24. Traffic Sniffing and Analysis
Chala mitrano, aaj network cha "CCTV" shikuya – sniffing. Network var je packets jatat te vachta ale, tar khup kahi kalte: kon konashi bolto, konti service vaparli jate, ani – dhokyachi goshta – plain text madhla password suddha disto! Aapan Wireshark ani tcpdump ne he baghu, ani mag sarvat mahatvacha dhada gheu: mhanunach HTTPS garjeche aahe (Chapter 13 madhe aapan Certbot ne HTTPS lavla hota, aata ka te kalel). Sagle capture fakt tumchya swatahchya lab network var. Samjla ka? Chala suru!
What you will learn in this chapter
- What sniffing is, and why switches limit it (and ARP spoofing gets around it)
- tcpdump: capturing packets from the command line
- Wireshark: capturing and reading traffic in a GUI
- Display filters and following a TCP stream
- Seeing why HTTP leaks passwords and HTTPS does not
- ARP spoofing / man-in-the-middle in concept, and how to detect and prevent it
Lab scope for this whole chapter
Capture traffic only on your own lab network and machines. Sniffing someone else's traffic, or ARP-spoofing a network you do not own, is interception under the IT Act (sections 43 and 66) and a serious offence. Keep everything on the host-only lab.
Concepts in this chapter
- 24.1What Sniffing Is
- 24.2tcpdump: Command-Line Capture
- 24.3Wireshark: Reading Traffic in a GUI
- 24.4Display Filters and Following a Stream
- 24.5Why HTTP Leaks and HTTPS Protects; ARP Spoofing
- 24.6Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.