View previous topic :: View next topic |
Author |
Message |
mitm n00b
data:image/s3,"s3://crabby-images/14c20/14c20699cdf7e07ed6ab9b097e628fa30cacbd62" alt="n00b n00b"
Joined: 23 Sep 2006 Posts: 1
|
Posted: Sat Sep 23, 2006 5:20 am Post subject: Gentoo network passthru packet logger? |
|
|
Hi all,
I have a client who is interested in logging all of the data that goes into and out of a small (<10 computers) LAN. They also don't want the traffic on the network when it's logged to be indistinguishable from the traffic on the network when it's unlogged. I have physical access to the site and carte blanche to do whatever is necessary to implement this logging.
The network is switched, so we can't just put a packet logger on a box with no IP address set in promiscuous mode. (Right?)
Instead, I was thinking that I would put a box between the gateway and the rest of the network. The box would have two NICs. Anytime one of the NICs received a packet, it would log that packet and write it out to the other NIC. (i.e. it woudln't decrement the TTL, it wouldn't change the source IP/MAC, etc.) It should do this for all protocols -- including arp, icmp, etc. -- so that the traffic for the logged network truly is indistinguishable from the traffic for the unlogged network. (So, essentially, it just copies data from each NIC to the other byte-for-byte, interpreting the data only enough so that it may be logged appropriately.) I have physical access, so I can just grab the logs off the comptuer and delete said logs by hand. The network is switched, so we don't need to worry too much about multiple copies of packets flying around.
Has anyone done something like this? Does anyone know of any tools to do this? I ran across ettercap, which can conduct man in the middle attacks. could this work? I want it to work at the byte level, so are we talking driver-level code here?
Thanks in advance! |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
badchien Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/0283b/0283b2c3f34a4c75e13b91a545d3bc4da329fe95" alt=""
Joined: 16 Feb 2004 Posts: 415 Location: doghouse
|
Posted: Sun Sep 24, 2006 8:05 am Post subject: Re: Gentoo network passthru packet logger? |
|
|
mitm wrote: | The network is switched, so we can't just put a packet logger on a box with no IP address set in promiscuous mode. (Right?) | Yes, but why not just plug in a hub between the LAN and the gateway and hook your logging box to the hub and sniff packets. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|