Why reinvent the wheel here.
_________________
K Wetzel
Programming - Technology - Communications
"The Home of the SLC Security Console"
SLC now available for Linux...
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    forum.vdsworld.com Forum Index -> General Help All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum

Twitter@vdsworld       RSS

Powered by phpBB © 2001, 2005 phpBB Group