Network Sniffing
Sniffing is capturing and analyzing the traffic flowing over the network. On a modern switched network you only see your own traffic by default, but combined with interception techniques (ARP spoofing, see ARP Spoofing/Man-in-the-Middle) or access to a strategic point (span port, compromised gateway), you capture others’ traffic. What you find: cleartext credentials, tokens, session cookies, authentication hashes, and all information that travels unencrypted.
What can be captured
Section titled “What can be captured”- Plaintext credentials: Telnet, FTP, HTTP, SMTP/POP3/IMAP without TLS.
- Authentication hashes: Net-NTLMv2 (Windows SMB/HTTP → see LLMNR / NBT-NS / mDNS Poisoning).
- Session cookies and tokens over unencrypted HTTP.
- Metadata: who talks to whom, which services are used, network structure.
- Even with TLS: SNI (which domains are visited), certificates, sizes/timings.
tcpdump -i eth0 -w capture.pcap # capture to file (lightweight, CLI)tcpdump -i eth0 'port 80 or port 21' # filter by portwireshark capture.pcap # deep graphical analysistshark -r capture.pcap -Y 'http.request' # wireshark in CLIngrep -d eth0 -q 'password' # search patterns in traffic# automatically extract credentialsnet-creds / PCredz -> extract credentials/hashes from a pcap or liveUseful Wireshark display filters
Section titled “Useful Wireshark display filters”http.request HTTP requestshttp.authorization authentication headersftp || telnet cleartext protocolsntlmssp NTLM authentication (hashes)tcp.port == 445 SMBip.addr == 10.0.0.5 by hostframe contains "password" by contentCapturing traffic that isn’t yours
Section titled “Capturing traffic that isn’t yours”On a switched network you need an interception point:
# promiscuous mode + active interception (see net-mitm)# ARP spoofing to get in the middle (see net-arp)# or access to: switch SPAN/mirror port, network tap, compromised gateway, WiFi# open/WEP WiFi: direct capture; WPA: you need the key/handshake (see wireless)Extract the loot from a pcap
Section titled “Extract the loot from a pcap”# credentials and hashesPCredz -f capture.pcap # cards, NTLM hashes, HTTP auth...# transferred fileswireshark -> File > Export Objects > HTTP/SMB/FTP# follow a full TCP streamwireshark -> Follow > TCP Stream# Net-NTLMv2 hashes -> crack (see fund-cripto)hashcat -m 5600 hashes.txt rockyou.txtFor the defense
Section titled “For the defense”Encrypt everything: HTTPS/TLS everywhere, SSH instead of Telnet, FTPS/SFTP, SNMPv3, VPN for sensitive traffic. On the network: disable legacy protocols, 802.1X and port security against unauthorized connections, promiscuous-mode and ARP-spoofing detection (arpwatch, dynamic ARP inspection), and segmentation to limit what traffic is reachable from a compromised point.
Testing checklist
Section titled “Testing checklist”- Capture traffic on your own segment (tcpdump/wireshark)
- Filter cleartext protocols (HTTP, FTP, Telnet, SMTP)
- Search for credentials/cookies/tokens in traffic
- Extract Net-NTLMv2 hashes (ntlmssp) and crack them
- Export transferred files from the pcap
- Follow full TCP streams to reconstruct sessions
- Combine with ARP spoofing for others’ traffic (ARP Spoofing)
- Automate extraction with PCredz/net-creds