Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Freebie Network Sniffers?

Thread Tools
 
Search this Thread
 
Old 13 January 2003, 12:06 PM
  #1  
Kevin Mc
Scooby Regular
Thread Starter
 
Kevin Mc's Avatar
 
Join Date: Mar 2002
Location: Leics
Posts: 689
Likes: 0
Received 0 Likes on 0 Posts
Question

Are there such things as Freebie Network Sniffers out there?

Need one specifically to see which port on a firewall a particular application is trying to use.

Situation is this: All ports on firewall are closed apart from one for windows printing and one for citrix. We have another process that needs to get through, though we have no idea which TCP/IP port it would be trying to get through.

Are there any decent freebies out there, or will we have to fork out (we being my work!)

Old 13 January 2003, 12:22 PM
  #2  
HHxx
Scooby Regular
 
HHxx's Avatar
 
Join Date: Nov 2001
Posts: 2,576
Likes: 0
Received 0 Likes on 0 Posts
Post

You shouldn't need a sniffer. Just go through the log files of the firewall to see whats happening.
Old 13 January 2003, 12:42 PM
  #3  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

What application is it ?
Old 13 January 2003, 01:27 PM
  #4  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

If you cant get what you need from Firewall Logs/Interface Snooping (if its Unix) then try Ethereal

If you need some basic packet capture its fine. Interface is clunky (nasty Linux port) but useable. Doesn't have the "experts" or some of the protocol decides that Sniffer etc have - but then its free and works with most NICs.

(Un)fortunately (I wanted some proper software ) it did everything I needed to diagnose a NAT bug recently.

www.ethereal.com

Deano

Old 13 January 2003, 01:33 PM
  #5  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

yep, a sniffer is not what you are after here.

Grab a copy of activeports which will reveal programs try/establish port connections. IF your running XP, I have heard that the netstat utility now has a new switch which will do this for you.

Easiest of all. Tell me what program it is, and I have a 95% chance of knowing which port and protocol it uses.

If you still wanna go for a sniffer most are free and there are loads out there.
I'm not a windows user, but if I remember correctly, ethereal does a sniffer for windows that is known for being one of the best. You can also check out things like snort. Although you are gonna need an understanding of packet structures, protocols etc. Leave your card out of promiscous mode. Most sniffers turn it on as standard.

Check www.securityfocus.com, blacksun.box.sk, neworder.box.sk, www.packetstormsecurity.nl and my mates site www.rishabhdara.com for more tools
Old 13 January 2003, 02:25 PM
  #6  
Kevin Mc
Scooby Regular
Thread Starter
 
Kevin Mc's Avatar
 
Join Date: Mar 2002
Location: Leics
Posts: 689
Likes: 0
Received 0 Likes on 0 Posts
Post

Easiest of all. Tell me what program it is, and I have a 95% chance of knowing which port and protocol it uses.
I've already asked the software author and they don't know (doesn't normally go through firewalls!)

Think the software will be in your 5% unfortunately, it is a Financial Accounting package (not off the shelf), and it is one of the server processes that prints that is causing the problem.

The firewall is at one of our customers - we've already asked them for the firewall logs, and they haven't exactly been forthcoming!

I think they just said that the firewall logs are by port number and we'd need to know the port number (catch 22 - if we knew that the bu66er would probably work!)

Server process is on a W2000 server.

Think I'll find out if they can get the logs just to show everything and not just by port number!

Cheers for the replies.

Old 13 January 2003, 02:28 PM
  #7  
ozzy
Scooby Regular
 
ozzy's Avatar
 
Join Date: Nov 1999
Location: Scotland, UK
Posts: 10,504
Likes: 0
Received 1 Like on 1 Post
Post

Kevin,

Ethereal is good. There's a Win32 port, so you can use on W2K/XP without any problems (IIRC, you need the WinPcap update too).

Stefan

Trending Topics

Old 13 January 2003, 03:23 PM
  #8  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

active ports will give you your answer.

http://www.webattack.com/get/activeports.shtml
Old 13 January 2003, 03:25 PM
  #9  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Do you know what Firewall it is ?

You could open up any protocol with a defined source and destination. Then you can filter the logs on destination and it should tell you what port/protocol is being used.
Old 13 January 2003, 03:26 PM
  #10  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Do you know what Firewall it is ?

You could open up any protocol with a defined source and destination. Then you can filter the logs on destination and it should tell you what port/protocol is being used.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
greg320
Non Car Related Items For sale
6
11 October 2015 11:44 AM
Mark Underwood
ScoobyNet General
5
22 July 2003 03:09 PM
Shark
Non Scooby Related
6
11 May 2001 05:52 PM
IWatkins
ScoobyNet General
1
24 October 2000 10:46 AM
Mick
Non Scooby Related
4
09 September 2000 11:45 PM



Quick Reply: Freebie Network Sniffers?



All times are GMT +1. The time now is 05:57 PM.