About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-01-30, 05:09
SnakeEye SnakeEye is offline
Regular
 
Default 1337 SKILLZ NEEDED! Yeah.

I am currently teaching myself sniffing, and I am practicing on my own LAN. Since I live in the norwegian equivalent of Hickston, Tenesee, I am just about the only guy around with a DSL connection, and thus most of my friends have moved their computers into my appartment on a semi-permanent basis, creating a perfect testing environment. The network layout is as follows:
http://www.anathema.dynu.com/Network.jpg

Since really L33T kids are hosted on geocities, you'll have to copy&paste the link.

I use an old ETL3 card to tap into the traffic, and as you see I've plugged it in between the switch and the router, since that is the only common point in the network where the MAC frames remain intact. There are no protocols installed on the sniffer adapter, save for the SnifferPro driver protocol.

The sniffer adapter is connected by means of an old 8-port repeater hub, and this is where the first problem shows its ugly head: Even with the very small loads generated by the ADSL connection (1024/256), I see frequent collition warnings both on the hub and the switch. To make matters worse, the collitions occur much more frequently on the DSL modem as well. I can't really imagine why this is, because it is separated from the rest of the network by the router. Previously, the coll light would blink every now and then when I took more than 80 k/s out of the line, but now it lights up already at 60 k/s.

To get rid of this problem, I'd like to entirely eliminate the repeater, and connect the sniffer adapter directly to the switch built into the router. That leads me to my first question:

Is it possible to kick the switch into repeating mode without compromising network performance? I know I can flood it with bogous MAC frames to owerflow the forward buffer, but that would severly degrade performance, wouldn't it? Besides, it would lead to packet loss every time the buffer resets and blocks the sniffer's access to the switch-WAN communication.

What I'd really like to do, though, is to set one of the ports on the main switch (the EZ108DT) to span mode. This would not only cut the repeater out of the loop, but it would allow me access to all the other traffic on the network. Sadly, it is an unmanaged switch, so all the obvious solutions are out of the question. Any help will be greatly appreciated.

~Snake

P.S: Oh, and BTW, the post title was a joke. Just in case you didn't figure it out.

<EDIT>

Moved the pic

</EDIT>

[This message has been edited by SnakeEye (edited 01-31-2002).]
 #2 
Old 2002-01-31, 00:41
soullace soullace is offline
Regular
 
Default Re: 1337 SKILLZ NEEDED! Yeah.

It looks like to me that your repeater is creating a packet loop. This is what is degrating your network preformace.

If your computer sends a packet out the switch will get it and forward it out to your repeater (assuming your trying to go outside your network). Your repeater will promptly shove the packet right back at ya. At low speeds this shouldn't be too noticable, but at higher speeds you should notice it.

I would suggest setting up a machine in place of your repeater. Something like this.

(from switch)---->(computer with sniffer)--->(router)

Have like 2 NICs one that connects to the switch and one that connects to the router. Have the 2 cards bridged, and sniffing packets as they pass through. I have no clue how to do this on a windows machine... but it is entirely possible to do on a linux machine.

Also note there are probally devices you can program to do the same thing. I however do not have exeperience with these devices.
 #3 
Old 2002-01-31, 00:52
SnakeEye SnakeEye is offline
Regular
 
Default Re: 1337 SKILLZ NEEDED! Yeah.

Thanks, I'm working on it.

~Snake
 #4 
Old 2002-01-31, 01:46
Jadedfool Jadedfool is offline
Regular
 
Default Re: 1337 SKILLZ NEEDED! Yeah.

It looks as if you're attempting to use the repeater as a hub, which is a rather silly idea. I took a look at your network diagram and am trying to figure out why you even need that second connection to the backbone. But assuming you do, it could just as easily be attained by using another hub or even merely tapping back into the original.

The repeaters traffic is getting sent to the hub because what it sends out looks exactly the same as all the other packets, so it gets through the routers ruleset.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics