Prev | Current Page 103 | Next

Mark D. Spivey

"Practical Hacking Techniques and Countermeasures"

This is an
effective tool.
As for an attacker??™s advantage, a prime example would be to have a
compromised Terminal Service account, term serve into the server, and execute
the ZxSniffer application. Then at the attacker??™s convenience log back in
and check the passwords captured, packets captured, and so forth.
Sniffing Traffic  249
Lab 47: Exploit Data from Target Computer ??“??“ Sniffit
Prerequisites: None
Countermeasures: Secure access control lists (ACLs), Bastion servers/
workstations, host-based firewalls
Description: The Sniffit application captures Transfer Control Protocol
(TCP), UDP, and ICMP packets, which provide detailed information in
hex or plain text. Sniffit can detect Ethernet and PPP and other devices,
can filter the results for desired effects, and can save the output to a
log file for further analysis. Remember that all commands in Linux are
case sensitive.
Procedure: Configure and create the Sniffit application and execute with
the following syntax:
sniffit
From the directory containing the compressed files type tar ??“zxvf snif-
fit.0.3.7.beta.tar.gz.
The files will uncompress into a new directory named sniffit.0.3.7.beta.
Change to the new directory by typing cd sniffit.0.3.7.beta and pressing
Enter.
The Sniffit application needs to be compiled to the specific machine it is
on by typing ./configure.
250  Practical Hacking Techniques and Countermeasures
The Sniffit application will configure for the specific machine.


Pages:
91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115