Results 1 to 10 of 10

Thread: wireshark... confused

  1. #1
    Senior Member BigMac's Avatar
    Join Date
    Jan 2008
    Posts
    213

    Default wireshark... confused

    freewebs.com/onedayillpay/mylan.gif
    desktop 192.168.254.1
    labtop 192.168.254.2

    this is my simple setup. i have a linksys router and adsl modem.
    when running wireshark on my labtop (promiscuous mode on or off) if there is any activity on the desktop i get some red packets.
    Code:
    192.168.1.235 -> 239.255.255.250 SSDP NOTIFY * HTTP/1.1
    192.168.256.2 -> 239.255.255.250 SSDP M-SEARCH * HTTP/1.1
    I dont understand why i cant log the desktop's traffic.

  2. #2
    Senior Member streaker69's Avatar
    Join Date
    Jan 2010
    Location
    Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
    Posts
    3,535

    Default

    Quote Originally Posted by BigMac View Post
    freewebs.com/onedayillpay/mylan.gif
    desktop 192.168.254.1
    labtop 192.168.254.2

    this is my simple setup. i have a linksys router and adsl modem.
    when running wireshark on my labtop (promiscuous mode on or off) if there is any activity on the desktop i get some red packets.
    Code:
    192.168.1.235 -> 239.255.255.250 SSDP NOTIFY * HTTP/1.1
    192.168.256.2 -> 239.255.255.250 SSDP M-SEARCH * HTTP/1.1
    I dont understand why i cant log the desktop's traffic.
    Umm, could be because you're attempting to monitor traffic on a switched network?
    A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.

  3. #3
    Super Moderator Archangel-Amael's Avatar
    Join Date
    Jan 2010
    Location
    Somewhere
    Posts
    8,012

    Default

    Quote Originally Posted by BigMac View Post

    I dont understand why i cant log the desktop's traffic.

    Do yourself a favor and download the docs for wireshark located here:
    http://www.wireshark.org/docs/
    They are in several different formats.
    This will help you tremendously in the long run
    To be successful here you should read all of the following.
    ForumRules
    ForumFAQ
    If you are new to Back|Track
    Back|Track Wiki
    Failure to do so will probably get your threads deleted or worse.

  4. #4
    Developer
    Join Date
    Mar 2007
    Posts
    6,124

    Default

    Plus you have to be arp poisoning on a switched network in order to capture.

  5. #5
    Senior Member BigMac's Avatar
    Join Date
    Jan 2008
    Posts
    213

    Default

    Quote Originally Posted by pureh@te View Post
    Plus you have to be arp poisoning on a switched network in order to capture.
    are there any programs for vista that can perform a man in the middle attack?

  6. #6
    Developer
    Join Date
    Mar 2007
    Posts
    6,124

    Default

    Not sure. I know cain & able does not work in vista yet but I bet ettercap does.

  7. #7
    Just burned his ISO
    Join Date
    Jan 2008
    Posts
    14

    Default

    I have had no problem with Cain and Able in Vista.

  8. #8
    Senior Member BigMac's Avatar
    Join Date
    Jan 2008
    Posts
    213

    Default

    ettercap does not work for me in vista. . . ill try cain and abel. . .

  9. #9
    Member PeppersGhost's Avatar
    Join Date
    Jan 2008
    Posts
    204

    Default

    Quote Originally Posted by BigMac View Post
    i cant log the desktop's traffic.
    Or, you could connect you're laptop to a multi-port repeater between the switch and the modem.
    <EeePc 1000HA BT4/W7 USB boot Alfa500 GPS BlueTooth>

  10. #10
    Junior Member duwey96's Avatar
    Join Date
    Nov 2007
    Posts
    41

    Default

    Quote Originally Posted by PeppersGhost View Post
    Or, you could connect you're laptop to a multi-port repeater between the switch and the modem.
    haha can't say hub?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •