Results 1 to 4 of 4

Thread: Ethereal/Wireshark

  1. #1
    Join Date
    Jul 2008
    Posts
    14

    Ethereal/Wireshark

    Plz point me how to trace the intruders and virus traffic from Ethereal/Wireshark

  2. #2
    Join Date
    May 2008
    Posts
    188
    Run tcpdump, or the dumpcap utility that comes with Wireshark, with superuser privileges to capture packets into a file, and later analyze these packets by running Wireshark with restricted privileges on the packet capture dump file.

  3. #3
    Join Date
    Sep 2005
    Posts
    1,476

  4. #4
    Join Date
    Apr 2008
    Posts
    3,424
    Quote Originally Posted by sumesh.tr View Post
    Plz point me how to trace virus traffic from Ethereal/Wireshark
    For some viruses/worms there might be a capture filter to recognize the virus traffic. Check the CaptureFilters page on the Wireshark Wiki to see if anybody's added such a filter.

    Note that Wireshark was not designed to be an intrusion detection system; you might be able to use it as an IDS, but in most cases software designed to be an IDS, such as Snort or Prelude, will probably work better.

    The Bleeding Edge of Snort has a collection of signatures for Snort to detect various viruses, worms, and the like.

Similar Threads

  1. Is there any alternative to wireshark?
    By silvery in forum Networking & Security
    Replies: 8
    Last Post: 02-10-2011, 07:42 PM
  2. How to use wireshark for analyzing protocols
    By Renau in forum Networking & Security
    Replies: 4
    Last Post: 05-04-2010, 11:32 AM
  3. Troubleshooting network with wireshark
    By Sandroo in forum Networking & Security
    Replies: 5
    Last Post: 09-03-2010, 12:21 PM
  4. How to monitor network with wireshark
    By Renau in forum Networking & Security
    Replies: 4
    Last Post: 10-02-2010, 09:02 AM
  5. How to Monitor traffic using Wireshark
    By ComPaCt in forum Networking & Security
    Replies: 3
    Last Post: 26-06-2009, 11:07 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,011,272.36704 seconds with 16 queries