Table of Contents
Tactics to Discover “Passive”Monitoring Devices
The Problem at Hand
How Systems Know What to Listen To
Passive Wiretapping (solsniff, ethersniff sample)
Passive Wiretapping (NFS Handles sample)
Passive Wiretapping (SMB sample)
Older 95 / 98 File Sharing
Traffic and Pattern Analysis
Ether and IP Headers
The Disconnect
DNS MethodDefinition
DNS Method 1Sniffing the Sniffer
DNS Method 2Queries to DNS Server
DNS MethodPros and Cons
Ether TricksDefinition
Ether Tricks 1Linux Classic
Ether Tricks 1linux (cont)
Ether Tricks 1linux (cont)
Ether Tricks 2BSD Style Problems
Ether Tricks 3Microsoft Shortcut
Ether TricksPros and Cons
Machine Latencydefined
Machine Latencyexample
Machine Latencyexample
Machine Latencyexample
Machine Latencyexample (non-addressable interface)
Machine LatencyMethods for increasing end-node processing
Machine LatencyPros and Cons
Spotting the curious
|