Penetration Testing mailing list archives

Re: [PEN-TEST] Protocol Sniffer on PPP interface


From: Dragos Ruiu <dr () KYX NET>
Date: Tue, 10 Oct 2000 20:21:41 -0700

The i960 there is a front end processor to do offload packet
filtering from the main CPU.  Most HW sniffers use this architecture...

The connectors are likely generic V.35 interfaces or such for
Frame Relay, X.25 and other HDLC based systems.... The distributed
sniffer postdates X.25 by a few years... It was released when
Frame Relay was just coming into vogue...

You may be able to find some old documentation on it at the NAI
site, or you may be able to find some stuff looking for the older
Network General brand name in the search engines..

cheers,
--dr

On Tue, 10 Oct 2000, Wolfgang Zenker wrote:
Hi,

Dunker, Noah wrote:
Just a quick question... I bought a Network General Distributed
Sniffer Server from an auction... It had all sorts of network
ports on it... 2 NICs with 100BaseTX and Coax, and a bizarre card
(that had it's own intel i960 proc on-board) with 2 d-sub
connectors... 25 Pin Female and 15 pin Female)... Might this be
a mysterious WAN card for sniffing PPP with the Distributed
Sniffer Server?

sounds like a X.21 (15 pin) and X.21bis (25 pin) port to me, probably
to sniff on X.25 connections.

--
Dragos Ruiu <dr () dursec com>   dursec.com ltd. / kyx.net - we're from the future
gpg/pgp key on file at wwwkeys.pgp.net


Current thread: