Iyini i-Network Sniffer?

Bobabili abakwa-Admins and Hackers bangathatha i-Traffic Network

I-sniffer yenethiwekhi ifana nje nokuzwakala; ithuluzi lesofthiwe eliqapha, noma elisha idatha egeleza phezu kwezixhumanisi zenethiwekhi yekhompyutha ngesikhathi sangempela. Kungaba uhlelo lwe-software oluzimele noma idivaysi yehadiwe ne-software efanele noma i-firmware.

Abasebenzisi be-Network sniffers bangathatha amakhophi we-snapshot yedatha ngaphandle kokuyiqondisa kabusha noma ukuyishintsha. Abanye abasebenzisa i-sniffers basebenza kuphela ngamaphakethe we- TCP / IP , kodwa amathuluzi afinyeleleka angasebenza namanye ama- protocols amaningi nakumazinga aphansi, kufaka phakathi ama- Ethernet ozimele.

Eminyakeni edlule, abashayeli bezimoto babezisebenzisa kuphela ochwepheshe benethiwekhi. Namuhla, nanoma kunjalo, ngezicelo zesofthiwe zitholakalayo mahhala kuwebhu, zibuye zithandwa nabaduni be-intanethi futhi abantu bafuna ukwazi ukuxhumana kuphela.

Qaphela: Ngezinye izikhathi ama-sniffers enethiwekhi abizwa ngokuthi ama-probe wenethiwekhi, ama-wireless sniffers, ama-sniffers e-Ethernet, ama-packer-sniffers, abahlaziyi bepakethe, noma bamane beshaya.

Yimaphi ama-Packet Analyzers asetshenziselwa

Kunezinhlobonhlobo zezicelo zamaphutha we-packet kodwa eziningi zamathuluzi wokuhlola idatha azihlukanisi phakathi kwesizathu esizwakalayo nesizathu esingenabungozi, esivamile. Ngamanye amazwi, iningi lamaphutha wepakethe lingasetshenziswa ngokungalungile umuntu oyedwa kanye nezizathu ezifanele ngomunye.

Uhlelo olungathatha amaphasiwedi, isibonelo, lungasetshenziswa yi-hacker kodwa ithuluzi elifanayo lingase lisetshenziswe umlawuli wenethiwekhi ukuthola izibalo zenethiwekhi njengemikhawuntthi etholakalayo.

I-sniffer ingase ibe usizo nasekuhloleni umlilo noma izihlungi zewebhu, noma ukuxazulula ubudlelwane bamakhasimende / iseva.

Amathuluzi we-Network Sniffer

I-Wireshark (eyayaziwa ngokuthi i-Ethereal) iyabonakala kabanzi njenge-sniffer yenethiwekhi ethandwa kakhulu emhlabeni. Kuyinto isicelo samahhala, evulekile yomthombo obonisa idatha yesigcawu ngekhamera yemibala ukukhombisa ukuthi iyiphi inqubo yokusetshenziswa eyasetshenziselwa ukuyithumela.

Kumanethiwekhi e-Ethernet, isikhombikubona somsebenzisi sikhombisa ozimele ngabanye ohlwini olunezinombolo kanye namaphuzu avelele ngemibala ehlukene noma ithunyelwe nge- TCP , UDP , noma ezinye izivumelwano. Ibuye isize iqembu ndawonye imifudlana yomlayezo ithunyelwa emuva naphambili emkhatsini wemthombo nokuya (okuvamise ukuxubana phakathi kwesikhathi nokuhamba kwezinye izingxoxo).

I-Wireshark isekela i-traffic captures nge-interface yokuqala / stop stop push button. Ithuluzi liqukethe nezinketho ezihlukahlukene zokuhlunga ezikhawulela ukuthi iyiphi idatha eboniswayo futhi ifakwe ekuthineni - isici esibucayi kusukela ku-traffic kumanethiwekhi amanengi aqukethe izinhlobo eziningi zemilayezo yokulawula evamile ngokuvamile engeyona inzalo.

Izinhlelo eziningi zesofthiwe zokuhlola ezihlukahlukene zakhiwe ngokuhamba kweminyaka. Nazi izibonelo ezimbalwa nje:

Amanye alawa mathuluzi akhululekile ngenkathi abanye bebiza noma bangaba nesilingo samahhala. Futhi, ezinye zalezi zinhlelo azisekelwe noma zibuyekezwe kodwa zisatholakala ukulanda.

Izinkinga ezine-Network Sniffers

Amathuluzi we-Sniffer anikeza indlela enhle yokufunda ukuthi ama-protocols asebenza kanjani. Kodwa-ke, futhi banikeza ukufinyelela okulula kolunye ulwazi oluyimfihlo njengamaphasiwedi enethiwekhi. Hlola nabanikazi ukuthola imvume ngaphambi kokusebenzisa i-sniffer kwinethiwekhi yomunye umuntu.

I-probes yenethiwekhi ingangena kuphela idatha kusuka kumanethiwekhi ikhompyutha yabo yokubamba ifakwe kuyo. Eminye ukuxhumeka, abashayeli be-sniffers bawuthatha kuphela umgwaqo oqondiswe kuleyo nethiwekhi yokuxhumana. Ama-interfaces amaningi enethiwekhi ye-Ethernet asekela okuthiwa i- mode yokuziphatha okuvumela ukuthi i-sniffer ithathe yonke imoto edlula kulowo mxhumanisi wenethiwekhi (ngisho noma ingakhulumi ngqo kumphathi.)