Tools to detect sniffers....Herramientas para detectar Sniffers.

The sniffers are major security threats in a network and can save time to detect intrusions as safety catches packets with authentication data, using programs like Cain & Abel. " Although the best way to protect against these threats is to use an IDS or encrypted connections, but sometimes it is not possible.

To detect these threats in a fast, in networks that do not use the countermeasures listed above, we can use tools that detect the network adapters that are running in promiscuous mode (so necessary for running sniffers). Tools such as:

In Linux.

Sniffdet is a system of tests for remote sniffers network. Test techniques used ICMP, ARP test, test and test DNS ping latency.

More info and download Sniffdet:
http://sniffdet.sourceforge.net/

The Sentinel project is an implementation of techniques for detection of promiscuous mode. Libraries Need: libpcap and libnet. Used methods: DNS test, test, ARP, ICMP Etherping test, ping and latency.

More info and download Sentinel:
http://www.packetfactory.net/Projects/sentinel/
Windows

ProDETECT is a browser sniffers, which uses an ARP packet analysis.

More info and download ProDETECT:
http://sourceforge.net/projects/prodetect/

Promgry and PromgryUI are two tools that detect the network adapters that are running in promiscuous mode, the difference between the two is that PromgryUI has Promgry graphical interface and runs in the command console.

More information, download and use of Promgry and PromgryUI:
http://support.microsoft.com/kb/892853/es

PromiscDetect checks if your network adapter is operating in promiscuous mode, serves to prove that an sniffers running on the machine.

More info and download PromiscDetect:
http://www.ntsecurity.nu/toolbox/promiscdetect/
................................................................................
Los sniffers son grandes amenazas de seguridad en una red y detectarlos a tiempo puede salvarnos de intrusiones de seguridad como las capturas de paquetes con datos de autentificación, usando programas como “Cain & Abel”. Aunque la mejor forma de protegerse ante estas amenazas es utilizar un IDS o cifrar las conexiones, aunque algunas veces no es posible.

Para detectar estas amenazas de una forma rápida, en redes que no utilizan las contramedidas anteriormente citadas, podemos utilizar herramientas que detectan los adaptadores de red que están funcionando en modo promiscuo (modo necesario para el funcionamiento de los sniffers). Herramientas como:

En Linux.

Sniffdet es un sistema de pruebas para la detección remota de los sniffers de red. Usa las técnicas test ICMP, test ARP, test DNS y test de ping de latencia.

Más información y descarga de Sniffdet:
http://sniffdet.sourceforge.net/

El proyecto del Sentinel es una puesta en práctica de las técnicas de detección de modo promiscuo. Necesita las bibliotecas: libpcap y libnet. Utiliza los métodos de: test DNS, test ARP, prueba ICMP Etherping, y ping de latencia.

Más información y descarga de Sentinel:
http://www.packetfactory.net/Projects/sentinel/

En Windows

ProDETECT es un explorador de sniffers, que utiliza una técnica de análisis del paquete ARP.

Más información y descarga de ProDETECT:
http://sourceforge.net/projects/prodetect/

Promgry y PromgryUI son dos herramientas que detectan los adaptadores de red que están funcionando en modo promiscuo, la diferencia entre una y otra es que PromgryUI tiene interfaz grafica y Promgry se ejecuta en consola de comandos.

Más información, descarga y modo de empleo de Promgry y PromgryUI:
http://support.microsoft.com/kb/892853/es

PromiscDetect comprueba si su adaptador de red está funcionando en modo promiscuo, sirve para probar que un sniffers está funcionando en la maquina.

Más información y descarga de PromiscDetect:
http://www.ntsecurity.nu/toolbox/promiscdetect/

No hay comentarios:

Protected by Copyscape Original Article Checker