Title: Packet Analysis Fluke Protocol Expert
1Packet AnalysisFluke Protocol Expert Misc
Applications
2Where to find your updates
3Promotions Page for CiscoNA
4Promotions Page for CiscoNA
5Beginning the Installation
6Readme File contains password
- Launching OPV-PE
-
- Login and Password
- -----------------------
- A valid, case sensitive, user name and password
is required to - launch OPV-PE software. The password for the
default - super user is shown below. The passwords for
these users should be - changed after the first launch of OPV-PE. To
change the default - password for these users, or create new users,
choose the menu - item HostgtAccess PrivilegesgtUser Manager,
highlight the first user - and click "Modify". Enter a new password for
the following - users.
- User Name su
- Password manager (hidden)
- User Name guest
- Password public (hidden)
7Initial Login Screen
8Capture and Monitoring Mode(Opening View)
9NIC Description
10Secondary NIC Description
11Hide Resource BrowserRename Network Adapters
12System Settings
13Module Settings
14Monitor View Preferences
15Expert Configuration
16Host Table
17Protocol Distribution
18MAC Statistics
19Size Distribution
20Name Table
21Remote vs. Local
22Expert View Symptoms Overview
23Expert View Symptoms Overview
24Expert View Transport Symptoms
25Expert View Network Symptoms
26Expert View Session Anaysis
27Expert View Transport Entities
28Host, Network, App Matrix
29Display Filter
30Capture Filter
31Stopping the Capture
32Capture View
33Buffer Limit with Education Version
34Viewing Captured Frames
35Viewing Captured Frames (Cont.)
36(No Transcript)
37(No Transcript)
38MAC Address Source Destination
39Change Capture View to Include Network Address
40Capture View with L3 Addressing
41Telnet Capture
42Username? Interesting
43Display Filter to Remove Clutter
44Username Capture
45Return of Keystroke by Switch
46Sending l keystroke
47Sending u keystroke
48Sending k keystroke
49Sending e keystroke
50Actual Terminal of User
51Password Prompt sent by Switch
52Passwords Are Not Echoed By Cisco Switch (1st
Char t)
532nd Char e
543rd Char S
554th Char t
565th Char P
576th Char a
587th Char s
598th Char s
609th Char !
61Switch Prompt is Displayed
62Capture of Show Run Output
63(No Transcript)
64Fluke Password in Config
65Http//www.astalavista.netAdvanced Security
Member Portal
66Advanced Security Member PortalTools Database
67Get Pass
68Hex Reveals Lowercase and Uppercase Difference
69Unload Display Filter
70Protocol Distribution for ACL Design
71ACL influenced byProtocol Distribution
- HOMEOFFICE831(config)ip access-list extended
TESTACL - HOMEOFFICE831(config-ext-nacl)permit tcp
192.168.111.0 0.0.0.255 any eq 119 - HOMEOFFICE831(config-ext-nacl)permit tcp
192.168.111.0 0.0.0.255 any eq 80 - HOMEOFFICE831(config-ext-nacl)permit tcp
192.168.111.0 0.0.0.255 any eq 3389 - HOMEOFFICE831(config-ext-nacl)permit tcp
192.168.111.0 0.0.0.255 any range 5631 5632 - HOMEOFFICE831(config-ext-nacl)permit udp
192.168.111.0 0.0.0.255 any range 5631 5632 - HOMEOFFICE831(config-ext-nacl)permit tcp
192.168.111.0 0.0.0.255 any eq 25 - HOMEOFFICE831(config-ext-nacl)permit tcp
192.168.111.0 0.0.0.255 any eq 110 - HOMEOFFICE831(config-ext-nacl)permit udp
192.168.111.0 0.0.0.255 any eq 53 - HOMEOFFICE831(config-ext-nacl)permit icmp any
any echo - HOMEOFFICE831(config-ext-nacl)permit icmp any
any echo- - HOMEOFFICE831(config-ext-nacl)permit icmp any
any echo-reply - HOMEOFFICE831(config-ext-nacl)permit icmp any
any echo-reply unrea - HOMEOFFICE831(config-ext-nacl)permit icmp any
any echo-reply unreachable
72Etherpeek User Capture
73Etherpeek Password Capture
74Etherpeek Filters
75(No Transcript)
76Ethereal
- To get up and running with Ethereal, you will
need to download and install Ethereal, and will
also need to download and install WinPcap if you
plan to capture packets with Ethereal. If you
don't install WinPcap, you will not be able to
capture packets with Ethereal!
77Ethereal Interface Capture
78Begin Capture (Ethereal)
79Capture Buffer (Ethereal)
80Filtering with Ethereal
81Ethereal Password Capture
82Follow TCP Stream
83Follow TCP Stream (Cont.)
84Questions?