Wireshark-dev: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 releaseandrequestfor feedbac
From: "Sake Blok" <sake@xxxxxxxxxx>
Date: Mon, 27 Apr 2009 22:14:03 +0200
Hi Sebastien,
Unfortunately SniffJoke does a lot more (sending
RST with bogus seq numbers, sending SYN/FIN/RST frames, etc, I have not looked
at all the frames yet). It would take quite some effort and code to analyse the
frames and consider the context to disregard them when doing a "follow TCP
stream". Even if we succeed in doing so, the sole purpose of SniffJoke is to be
evasive, so they will definitely come up with new tricks and we end up in a
battle writing code.
Then think of the gain for wireshark users? If they
are running SniffJoke themselves? Well then they know what data they did send,
so no use in trying to extract it for them. If they sniffed the packets in
between source and destination, let's keep the SniffJoke purpose intact and let
the user have some form of privacy, people in between networks have no use
looking into the payload IMHO, so lets not give them extra tools to do so
;-) Of course and experienced WS user will be able to extract the
data anyhow, just not easily. And if the WS user
is at the server end analysing a problem of some client that is using SniffJoke,
they see al the bogus traffic coming from the client and will tell them to clean
up their act. So who is to benefit from code that tries to reassemble the
SniffJoke traffic? Apart from the nice exercise to do so of
course ;-) But time is limited and there are more important things to
be fixed!
Regarding the Expert Info, since there are packets
with all kinds of TTL's and it would take a broader look at all frames to
discover the right TTL, I would say it would be a bit tricky to create such an
expert info item. Also, filtering on TTL alone won't do it, as you would need to
save these frames to a new file first, otherise the bogus frames will still be
used for reassembly.
Cheers,
Sake
|
- Follow-Ups:
- References:
- [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and request for feedback (forw)
- From: Joerg Mayer
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and requestfor feedback (forw)
- From: Sake Blok
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and requestfor feedback (forw)
- From: Sébastien Tandel
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release andrequestfor feedback (forw)
- From: Sake Blok
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release andrequestfor feedback (forw)
- From: Sébastien Tandel
- [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and request for feedback (forw)
- Prev by Date: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release andrequestfor feedback (forw)
- Next by Date: [Wireshark-dev] IEC dissectors
- Previous by thread: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release andrequestfor feedback (forw)
- Next by thread: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 releaseandrequestfor feedback (forw)
- Index(es):