Dimanche 20 août 2006
Data theft via sniffing:


f. with a command line sniffer (currently detected by none antivirus on Virus Total):

We run (locally) the sniffer and connect to the web mail.



g. with Sniffer (Renamed, not detected by antivirus on Virus Total):

We run (locally) the sniffer and connect to the web mail.

Here the message hooks of the sniffer (with IceSword):



and some captured data while connecting to the web mail:



Here we can get more information about the cookies (and then the password):




h. with ngSniff:


With this known sniffer (scan on Virus Total), we capture packets from the host H1 with the IP 192.168.a.b of the computer A and the host H2 with the IP 192.168.b.c of the machine B.
The product is installed on A and the sniffer is launched from B.

i. Instant Messaging sniffing:

Here we use a free tool unknown from AVs database and which has the ability to sniff instant messenging conversations (MSN, Yahoo, IRC etc).




NB. For more information about security and instant messenging in general:

- "Securing Instant Messanging" by Symantec,

- For a deep study, it can be suited to take a look at M. Mannan papers and research, especially the diploma thesis.






par Kareldjag publié dans : METHODOLOGY
ajouter un commentaire commentaires (1)    recommander

Calendrier

Août 2006
L M M J V S D
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      
<< < > >>

Recherche

Blog : Gay sur over-blog.com - Contact - C.G.U. - Rémunération en droits d'auteur avec TF1 Network - Signaler un abus