Sniffers
Sean-Philip Oriyano · 2016
This chapter describes sniffers as utilities that an ethical hacker can use to capture and scan traffic moving across a network. Sniffers are a broad category that encompasses any utility that has the ability to perform a packet-capturing function. The real advantage of one over the other is the robustness of functionality in how the sniffer displays that data and what options are available to help users digest and dissect it. Switched networks present an inherent initial challenge to sniffing a network in its entirety. A wired switch does not allow users to sniff the whole network. MAC spoofing is a simple concept in which an attacker (or pentester) changes their MAC address to the MAC address of an existing authenticated machine already on the network. The simplest example of employing this strategy is when a network administrator has applied port security to the switches on their network. Aside from pure defensive tactics, it is possible to be proactive and use detection techniques designed to locate any attempts to sniff and shut them down. Sniffing is a technique used to gather information as it flows across the network. Sniffing can be performed using software-based systems or through the use of hardware devices known as protocol analyzers.