Before we discuss about how to sniffing action in a LAN network, it's good that we know what is meant by sniffing.
Sniffing is a tapping action. See how that is used, sniffing divided kedalan two categories, namely passive sniffing do without tapping the data packet or any of the network while active in the packet sniffing the network or send a packet with the MAC address change randomly in a number of very many. Active sniffing usually use the additional tool (which is normally used Etherflood), but this time we will only discuss how to use the passive sniffing and tools that we use is Cain & Abel.
Cain & Abel is a tool that is very popular and very simple way penggunaannyapun, to sedot Cain & Abel can be taken on the topic TOOLS.
The steps that must be done:
1. Install the program Cain & Abel
2. Run Cain
3. To do sniffing action, click on the tab of sub-Sniffer
4. Click the tab of sub-APR
5. Click the Configure menu - Configure dialog will appear that contains several of the sub-configuration tab - click the tab Sniffer - will appear some information about the adapter, IP Address, etc. - click on a line below the previous menu that contains a description of the computer's IP Address, MAC etc. - and then OK.
6. Cain's active by clicking Start button
7. So that we have the computer capability routing, click the Start button APR
8. Run Command Prompt
9. Make communication with the target computer to do with pinging the IP Address to the target computer, for example c: \ ping 192.168.0.2, in some cases our pinging must do (according to my experience, pinging is the fastest way to make communication with the target computer) more than one computer , It aims to make computers as the gateway.
10. Cain on the table, two bermenu the same status, IP Address, MAC Address, etc.. To start, click the top of the table (the router area), then click the plus sign (Add to the list)
11. New dialog will appear ARP Aim Routing. Click the IP Address that the target computer in the left column and click the IP Address computer gateway in the right column. Click OK
After the IP Address into the list, we wait in traffic lived a packet caught by Cain. To know the results caught, click the Passwords tab.
- The work of Cain:
Cain & Abel poison ARP table of the target computer so that communication between a computer with the target should be the gateway through the computer.
- Issues that are often found:
Cain & Abel is often identified as viruses by antivirus software, this is because antivirus software using the facilities heuristic-guessing nebak file as a virus, this function aims to identify new viruses that have not yet detected by antivirus databases. However, this facility sometimes a "false warning" and assume certain programs, especially a hack tools, as viruses, and even considered any other anti-virus.
- How to prevent this action snifing:
To prevent this action, do the changes in the ARP, in this type of ARP that we will change the dynamic of a static. How: c: \ ARP-s [IP Address] [MAC Address] and to return to the original state, change the attributes of a-s-d
http://www.oxid.it/cain.html











 

0 komentar:
Posting Komentar