OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-Disclosure] Telnet Sniff Problems

From: Alexander Schreiber (alsthangorodrim.de)
Date: Mon Mar 22 2004 - 16:36:16 CST


On Mon, Mar 22, 2004 at 08:51:23PM +0100, Nico Golde wrote:
> Hallo IndianZ,
> realname is welcome.
> * IndianZ <indianzindianz.ch> [2004-03-22 14:08]:
> > Have a problem while auditing a network.
> > I will capture telnet-passwords, but tcpdump
> > and dsniff only show a single empty frame
> > instead of a password. Has anybody a hint
> > what happend? Other things are captured
> > well...
>
> how do you sniff with tcpdump?
> if i youse tcpdump -n -s 2048 -i eth0 -w dump.log

Actually, setting the snaplen to 1500 will be sufficient as long as you
are dealing with plain old ethernet, since thats the maximum size of the
ethernet frames.

Regards,
       Alex.
--
"Opportunity is missed by most people because it is dressed in overalls and
 looks like work." -- Thomas A. Edison

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html