Wireshark-dev: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 releaseandrequestfor feedbac
From: "Sake Blok" <sake@xxxxxxxxxx>
Date: Mon, 27 Apr 2009 22:14:03 +0200
| Hi Sebastien, Unfortunately SniffJoke does a lot more (sending 
RST with bogus seq numbers, sending SYN/FIN/RST frames, etc, I have not looked 
at all the frames yet). It would take quite some effort and code to analyse the 
frames and consider the context to disregard them when doing a "follow TCP 
stream". Even if we succeed in doing so, the sole purpose of SniffJoke is to be 
evasive, so they will definitely come up with new tricks and we end up in a 
battle writing code.  Then think of the gain for wireshark users? If they 
are running SniffJoke themselves? Well then they know what data they did send, 
so no use in trying to extract it for them. If they sniffed the packets in 
between source and destination, let's keep the SniffJoke purpose intact and let 
the user have some form of privacy, people in between networks have no use 
looking into the payload IMHO, so lets not give them extra tools to do so 
;-) Of course  and experienced WS user will be able to extract the 
data anyhow, just not easily. And if the WS user 
is at the server end analysing a problem of some client that is using SniffJoke, 
they see al the bogus traffic coming from the client and will tell them to clean 
up their act. So who is to benefit from code that tries to reassemble the 
SniffJoke traffic? Apart from the nice exercise to do so of 
course ;-)  But time is limited and there are more important things to 
be fixed! Regarding the Expert Info, since there are packets 
with all kinds of TTL's and it would take a broader look at all frames to 
discover the right TTL, I would say it would be a bit tricky to create such an 
expert info item. Also, filtering on TTL alone won't do it, as you would need to 
save these frames to a new file first, otherise the bogus frames will still be 
used for reassembly. Cheers,      Sake 
 | 
- Follow-Ups:
- References:
- [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and request	for feedback	(forw)
- From: Joerg Mayer
 
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and	requestfor feedback	(forw)
- From: Sake Blok
 
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and	requestfor feedback (forw)
- From: Sébastien Tandel
 
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release	andrequestfor feedback (forw)
- From: Sake Blok
 
- Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release	andrequestfor feedback (forw)
- From: Sébastien Tandel
 
 
- [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release and request	for feedback	(forw)
- Prev by Date: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release andrequestfor feedback (forw)
- Next by Date: [Wireshark-dev] IEC dissectors
- Previous by thread: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 release andrequestfor feedback (forw)
- Next by thread: Re: [Wireshark-dev] [Full-disclosure] SniffJoke 0.3 releaseandrequestfor feedback (forw)
- Index(es):