Data sniffing

Results 1 to 9 of 9
  1. #1
    Programmer cyberinferno is offline
    MemberRank
    Jun 2009 Join Date
    127.0.0.1Location
    707Posts

    talk Data sniffing

    Can anyone give me a hint how to sniff all the data that is being sent from Zone Agent to Zone Server and vice-versa?


  2. #2
    Goodbye chrissdegrece is offline
    MemberRank
    Oct 2009 Join Date
    GreeceLocation
    1,015Posts

    Re: Data sniffing

    [url=http://www.wireshark.org/]Wireshark

    or you can intercept winsock functions and do yourself.

  3. #3
    Programmer cyberinferno is offline
    MemberRank
    Jun 2009 Join Date
    127.0.0.1Location
    707Posts

    Re: Data sniffing

    So if I use 'Socket.Bind' method of C# with Zone Server's IP and port can I get all data?

  4. #4
    @work onyourrisk is offline
    MemberRank
    Jan 2008 Join Date
    IndiaLocation
    706Posts

    Re: Data sniffing

    If you are running on a local machine wireshark it can not trace local packets, for such purpose you may try Local Network Monitor by ntkernel

  5. #5
    Goodbye chrissdegrece is offline
    MemberRank
    Oct 2009 Join Date
    GreeceLocation
    1,015Posts

    Re: Data sniffing

    no, socket.bind won't work. And yes you have to put one of the servers (ZA,ZS) inside a vm for wireshark to capture packets.

    You will have to hijack winsock functions by e.g. injecting a dll and redirect sending/receiving functions to your dll which will then log the packet buffer.

  6. #6
    Programmer cyberinferno is offline
    MemberRank
    Jun 2009 Join Date
    127.0.0.1Location
    707Posts

    Re: Data sniffing

    Quote Originally Posted by onyourrisk View Post
    If you are running on a local machine wireshark it can not trace local packets, for such purpose you may try Local Network Monitor by ntkernel
    Will try this software bit later. Right now building my own sniffer in C# which sniffs from a particular TCP/UDP port.

  7. #7
    Ŋ cvrdheeraj is offline
    MemberRank
    Jul 2006 Join Date
    IndiaLocation
    1,210Posts

    Re: Data sniffing

    Inject a DLL and hook the Winsock functions to read the data.

  8. #8
    Goodbye chrissdegrece is offline
    MemberRank
    Oct 2009 Join Date
    GreeceLocation
    1,015Posts

    Re: Data sniffing

    Download winject (search google) and try injecting this dll in your za process.

    Start LS,LA etc. when communication starts it will create a file c:\zalog.txt like this:

    Code:
    03:44:30 PM: ZoneAgent -> 127.0.0.1:2429 (Length: 52 bytes)
    
            0  1  2  3  4  5  6  7   8  9  A  B  C  D  E  F
           -- -- -- -- -- -- -- --  -- -- -- -- -- -- -- --
    0000   20 01 41 11 00 00 73 26  b1 c0 0a 00 00 00 00 00    .A...s&........
    0010   00 00 01 ff 20 01 71 1d  00 01 04 8d f6 1b 16 00   .... .q.........
    0020   00 00 00 00 00 00 01 f0  00 00 00 00 b8 9c fc 4d   ...............M
    0030   00 00 00 00                                        ....
    
    
    03:44:35 PM: ZoneAgent -> 127.0.0.1:2429 (Length: 32 bytes)
    
            0  1  2  3  4  5  6  7   8  9  A  B  C  D  E  F
           -- -- -- -- -- -- -- --  -- -- -- -- -- -- -- --
    0000   2d 01 71 1d 00 02 01 9a  e5 e6 16 00 00 00 00 00   -.q.............
    0010   00 00 01 f0 01 00 00 00  42 b0 fc 4d 00 00 00 00
    Close ZA and study file
    Attached Files Attached Files

  9. #9
    Programmer cyberinferno is offline
    MemberRank
    Jun 2009 Join Date
    127.0.0.1Location
    707Posts

    Re: Data sniffing

    Quote Originally Posted by chrissdegrece View Post
    Download winject (search google) and try injecting this dll in your za process.

    Start LS,LA etc. when communication starts it will create a file c:\zalog.txt like this:

    Code:
    03:44:30 PM: ZoneAgent -> 127.0.0.1:2429 (Length: 52 bytes)
    
            0  1  2  3  4  5  6  7   8  9  A  B  C  D  E  F
           -- -- -- -- -- -- -- --  -- -- -- -- -- -- -- --
    0000   20 01 41 11 00 00 73 26  b1 c0 0a 00 00 00 00 00    .A...s&........
    0010   00 00 01 ff 20 01 71 1d  00 01 04 8d f6 1b 16 00   .... .q.........
    0020   00 00 00 00 00 00 01 f0  00 00 00 00 b8 9c fc 4d   ...............M
    0030   00 00 00 00                                        ....
    
    
    03:44:35 PM: ZoneAgent -> 127.0.0.1:2429 (Length: 32 bytes)
    
            0  1  2  3  4  5  6  7   8  9  A  B  C  D  E  F
           -- -- -- -- -- -- -- --  -- -- -- -- -- -- -- --
    0000   2d 01 71 1d 00 02 01 9a  e5 e6 16 00 00 00 00 00   -.q.............
    0010   00 00 01 f0 01 00 00 00  42 b0 fc 4d 00 00 00 00
    Close ZA and study file
    Thanks a lot :)



Advertisement