Penetration Testing mailing list archives

Re: [PEN-TEST] snoop ona live telnet session?


From: Mordechai Ovits <movits () OVITS NET>
Date: Wed, 29 Nov 2000 14:31:42 -0500

On Wed, Nov 29, 2000 at 11:20:12AM -0600, Dunker, Noah wrote:
I prefer Sniffit and hunt.

If you use Sniffit's -D <file> option, and make
the "file" a tty, then you can get a nice
full-screen view of the session in progress
on another virtual terminal or another telnet session.

sniffit -I -f eth0 -D /dev/tty6

will put a full-screen version of their stream on tty6

Sort of... It only shows the client side data, i.e what
the user typed.  Am I wrong?


hunt does all sorts of things, including session
HIJACKING, but that's probably more than you need.  It
has a decent live TCP stream follower though.
Sniffit's the better tool for this particular job, IMHO

-----Original Message-----
From: Mordechai Ovits [mailto:movits () OVITS NET]
Sent: Wednesday, November 29, 2000 10:43 AM
To: PEN-TEST () SECURITYFOCUS COM
Subject: snoop ona live telnet session?


Does anyone know of a tool that will allow me to snoop on a live telnet
session?  I'd like to be able to run this on a firewall to see sessions as
they pass through.  Sort of like what ethereal does with "follow TCP
Stream", but live.
Thanks!
Mordy



Current thread: