Section: .. / sniffers /
| /// File Name: |
driftnet-0.1.6.tar.gz |
Description:
|
Driftnet is a program which sniffs network traffic and picks out images from TCP streams it observes. It is interesting to run it on a host which sees a lot of web traffic.
| | Homepage: | http://www.ex-parrot.com/~chris/driftnet | | Changes: | This release fixes problems with building in adjunct-only mode. There are performance enhancements. | | File Size: | 36989 | | Last Modified: | Jul 10 02:34:32 2002 |
| MD5 Checksum: | 8e11d77770452f97bb3c23f510489815 |
|
| /// File Name: |
snmpsniff-0.8b.tar.gz |
Description:
|
SNMP promiscuous packet sniffer/decoder.
| | File Size: | 34546 | | Last Modified: | Aug 16 20:13:44 1999 |
| MD5 Checksum: | 0e4ebb0fb00975e4dbad5f7f849af1e6 |
|
| /// File Name: |
brian.c |
Description:
|
Brian.c is a simple tool to effectively convert a switched network (or a part of it) into a shared network so that sniffing can take place. Allows ARP spoofing of any number of machines, includes an internal relay process for relaying packets to the correct destination, provides a gateway switch for spoofing routers, includes various timing options, and includes a DOS switch for spoofing without relaying. Includes everything to turn a switched network into a shared network so that sniffing can take place, in one easy to use tool. Based on ARP poisoning from Ettercap, but unlike Ettercap it works in many-to-many scenarios which are present in shared networks. Tested on Redhat 8, it compiles under Linux. Requires libnet and libpcap.
| | Author: | Kev | | Homepage: | http://www.bournemouthbynight.co.uk | | File Size: | 33848 | | Last Modified: | Dec 2 22:58:35 2003 |
| MD5 Checksum: | fb9951c00ae07464d20360666ecce380 |
|
| /// File Name: |
ippacket-2.1.tar.gz |
Description:
|
ippacket 2.1 - ippacket is a command line/curses utility to construct IP/TCP/UDP/ICMP packets on a Linux system.
| | Author: | Sean Harney | | Changes: | Redid curses interface, worked out some Makefile issues. | | File Size: | 31540 | | Last Modified: | Aug 16 20:13:53 1999 |
| MD5 Checksum: | 6d2baca3e5a362e365832377347c1140 |
|
| /// File Name: |
fl0p-devel.tgz |
Description:
|
fl0p is a passive L7 flow fingerprinter that examines TCP/UDP/ICMP packet sequences, can peek into cryptographic tunnels, can tell human beings and robots apart, and performs a couple of other infosec-related tricks.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 30297 | | Last Modified: | Dec 6 00:15:28 2006 |
| MD5 Checksum: | 2f5fe95ef695eb2ff566ca2aa403b945 |
|
| /// File Name: |
screenshot04.gif |
Description:
|
Unavailable.
| | File Size: | 30137 | | Last Modified: | Nov 8 14:06:49 1999 |
| MD5 Checksum: | 5a5c49d6d234cd0e2f4e577df70c0249 |
|
| /// File Name: |
trafdisp.tgz |
Description:
|
Trafdisp is a sniffer which allows you to monitor the amount of incoming/outgoing KBps on a selected network interface(s) from at least one machine. It allows a network administrator to monitor the traffic that is generated by all the hosts on the network. The traffic is viewable in neat graphs that are generated by a PHP-enabled Web-server. The logs are stored in a MySQL table.
| | Homepage: | http://thegod.bsd.org.il/projects.php | | File Size: | 29051 | | Last Modified: | Apr 6 17:37:28 2001 |
| MD5 Checksum: | b38a9aa186a68fb96025ab683a900709 |
|
| /// File Name: |
promiscdetect.exe |
Description:
|
PromiscDetect for Windows NT 4.0 / 2000 / XP checks if your network adapter(s) is in promiscuous mode or not (that is, in most cases, if a sniffer is running on the computer or not). Of course the attacker might be intercepting the communication between the tool and the adapter, making the result unreliable, but there are probably many more cases out there where the tool will really detect a sniffer.
| | Author: | Arne Vidstrom | | Homepage: | http://ntsecurity.nu/toolbox/promiscdetect/ | | File Size: | 28672 | | Last Modified: | Apr 23 01:21:10 2002 |
| MD5 Checksum: | 117ec27602980ae13307a7c2021a5d90 |
|
| /// File Name: |
rtpbreak-1.0.tgz |
Description:
|
rtpBreak detects, reconstructs and analyzes any RTP [rfc1889] session through heuristics over the UDP network traffic. It works well with SIP, H.323, SCCP and any other signaling protocol. In particular, it does not require the presence of RTCP packets (voipong needs them) that are not always transmitted from the recent VoIP clients.
| | Author: | Michele Dallachiesa | | Homepage: | http://xenion.antifork.org/rtpbreak/rtpbreak.html | | File Size: | 28009 | | Last Modified: | May 30 23:09:47 2007 |
| MD5 Checksum: | fc63c4dbe617384f97cacdbbc85e4584 |
|
| /// File Name: |
assitch-2.6.tgz |
Description:
|
Assitch is a remote packetfilter analyzer, that detects in and OUT rules by doing ACK scanning. (It's useless against state-full filters.) Assitch is 3 years old, but still useful for debugging filter rules.
| | Author: | Thomas Biege | | Homepage: | | | File Size: | 26132 | | Last Modified: | Oct 30 18:46:50 2000 |
| MD5 Checksum: | 3d88df3f893dc36c738211b59fa86817 |
|
| /// File Name: |
sniffy-0.1.1.tar.bz2 |
Description:
|
The sniffy project can trace/log the data of any pseudo terminal in the system. Due to the way the terminal works, such a terminal trace provides complete information of what happened on the terminal screen, and sniffy is able to display/replay this information. It consists of a kernel module able to connect/hook on the pseudo terminal, a program to display the contents of any pseudo terminal on the fly, a daemon process tracing the pseudo terminal content into the file, and a replay program to replay any stored pseudo terminal session.
| | Author: | jolsa | | Homepage: | http://sniffy.sourceforge.net/ | | File Size: | 21640 | | Last Modified: | Nov 4 00:56:06 2008 |
| MD5 Checksum: | bff2beb2a62f86a56b24c820a573d750 |
|
| /// File Name: |
rpfcd-0.10.tar.gz |
Description:
|
Remote pf control daemon allows remote control and monitoring of OpenBSD packet filter. It communicates with clients using RPFC protocol running on top of SSL (Secure Socket Layer). The protocol is designed to be relatively forgiving and easy to use.
| | Homepage: | http://www.insecure.dk/rpfcd | | File Size: | 21343 | | Last Modified: | Oct 30 03:30:58 2002 |
| MD5 Checksum: | 11374aabaa798230ebb27c655c205700 |
|
| /// File Name: |
Sniffer_construction.txt |
Description:
|
Basic Packet-Sniffer Construction from the Ground Up - This is a detailed whitepaper on how to constuct a working packet-sniffer in ansii C. Excellent work, very detailed, a "must-read" for everybody.
| | Author: | Chad Renfro | | File Size: | 20577 | | Last Modified: | Aug 16 20:13:52 1999 |
| MD5 Checksum: | cc86fc1debd85c740076e84a3a352b08 |
|
| /// File Name: |
gdd13.c |
Description:
|
Ethernet Packet Sniffer 'GreedyDog' Version 1.30. The Shadow Penguin Security. Written by Unyun
| | File Size: | 19947 | | Last Modified: | Oct 17 07:35:09 1999 |
| MD5 Checksum: | b49715544cdb7743f6a28eec00e6c2a3 |
|
| /// File Name: |
tgk-log-2.2.tar.gz |
Description:
|
tgk-log 2.2 - A remade version of linsniffer, no longer recording just contents of a packet but some additional information. Designed to be used for logging the traffic through a ipmasq gateway. More TCP, UDP, ICMP support, and code optimization with this release.
| | Author: | The c5 Project | | File Size: | 19865 | | Last Modified: | Aug 16 20:13:50 1999 |
| MD5 Checksum: | a5280e65d98fc879c62930fd412cb580 |
|
| /// File Name: |
tgk-log-2.3.tar.gz |
Description:
|
tgk-log 2.3 - A remade version of linsniffer, no longer recording just contents of a packet but some additional information. Designed to be used for logging the traffic through a ipmasq gateway. More TCP, UDP, ICMP support, date bug fixed, correctly logs a ip-masq gateway with 2.2.x kernel, and code optimization with this release. 19k.
| | Author: | The c5 Project | | File Size: | 19835 | | Last Modified: | Aug 16 20:13:51 1999 |
| MD5 Checksum: | c8926364ad9b7e2d07ec62d6ba053d0a |
|
| /// File Name: |
solsniff.c |
Description:
|
This is sunsniffer.c modified to run on dlpi systems, notably solaris 2.x.
| | File Size: | 19596 | | Last Modified: | Aug 16 20:13:44 1999 |
| MD5 Checksum: | 8100356d04d4a6c01b51444b50ab29f9 |
|
| /// File Name: |
getdatang.tar.gz |
Description:
|
Getdata Protocol Analyzer is another sniffer made with libpcap that supports multiple protocols like TCP, UDP, ICMP, IGMP, etc.
| | Author: | Victor Pereira | | Changes: | Added experimental support for traffic statistics and various bugfixes. | | File Size: | 16498 | | Last Modified: | Apr 30 10:12:59 2003 |
| MD5 Checksum: | e0779d4543df512cd6808c01ebb8e920 |
|
| /// File Name: |
Sniffer2.txt |
Description:
|
Packet Sniffer Construction, Part II - The second installment of the "Packet Sniffer Construction" series off whitepapers by Chad Renfro. Includes good code and excellent, detailed descriptions.
| | File Size: | 15056 | | Last Modified: | Aug 16 20:13:44 1999 |
| MD5 Checksum: | cf09ba4b466066d23ab085ba1c5f25b7 |
|
| /// File Name: |
iosniff.tgz |
Description:
|
Cisco Systems IOS 11.x UDP echo memory leak remote sniffer. The UDP echo service (UDP port 7) has to be enabled on the device. The bug will cause the Cisco router to send about 20 kilobytes of data from the interface buffer pools containing packets in the send/recv/forward queues. This tool will identify IOS memory blocks, find the router specific offset for packets in the block and decode the packet to the screen. Note that this is not a full dump of the traffic through the remote router but rather a subset of received data. Features include a packet checksum cache to prevent repeated output of the same packet, auto identification of packets and buffer offsets, and IPv4 decoding.
| | Author: | FX | | Homepage: | http://www.phenoelit.de | | File Size: | 14594 | | Last Modified: | Aug 10 16:35:45 2003 |
| MD5 Checksum: | ad960f073fda285b82dea6d8225ec6f8 |
|
| /// File Name: |
sniffer-analysis.htm |
Description:
|
Sniffer analysis of a captured frame.
| | File Size: | 14313 | | Last Modified: | Aug 16 20:13:44 1999 |
| MD5 Checksum: | ab51e76b602528f6b219f2ed5da1a06c |
|
| /// File Name: |
dietsniff-0.4.tar.bz2 |
Description:
|
dietsniff is a tiny tool for analyzing traffic on a network. It is not intended to replace well-known tools like tcpdump or ethereal. It is intended for the case when a small and especially static sniffer is required. Accordingly, it is also by far not that powerful, and is also bound to Linux as a platform.
| | Author: | Hynek Schlawack | | Homepage: | http://www.ularx.de/dietsniff/ | | Changes: | Multiple bug fixes. | | File Size: | 13574 | | Last Modified: | Dec 30 14:06:44 2008 |
| MD5 Checksum: | 7ffed56c4a0f1f050457dd526e628d07 |
|
|
|
|
|