| Table of ContentsTactics to Discover “Passive”Monitoring Devices The Problem at Hand How Systems Know What to Listen To Passive Wiretapping (solsniff, ethersniff sample) Passive Wiretapping (NFS Handles sample) Passive Wiretapping (SMB sample) Older 95 / 98 File Sharing Traffic and Pattern Analysis Ether and IP Headers The Disconnect DNS MethodDefinition DNS Method 1Sniffing the Sniffer DNS Method 2Queries to DNS Server DNS MethodPros and Cons Ether TricksDefinition Ether Tricks 1Linux Classic Ether Tricks 1linux (cont) Ether Tricks 1linux (cont) Ether Tricks 2BSD Style Problems Ether Tricks 3Microsoft Shortcut Ether TricksPros and Cons Machine Latencydefined Machine Latencyexample Machine Latencyexample Machine Latencyexample Machine Latencyexample (non-addressable interface) Machine LatencyMethods for increasing end-node processing Machine LatencyPros and Cons Spotting the curious |