天天看點

Common Network Analyzers

the diversity and number of sniffers available. Some of the most prominent are:

■ Wireshark Wireshark is one of the best sniffers available and is being

developed as a free, commercial-quality sniffer. It has numerous features, a

nice graphical user interface (GUI), decodes over 400 protocols, and is

actively being developed and maintained. It runs on UNIX-based systems,

Mac OS X, and Windows.This is a great sniffer to use in a production

<a href="http://www.syngress.com/">[url]www.syngress.com[/url]</a>

8 Chapter 1 • Introducing Network Analysis

Figure 1.2 Sniffing a Connection

■ WinDump WinDump is the Windows version of tcpdump, and is available

on Windows 95, 98, ME, NT, 2000, and XP.

■ Network General Sniffer A Network General Sniffer is one of the most

popular commercial sniffers available.Now a suite of enterprise network capture

■ Windows 2000 and 2003 Server Network Monitor Both the

Windows 2000 Server and the Windows 2003 Server have a built-in program

to perform network analysis. It is located in the “Administrative

Tools” folder, but is not installed by default; therefore, you have to add it

from the installation CD.

■ EtherPeek EtherPeek is a commercial network analyzer developed by

WildPackets.Versions for both Windows and Mac, and other network analysis

■ Tcpdump Tcpdump is the oldest and most commonly used network

sniffer, and was developed by the Network Research Group (NRG) of the

Information and Computing Sciences Division (ICSD) at Lawrence

Berkeley National Laboratory (LBNL). It is command line-based and runs

on UNIX-based systems, including Mac OS X. It is actively developed and

■ Snoop Snoop is a command-line network sniffer that is included with the

Sun Solaris OS.

■ Snort Snort is a network IDS that uses network sniffing, and is actively

to Nessus, Snort, &amp; Ethereal Power Tools: Customizing Open Source Security

Applications (Syngress Publishing: 1597490202) and Snort Intrusion Detection

and Prevention Toolkit (Syngress, ISBN: 1597490997).

■ Dsniff Dsniff is a very popular network-sniffing package. It is a collection

of programs that are used to specifically sniff for interesting data (e.g., passwords)

and to facilitate the sniffing process (e.g., evading switches). It is

■ Ettercap Ettercap was specifically designed to sniff a switched network. It

has built-in features such as password collecting, OS fingerprinting, and

character injection, and runs on several platforms including Linux,

Windows, and Solaris. It is actively maintained at ettercap.sourceforge.net.

Introducing Network Analysis • Chapter 1 9

■ Analyzer Analyzer is a free sniffer that is used for the Windows OS. It is

being actively developed by the makers of WinPcap and WinDump at

Politecnico di Torino, and can be downloaded from analyzer.polito.it.

■ Packetyzer Packetyzer is a free sniffer (used for the Windows OS ) that

uses Wireshark’s core logic. It tends to run a version or two behind the current

release of Wireshark. It is actively maintained by Network Chemistry

■ MacSniffer MacSniffer is specifically designed for the Mac OS X environment.

It is built as a front-end for tcpdump.The software is shareware

and can be downloaded from

本文轉simmy51CTO部落格,原文連結:http://blog.51cto.com/helpdesk/122586,如需轉載請自行聯系原作者

繼續閱讀