EMZETT.
Login

Sniffer

In short: A tool that reads and records traffic on a network — e.g. Wireshark. Can be used both for legitimate diagnostics and for attacks.

In more detail: A sniffer puts the network card into “promiscuous mode”, where it processes not only packets addressed to it but records all visible traffic. On a switched network, a sniffer normally only sees its own traffic — attackers therefore often combine sniffing with ARP spoofing to redirect other people’s traffic through their own machine. Legitimate uses: network troubleshooting, protocol analysis, security audits.

In Depth

Whether a sniffer can see other people’s traffic at all depends heavily on the network topology:

Old hub-based network:     hub sends every packet to ALL ports -> sniffing
                            other traffic is trivial, no extra trick needed.

Modern switched network:   switch sends packets only specifically to the
                            destination port -> by default the sniffer
                            only sees its own traffic, needs an extra
                            trick (e.g. ARP spoofing, "port mirroring"
                            on the switch) to see more.

For legitimate network diagnostics, professional switches therefore often have a dedicated “mirror port” or “SPAN port” that deliberately sends a copy of all traffic to an analysis machine — without this explicit configuration (or physical access to a hub instead of a switch), a sniffer on a modern network by itself only sees what’s actually addressed to its own network card.

For unencrypted traffic (e.g. old HTTP instead of HTTPS, unencrypted Wi-Fi), a sniffer can read passwords and content in plain text — a main reason why practically the entire modern web has switched to HTTPS/TLS. With encrypted traffic, a sniffer still sees metadata (which IP is talking to which IP, how much data, when), but not the content itself — this distinction between “metadata visible” and “content protected” is an important point when assessing how much protection encryption actually provides.

Sniffer as a diagnostic tool

For IT administrators, a sniffer is one of the most important troubleshooting tools: when an application “just doesn’t work” and logs alone don’t give an answer, a look at the actual network traffic often reveals the problem immediately — for example a DNS server that doesn’t respond, a TLS handshake that fails with the wrong certificate, or a firewall rule that silently drops packets. Wireshark is by far the most widely used graphical tool, tcpdump the corresponding command-line counterpart for servers without a graphical interface:

# Record all traffic on a network interface
tcpdump -i eth0
 
# Only traffic to/from a specific IP address, save to a file
tcpdump -i eth0 host 192.168.1.10 -w capture.pcap

The resulting .pcap file can then be loaded into Wireshark to analyse the traffic packet by packet with full protocol decoding — including reconstructing entire TCP connections (“follow TCP stream”), which is very helpful when troubleshooting complex client-server interactions.

Recording network traffic on a network you don’t have explicit authorisation for is a criminal offence in most jurisdictions (unauthorised interception of data) — using a sniffer on your own home network or with the explicit permission of the network operator (e.g. as part of a penetration test with a written engagement) is unproblematic, secretly recording other people’s traffic is not.

See also: Wireshark, Spoofing