Presentation is loading. Please wait.

Presentation is loading. Please wait.

Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Similar presentations


Presentation on theme: "Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck."— Presentation transcript:

1 Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck

2 Where to find your updates

3 Promotions Page for CiscoNA

4

5 Beginning the Installation

6 Readme File contains password Launching OPV-PE ====================== Login and Password ----------------------- A valid, case sensitive, user name and password is required to launch OPV-PE software. The password for the default super user is shown below. The passwords for these users should be changed after the first launch of OPV-PE. To change the default password for these users, or create new users, choose the menu item Host>Access Privileges>User Manager, highlight the first user and click "Modify". Enter a new password for the following users. User Name: su Password : manager (hidden) User Name: guest Password : public (hidden) **Note:A checkbox is provided to select a default User Name (not password) for easier Login.

7 Initial Login Screen

8 Capture and Monitoring Mode (Opening View)

9 NIC Description

10 Secondary NIC Description

11 Hide Resource Browser Rename Network Adapters

12 System Settings

13 Module Settings

14 Monitor View Preferences

15 Expert Configuration

16 Host Table

17 Protocol Distribution

18 MAC Statistics

19 Size Distribution

20 Name Table

21 Remote vs. Local

22 Expert View – Symptoms Overview

23

24 Expert View – Transport Symptoms

25 Expert View – Network Symptoms

26 Expert View – Session Anaysis

27 Expert View – Transport Entities

28 Host, Network, App Matrix

29 Display Filter

30 Capture Filter

31 Stopping the Capture

32 Capture View

33 Buffer Limit with Education Version

34 Viewing Captured Frames

35 Viewing Captured Frames (Cont.)

36

37

38 MAC Address – Source & Destination

39 Change Capture View to Include Network Address

40 Capture View with L3 Addressing

41 Telnet Capture

42 Username? Interesting…

43 Display Filter to Remove Clutter

44 Username Capture

45 Return of Keystroke by Switch

46 Sending ‘l’ keystroke

47 Sending ‘u’ keystroke

48 Sending ‘k’ keystroke

49 Sending ‘e’ keystroke

50 Actual Terminal of User

51 Password Prompt sent by Switch

52 Passwords Are Not Echoed By Cisco Switch (1 st Char = ‘t’)

53 2 nd Char = ‘e’

54 3 rd Char = ‘S’

55 4 th Char = ‘t’

56 5 th Char = ‘P’

57 6 th Char = ‘a’

58 7 th Char = ‘s’

59 8 th Char = ‘s’

60 9 th Char = ‘!’

61 Switch Prompt is Displayed

62 Capture of Show Run Output

63

64 Fluke Password in Config

65 Http://www.astalavista.net Http://www.astalavista.net Advanced Security Member Portal

66 Advanced Security Member Portal Tools Database

67 Get Pass

68 Hex Reveals Lowercase and Uppercase Difference

69 Unload Display Filter

70 Protocol Distribution for ACL Design

71 ACL influenced by Protocol Distribution HOMEOFFICE831(config)#ip access-list extended TESTACL HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 119 HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 80 HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 3389 HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any range 5631 5632 HOMEOFFICE831(config-ext-nacl)#permit udp 192.168.111.0 0.0.0.255 any range 5631 5632 HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 25 HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 110 HOMEOFFICE831(config-ext-nacl)#permit udp 192.168.111.0 0.0.0.255 any eq 53 HOMEOFFICE831(config-ext-nacl)#permit icmp any any echo HOMEOFFICE831(config-ext-nacl)#permit icmp any any echo- HOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-reply HOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-reply unrea HOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-reply unreachable

72 Etherpeek User Capture

73 Etherpeek Password Capture

74 Etherpeek Filters

75

76 Ethereal To get up and running with Ethereal, you will need to download and install Ethereal, and will also need to download and install WinPcap if you plan to capture packets with Ethereal. If you don't install WinPcap, you will not be able to capture packets with Ethereal!

77 Ethereal Interface Capture

78 Begin Capture (Ethereal)

79 Capture Buffer (Ethereal)

80 Filtering with Ethereal

81 Ethereal Password Capture

82 Follow TCP Stream

83 Follow TCP Stream (Cont.)

84 Questions?


Download ppt "Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck."

Similar presentations


Ads by Google