Packet Sniffers: Prepared By: Amer Alhorini Supervised By: Dr. Lo'ai Tawalbeh Nyit New York Institute of Technology
Packet Sniffers: Prepared By: Amer Alhorini Supervised By: Dr. Lo'ai Tawalbeh Nyit New York Institute of Technology
Prepared By:
Amer Alhorini
Supervised By:
Dr. Lo'ai Tawalbeh
NYIT
New York Institute of Technology
1
The Network Today
2
Packet Sniffers
Host A Host B
Router A Router B
• A packet sniffer is a software application that uses a network adapter card in promiscuous mode to capture
all network packets. The following are the packet sniffer features:
Packet sniffers exploit information passed in clear text. Protocols that pass information in the clear include the following:
•Telnet
•FTP
•SNMP
•POP
Packet sniffers must be on the same collision domain.
3
Packet Sniffer Mitigation
Host A Host B
Router A Router B
4
Trends that Affect Security
5
Network Threats Attack Examples
Compromised
host
6
Four Classes of Network Attacks
Reconnaissance attacks
Access attacks
Denial of service attacks
Worms, viruses, and Trojan horses
7
Specific Attack Types
8
Reconnaissance Attack Example
• Sample IP address
query
Sample
domain
name
query