Security Basics mailing list archives

Re: using promiscuous mode to tabulate network statistics


From: Chris Teodorski <chris.teodorski () gmail com>
Date: Tue, 25 Nov 2008 19:27:01 -0500

Terra Frost wrote:
I have four computers all plugged into a hub and I'd like to see which
one (well, which IP address) is sending / receiving the most data.  To
do this, I was thinking I could just install a package that would
tabulate such statistics using promiscuous mode.  Wireshark can sniff
packets via promiscuous mode but if it can be used in this manner, I'm
unsure of how.

I'm also not interested in real time statistics - I just want to know
how much data has been sent / received since the analysis program has
been running.

Any ideas?
Terra,

I'd look at ntop.

http://www.ntop.org/overview.html

Chris


Current thread: