Penetration Testing mailing list archives

RE: sniffing X traffic.


From: Joshua Wright <Joshua.Wright () jwu edu>
Date: Mon, 13 Aug 2001 08:30:56 -0400

You should be looking at dsniff by Dug Song
(http://www.monkey.org/~dugsong/).

Included is an X11 decoder to display clear-text passwords.  You can
probably modify this to fit your needs.

-Joshua Wright
Joshua.Wright () jwu edu 


-----Original Message-----
From: Power Steve [mailto:steve.power () barclaycard co uk]
Sent: Friday, August 10, 2001 10:45 AM
To: 'PEN-TEST () securityfocus com'
Subject: sniffing X traffic.


Hey all

long time listener, first time caller.

Anyone know if you can meaningfully sniff Exceed ( I guess it's the same as
X) traffic?  Im being a bit lame, my personal test lab is down atm, and I
cant find anything on the net re sniffing and interpreting X traffic.

If anyone would be so kind as to answer a specific question, could I see
passwords etc in the traffic?

thanks in advance.

Steve Power
Security Consultant




Legal Disclaimer:-

Please be aware that messages sent over
the Internet may not be secure and should
not be seen as forming a legally binding
contract unless otherwise stated.


----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: