Sniffer Detectors |
|
| Sniffers |
|
| Sniffer Scripts |
|
| Hunting for Sniffers ( Sniffer Detector ) Howto |
- Check for local sniffers
- Check for Remote sniffers ( wireless, vpn, upstream isp, colo, ... )
- Check for sniffers on the other side of the switch
- Check for ipv6 sniffers
- Check for "sniffer drivers" ( e.g. winpcap/libpcap ) used by the sniffers
- Search for any NIC card in promiscuous mode
- Search for sniffer apps: tcpdump, ethereal, ethapp, etc..
- Search for hidden processes
- Search for rogue ( un-authorized ) machines
- Perform kernel tests
- Perform DNS tests
- Perform ARP tests
- Perform latency tests
- Perform icmp ( ping ) tests
|
| Sniffer Detectors |
|
| Misc Sniffer Detectors |
|
| Promiscuous Detectors |
- Check for Promiscuous mode
ifconfig -v | grep -i Promisc
# Turn Off Promiscuous mode
ifconfig eth0 -promisc
- CPM Check for network interfaces in Promiscuous Mode
- ifstatus
- AntiSniff --> atstake.com --> symantec
- neped.c = Neped = NEtwork Promiscuous Ethernet Detector ( local copy )
- proscan.c promiscuous mode scanner
- Sentinel remote promiscuous detection techniques
|
| Windoze-based Sniffer Detectors |
- ProDetect promiscuous mode scanner
|