Ethical Hacking: Sniffers (2016)
1h 27mBeginner2021-05-25
Authors

Lisa Bock
Security ambassador with a broad range of IT skills and knowledge
Course details
Ethical hackers: Get an inside look into the tools the black hat hackers use to "sniff" network traffic, and discover how to countermeasure such attacks. Security ambassador Lisa Bock explains what a sniffer is, and how hackers use it to intercept network traffic. She reviews the seven-layer OSI model, active vs. passive attacks, and the different types of protocol attacks, including MAC and macof attacks, DNS caching and forgery, DHCP denial-of-service attacks, and ARP cache poisoning. Learn how ethical hackers have an arsenal of tools to emulate these attacks and techniques, from examining headers and URLs to capturing images. Lisa relies on Wireshark, a network protocol analyzer for Unix and Windows, but also introduces other sniffing tools, including TShark, tcpdump, and CloudShark.
Topics include:
Sniffing network traffic
Passive vs. active attacks
Comparing IPv4 to IPv6
MAC and macof attacks
Investigating DHCP attacks
Detecting ARP and DNS spoofing
Sniffing tools and techniques
Topics include:
Sniffing network traffic
Passive vs. active attacks
Comparing IPv4 to IPv6
MAC and macof attacks
Investigating DHCP attacks
Detecting ARP and DNS spoofing
Sniffing tools and techniques
Skills covered
Security TestingLinuxCybersecurityCert PrepOpen Source
Concepts
0. Introduction
- 01 - Visualizing network traffic
- 02 - What you should know
- 03 - Hacking ethically
1. Sniffing Overview
- 04 - Sniffing network traffic
- 05 - The OSI model
- 06 - Passive and active attacks
- 07 - Tapping into the data stream
- 08 - Comparing IPv4 to IPv6
- 09 - Challenge - Compare IPv4 to IPv6
- 10 - Solution - Compare IPv4 to IPv6
2. MAC Attacks
- 11 - macof attack demo
- 12 - Yersinia for exploiting protocols
- 13 - Spoofing a MAC address
- 14 - Defending against MAC attacks
3. DHCP
- 15 - Investigating DHCP
- 16 - Depleting the DHCP pool
- 17 - Deploying a rogue DHCP server
- 18 - Defending against DHCP attacks
4. ARP
- 19 - Address Resolution Protocol
- 20 - Ettercap for ARP poison
- 21 - Detecting ARP spoofing
- 22 - Defending against ARP attacks
5. DNS
- 23 - Domain Name Systems
- 24 - Caching and forgery
- 25 - Poisoning DNS
- 26 - Defending against DNS spoofing
- 27 - Challenge - Investigate a DNS header
- 28 - Solution - Investigate a DNS header
6. Sniffing Tools and Techniques
- 29 - Capturing images
- 30 - Examining HTTP headers and URLs
- 31 - Sniffing with TShark and Wireshark
- 32 - Packet sniffing tools for mobile devices
- 33 - Investigating OmniPeek
- 34 - Other sniffing tools
- 35 - Defending against sniffing
Conclusion
- 36 - Next steps