Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-15-2007, 06:20 AM
Five By Five
Guest
 
Posts: n/a
Default Monitoring Content of Connections


Is there an application that allows me to sniff or read-and-pass-along
content of users joining their wireless connections? I think there is a
virtual server system that might allow this, right? The router is a Belkin
DSL/Cable Wireless Router.

I am not interested in invading privacy (there is no assumption of it, as
the system warns the user), but in doing random checks to ensure that an
acceptable use policy is not being infringed.


There is probably a better newsgroup to post this in, but since the router
is wireless, I figure it qualifies.

Reply With Quote
  #2 (permalink)  
Old 08-15-2007, 10:17 PM
Mark McIntyre
Guest
 
Posts: n/a
Default Re: Monitoring Content of Connections

On Wed, 15 Aug 2007 05:20:08 GMT, in alt.internet.wireless , Five By
Five <5x5@5x5.com> wrote:

>
>Is there an application that allows me to sniff or read-and-pass-along
>content of users joining their wireless connections?


I believe Ethereal can do this. Interpreting the data is the hard
part.

>I think there is a
>virtual server system that might allow this, right?


I guess you could pass all traffic through a proxy that stored a copy
on disk and then allowed you to dissect it at your leisure. Thats
likely to be expensive tho.

>I am not interested in invading privacy (there is no assumption of it, as
>the system warns the user), but in doing random checks to ensure that an
>acceptable use policy is not being infringed.


You probably don't want to do this. As it stands, I think you can rely
on "common carrier" type laws to protect you from the actions of your
users. If you actively monitor and announce you do this, I strongly
suspect you will lose that protection.

>There is probably a better newsgroup to post this in,


One with security in the title?
--
Mark McIntyre

Reply With Quote
  #3 (permalink)  
Old 08-15-2007, 11:23 PM
Jeff Liebermann
Guest
 
Posts: n/a
Default Re: Monitoring Content of Connections

Five By Five <5x5@5x5.com> hath wroth:

>Is there an application that allows me to sniff or read-and-pass-along
>content of users joining their wireless connections?


Yes, there is. It's usually specific to the maker and model of the
router. Do you want URL's, services, socket numbers, protocols used,
traffic statistics, error, or the actual content? If you're
monitoring content, I don't want to get involved.

>I think there is a
>virtual server system that might allow this, right? The router is a Belkin
>DSL/Cable Wireless Router.


Does this Belkin have a model number? Duz is support either syslog or
SNMP? If not, you're stuck because you have a conglomerated
modem/router. You would normally do the sniffing at the junction
between the DSL modem and the ethernet router. However, since these
are all in one package, there's no access to this point. The only way
you're going to do any sniffing is if you replace BOTH the DSL modem
and the wireless router.

>I am not interested in invading privacy (there is no assumption of it, as
>the system warns the user), but in doing random checks to ensure that an
>acceptable use policy is not being infringed.


That's fine. Just realize that you're doing it anyway. I have my own
ethical formula for such things. I also sniff erratically to make
sure there's nothing amis on my networks. However, I don't save
anything other than traffic logs, and always inform the users that I'm
monitoring their connection either before or after. If you're setting
up a Carnivore clone, you most certainly are violating their
expectation of privacy.
<http://en.wikipedia.org/wiki/Carnivore_%28FBI%29>

Most acceptable use policies are NOT based on content. They're based
on services and traffic. For example, an ISP might decide that file
sharing is inappropriate or that daily traffic in excess of 30GBytes
is abuse. There are quite a few traffic monitors (MRTG, RRDTool,
Nagios, etc) that will give pretty graphs and belch alarms when some
form of pre-programmed abuse it triggered. They do that without
sniffing content. I think you'll find that random checks will not
suffice for excessive traffic problems (which includes worm and virus
infections). You'll need a dedicated and 7x24 continuous data logger
and management workstation.

>There is probably a better newsgroup to post this in, but since the router
>is wireless, I figure it qualifies.


Sniffing internet traffic has nothing to do with wireless. I don't
know which newsgroup or mailing list would be appropriate for
sniffing.

--
Jeff Liebermann jeffl@cruzio.com
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Verizon Wireless thumbs its nose at the iPhone Jeff alt.cellular.cingular 242 07-08-2007 08:32 PM
thinkpad access connections can no longer turn my wireless card on Chris F Clark alt.internet.wireless 1 02-17-2007 05:45 PM
Hotspot for 2 hundred people in one place filomaters alt.internet.wireless 10 01-20-2007 03:15 PM
More Brew nonsense Ange1o DePa1ma alt.cellular.verizon 2 10-01-2006 12:11 AM
SSL Proxy / How to forward HTTPS connections? fritz-bayer@web.de comp.security.misc 2 08-14-2005 04:35 AM


All times are GMT. The time now is 08:02 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45