BUGTRAQ PRODUCTS NEWS AWARDS
MSN Protocol Analyzer
SwitchSniffer
MACMask
Windows ARP Spoofer
Download Free Software:
Freeware & Shareware for
Computer Utilities Programs
www.softahead.com

SwitchSniffer

MSN Protocol Analyzer SwitchSniffer MACMask Windows ARP Spoofer
[SwitchSniffer DOWNLOAD]

1. Overview

SwitchSniffer is a program that can scan your switched LAN for up hosts and can reroute and collect all packets without the target users' recognition. It can also detect the ¡®arpspoofer¡¯ program running on the network and block user definable sessions like firewall. If you use this program in tandem with any sniffer program, you can capture and see the users¡¯ IDs and passwords on a switched network.

That is, SwitchSniffer enables you to monitor all the packets and all the hosts on a switch network.



SwitchSniffer has the following features:
SwitchSniffer can poll and collect all the packets on the switched LAN.
SwitchSniffer can scan and display the active hosts on the LAN quickly, and automatically.
While spoofing ARP tables, SwitchSniffer can act as another gateway (or ip-forwarder) without other users' recognition on the LAN.
It can collect and forward packets by selecting inbound, outbound, and both to be sent to the Internet.
An ARP table is recovered automatically in about 30 seconds. But, SwitchSniffer can keep spoofing continuously by updating the target computer¡¯s ARP table more frequently.
If one or more network interface cards are installed on a computer, you can choose which NIC you would like SwitchSniffer to scan and spoof through.
SwitchSniffer can display information about the amount of data transferred to and from the internet.
SwitchSniffer can detect if any computer on the LAN is running an ¡®arpspoofer¡¯ program.
SwitchSniffer can filter: sessions, local hosts, and remote hosts.
The installation of the ¡®winpcap¡¯ driver is not necessary for SwitchSniffer.
SwitchSniffer can manage the local hosts based on MAC Address.
SwitchSniffer can act as a plug-and-played router.
SwitchSniffer can export the data of view into an excel file.

SwitchSniffer has the following benefits:
SwitchSniffer can find the hidden hosts on the LAN, which is not found by IP-Scanners.
SwitchSniffer can find if abnormal hosts are connected to your wireless network.
SwitchSniffer protects your network from abnormal users.
SwitchSniffer can check if there are abnormal packets on the LAN.
SwitchSniffer allows you to capture user IDs, passwords, chat sessions and web sessions etc., on the switched network through the use of a sniffer application.
SwitchSniffer can block the local hosts based on MAC Address.
SwitchSniffer can resolve the problem of IP Collision.
SwitchSniffer can find out the country name by ip address on remote.
SwitchSniffer enables you to monitor all the packets on a switch network.

2. System Requirement

Local : Windows nt4/2000/xp/2003, 25MB free main memory, Network adapter which supports promiscuous mode.
Remote : All computers including network devices must support Ethernet

Local Host Info Screen.


Remote Host Info Screen.


Sessions Info Screen.


Definitions Screen.


Options Screen.


3. What's New

MAC Based Blocking.
Converting the ip address into the country name.
Export the view data into an excel file
Coloring each row items.
Employing the speed bars.
Finding out the collision of ip addresses.

4. Getting Started

1) Install this program (SwitchSniffer).
2) Select Start->Programs->SwitchSniffer->SwitchSniffer.
3) Click ¡°Scan¡± button to poll which hosts are up on the local network.
4) Select the target hosts on left window, Local View, if you capture the packets from these target hosts you should ensure ¡°Act as a router¡¦¡± on Options->Spoof page is checked.

5. Known Issues

1) SwitchSniffer must be run with the administrator privileges. If not,
the program will work abnormally.

2) SwitchSniffer does not spoof communication on local network (intranet
communication), only Internet communication.

3) While spoofing, if you unplug the ethernet cable or reboot the system,
then your network is able to die for a while.

4) If you find that the network function of target computer dies:

- First, delete \windows\system32\drivers\nspacket.sys and restart
the system

- Second, ensure that a pcap device driver other than winpcap (npf.sys)
for sniffing is not installed on your system.

For example windis. If an additional driver exists, uninstall it while
using SwitchSniffer.

- Third, if your system is Windows 2003 Server or Windows 2000 Server,
and the system runs a routing service (such as RRAS) then in Options
->Spoof of SwitchSniffer, uncheck "Act as a router while spoofing."

- Fourth, switch the ¡°Act as a Router (or Gateway) while spoofing.¡±
option to "With System router" Options->Spoof-> select "With System
Router" if you¡¯re using ¡°With Internal Router.¡±

- Finally, if none of the above solutions fix your problem, please send
us bug report and the problem will be investigated further.

6. Tools and Programs working with SwitchSniffer

Please contact us at support [at] nextsecurity.net to add new tools to this list.

MSN Prototocol Analyzer - Monitoring all the session of MSN Protocol including MSN commands and conversations.

Astral II - the packet capturing software

7. Revision History

= bug fixed
+ improvement/modification

[Start of Versions History]

Version 1.5.1 (Oct. 10, 2007)
--------------------------------
=. Shareware again
+. Total 10785 mac addresses are added.
+. To open remote computer in RemoteHost Info view tab.
=. Some bugs are fixed.

Version 1.4 (Oct. 3, 2006)
--------------------------------
+. Freeware

Version 1.3.2 (May. 5, 2006)
--------------------------------
= Total 9214 mac addresses are added.

Version 1.3.0 (May. 5, 2006)
--------------------------------
= The problems of registration has been fixed.
= Somebugs are fixed.

Version 1.1.0 (Feb. 9, 2006)
--------------------------------
+. Curing arp-cache poisoning
+. Adding "add button" on Filter-rule definitions.
=. Fixed InitInstance exception error.

Version 1.0.12 (Jan. 9, 2006)
--------------------------------
= Fixed the bug that the windows state of Definition wasnt saved.
= Removed the stalling problem when opening the local hosts.
= Strengthened the copy-protection mechanism.

Version 1.0.9 (Jan. 2, 2006)
--------------------------------
= Fixed the bug that progress bar is disappeared.
= Modified the update message.
= Fixed sorting bug in MacBased-Action page of Definitions.
= If unregistered, display "Register Dialog".

Version 1.0.5 (Dec. 30, 2005)
--------------------------------
= Fixed the bug that Exit menu is malfunctioned.
= Fixed the exception bug of Properth button on MacBased Action.
= Saving the state of Definitions Windows
= If unregistered, unchecking the check box button of detecting arp-spoofer.
= Modified App version in About box.

Version 1.0 (Dec. 26, 2005)
--------------------------------
+ MAC Based Blocking.
+ Converting the ip address into the country name.
+ Export the view data into an excel file
+ Coloring each row items.
+ Employing the speed bars. + Finding out the collision of ip addresses.

Version 0.8.4b (Nov. 28, 2005)
--------------------------------
= Fixed compile error of filtering string in Filtering feature.
= Corrected incorrect words or statement in Options.
= Removed "Block .... " in Option > Spoof.

Version 0.8.3b (Nov. 23, 2005)
--------------------------------
= Fixed the bugs related to Filtering feature.
= Fixed 2 exceptions reported by Maher.

Version 0.8.2b (Nov. 16, 2005)
--------------------------------
= Fixed the bug that filtering feature doesn't work.
= Fixed the bug that Rules don't be saved in Filtering feature.
= Modified the unit of size on session info. tab and remote host info tab.

Version 0.8.1b (Nov. 08, 2005)
--------------------------------
= To make the size of the big main window and the state of the toolbar buttons to be saved.
= Added the unit (B) in the recv and sent size and in recv and sent speed and added space between the number and the unit.
= Corrected the speed sorting according to the unit.

Version 0.8.0b (Nov. 04, 2005)
--------------------------------
+ Added two more columns in the Local Hosts Info. tab to show the up and down speed of every host and at the bottom in the status bar show the total up and down speed(and size).
+ The states of the view and dimensions of windows are saved.
+ Added a check box "Show the options window at start up " in Options->General page.
+ Added a check box "Auto scan at start up" and under it "Auto start spoofing at start up ".
+ Added a check box "Auto startup at Windows startup"
+ Added a Context menu (including a clear view) to the output.
+ In setting -> definitions -> sevices and also in filter rules you can remove multi choices at once.
= Fixed the bug that the sent size remains 0 in Local Hosts Info. tab.
= Fixed the bug that it doesn't work in win2000 system.
= Addionally, some bugs are fixed.

Version 0.7.8b (Oct. 21, 2005)
--------------------------------
=. Fixed an exception error when a host up.
I think that this is the last error in the engine part of SwitchSniffer.

Version 0.7.7b (Oct. 20, 2005)
--------------------------------
+. Added the feature of stopwatch.
=. Changed the Output View with color.
=. Fixed the bug of wrong matched count.
=. Fixed a bug "Always check when a host is up".

Version 0.7.4b (Oct. 13, 2005)
--------------------------------
+ Added "Detect and Alert" tab to detect and alert the abnormal packets(ex. arpspoof).
+ Added the system router which computer has.
= Upgraded the feature of autoscan.
= Upgraded the notice feature of trayicon.

Version 0.7.0b (Oct. 7, 2005)
--------------------------------
= User Interface is modified.
= fixed the bug that the hosting computer running switchsniffer dies.
= some bugs are fixed additionally.

Version 0.6.11b (Sep. 30, 2005)
--------------------------------
+ Added Verbose mode in Autoscan feature.
= Fixed some critical bugs.

Version 0.6.9b (Sep. 26, 2005)
--------------------------------
= Fixed an installation bug in Windows2003 and some other bugs.
+ modified the feature of live update.

Version 0.6.7b (Sep. 26, 2005)
--------------------------------
+ Added a file http://www.graffiti.com/services to the package.
= modified traymenus and No Taskbar icon.
= fixed some bugs in Services including memory leaks.
= fixed a GUI bug in TabControlbar.

Version 0.6.3b (Sep. 24, 2005)
--------------------------------
= Sort problem in listviews.
+ Added 500 MAC Address Vendor Codes.
+ To trayIconize

Version 0.6 (Sep. 20, 2005)
--------------------------------
Version 0.6 is published.

[End of Versions History]

Copyright(c) 2003-2007 NextSecurity.net All Rights Reserved.
NextSecurity.net is a newly coming-up site for your requirement related to Computer and Network Security
BUGTRAQ | MSN Protocol Analyzer | SwitchSniffer | MACMask | Windows ARP Spoofer | Sitemap | Link to us