5 ms·
Could you elaborate on the suite of tools you used to do this kind of network traffic analysis?
by drzoltar 6y ago
Could you elaborate on the suite of tools you used to do this kind of network traffic analysis?
- err4nt 6y agoNot the original commenter but I've heard of people debugging smart TV's using https://www.wireshark.org https://www.wireshark.org to see the network requests, you would connect the device you want to inspect to a network being shared through your computer running Wireshark, and then you can analyze every request going in and out (or at least see them and be aware of the traffic)
- cgriswald 6y agoAlternatively, put your NIC into promiscuous mode and capture the traffic that way.
- nitrogen 6y agoThat only works if you use a hub instead of a switch, or if the traffic is broadcast, or if you somehow convince the switch to give your port all traffic. It's easiest to just use two NICs bridged in one PC as a MITM.
- mschuster91 6y agoYou can also easily run an ARP spoofing attack, and not just to sniff but also to manipulate. Done that quite often back in my school time, oh the glorious days when web traffic was mostly plain HTTP. There were entire command lists going around specifying what exactly one needed to replace, say, the logo of an online newspaper with a picture of a dong.
- dialamac 6y agoEven an el cheap basic managed switch will do port mirroring
- indymike 6y agoI got enough data on what was going on by just using dns logs and my router's built in logging.
- fiddlerwoaroof 6y agoYou can see a lot just with tcpdump on your router: either buy one supported by openwrt or buy a model with shell access available out of the box. You can also use tcpdump to save a pcap file that can then be analyzed with wireshark.
- fingerlocks 6y agoCould you suggest a small home router? I've been trying to find an 5Ghz / 802.11ax Wifi router with such features.
- fiddlerwoaroof 6y agoI’m not sure, you basically have to do the homework for consumer hardware: one issue you’ll run into is that consumer routers often depend on binary blobs and propriety drivers for WiFi functionality like MIMO. Netgear’s firmwares are based on OpenWRT, though, and nearly every netgear device I’ve owned has had some way to get shell access (my current device is a netgear Orbi (RBR40)). It has shell access and tcpdump is included in the base image.
- bane 6y agoIf all you need are connection info, pump the pcap through zeek and you'll get a nice set of rich tab delimited log files you can analyze.
- fiddlerwoaroof 6y agoYeah, zeek is a great tool. It took me a while to recognize it, though, the last time I used it, it was still called “bro”.
- indymike 6y agoA consumer grade router with logging configured to dump to a linux box + opendns.