(This is another nice feature of ZxSniffer as it saves the data in HTML format.)
By opening the file (the default location ZxSniffer files are saved to is C:\
ProgramFiles\ZxSniffer/, you can review the results of the file in HTML format.
246 Practical Hacking Techniques and Countermeasures
From the ZxSniffer application click on the Capture icon. The packet
capture screen will appear.
Click on the Start icon to initiate the packet capture (sniffer).
Sniffing Traffic 247
When enough data has been captured, click on the Stop icon and the
captured data will appear.
From the data captured, scroll through the center area and view the content
of the packet in the lower-right area of the ZxSniffer screen to look for any
valuable data that may be in the packets (plain text).
In this case, an FTP session was established with the username of hacker.
248 Practical Hacking Techniques and Countermeasures
By scrolling through the packets one at a time, the password is also
displayed. In this case the password is zerocool.
Minimize the application and it will place an icon by the clock in the lowerright
section of the Windows desktop. By placing the mouse over this icon
periodically, ZxSniffer will let you know how many new passwords have been
captured since the last time you checked.
*Note: I have personally used this application in conjunction with the ???see all??? port
on a switch to help track down a hacker coming out of New York City via a
compromised server of a travel agency out of Washington state.
Pages:
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114