Skip to content

Network Sniffing

Sniffing is capturing and analyzing the traffic flowing over the network. On a modern switched network you only see your own traffic by default, but combined with interception techniques (ARP spoofing, see ARP Spoofing/Man-in-the-Middle) or access to a strategic point (span port, compromised gateway), you capture others’ traffic. What you find: cleartext credentials, tokens, session cookies, authentication hashes, and all information that travels unencrypted.

  • Plaintext credentials: Telnet, FTP, HTTP, SMTP/POP3/IMAP without TLS.
  • Authentication hashes: Net-NTLMv2 (Windows SMB/HTTP → see LLMNR / NBT-NS / mDNS Poisoning).
  • Session cookies and tokens over unencrypted HTTP.
  • Metadata: who talks to whom, which services are used, network structure.
  • Even with TLS: SNI (which domains are visited), certificates, sizes/timings.
tcpdump -i eth0 -w capture.pcap # capture to file (lightweight, CLI)
tcpdump -i eth0 'port 80 or port 21' # filter by port
wireshark capture.pcap # deep graphical analysis
tshark -r capture.pcap -Y 'http.request' # wireshark in CLI
ngrep -d eth0 -q 'password' # search patterns in traffic
# automatically extract credentials
net-creds / PCredz -> extract credentials/hashes from a pcap or live
http.request HTTP requests
http.authorization authentication headers
ftp || telnet cleartext protocols
ntlmssp NTLM authentication (hashes)
tcp.port == 445 SMB
ip.addr == 10.0.0.5 by host
frame contains "password" by content

On a switched network you need an interception point:

# promiscuous mode + active interception (see net-mitm)
# ARP spoofing to get in the middle (see net-arp)
# or access to: switch SPAN/mirror port, network tap, compromised gateway, WiFi
# open/WEP WiFi: direct capture; WPA: you need the key/handshake (see wireless)
# credentials and hashes
PCredz -f capture.pcap # cards, NTLM hashes, HTTP auth...
# transferred files
wireshark -> File > Export Objects > HTTP/SMB/FTP
# follow a full TCP stream
wireshark -> Follow > TCP Stream
# Net-NTLMv2 hashes -> crack (see fund-cripto)
hashcat -m 5600 hashes.txt rockyou.txt

Encrypt everything: HTTPS/TLS everywhere, SSH instead of Telnet, FTPS/SFTP, SNMPv3, VPN for sensitive traffic. On the network: disable legacy protocols, 802.1X and port security against unauthorized connections, promiscuous-mode and ARP-spoofing detection (arpwatch, dynamic ARP inspection), and segmentation to limit what traffic is reachable from a compromised point.

  • Capture traffic on your own segment (tcpdump/wireshark)
  • Filter cleartext protocols (HTTP, FTP, Telnet, SMTP)
  • Search for credentials/cookies/tokens in traffic
  • Extract Net-NTLMv2 hashes (ntlmssp) and crack them
  • Export transferred files from the pcap
  • Follow full TCP streams to reconstruct sessions
  • Combine with ARP spoofing for others’ traffic (ARP Spoofing)
  • Automate extraction with PCredz/net-creds