Working packet sniffers menu

User Tag List

Results 1 to 11 of 11
  1. #1
    BoogieManTM's Avatar Active Member
    Reputation
    52
    Join Date
    May 2008
    Posts
    193
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Working packet sniffers

    Are there any out there that still work?

    I mean specifically one that does the following:

    A) Decrypts packets from both directions
    B) dumps the packets prior to encryption/after decryption

    Wireshark doesn't cut it for these two, without manually pulling the session key down and doing it yourself.

    Working packet sniffers
  2. #2
    lanman92's Avatar Active Member
    Reputation
    50
    Join Date
    Mar 2007
    Posts
    1,033
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Didn't they change the encryption so that you couldn't find the key through sniffing now? You used to be able to do it quite simply, and it would be caught by the time you logged in. Something to do with the 'size' field in the packet and brute forcing it through that if I'm not mistaken. You probably know this though...

  3. #3
    BoogieManTM's Avatar Active Member
    Reputation
    52
    Join Date
    May 2008
    Posts
    193
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yes, it was pretty easy to passively sniff packets. It used to be simple XOR on the headers with a 40 byte key, now it's RC4. I guess i'll just write something to decrypt a pcap dump (just need to pull the key from memory every session)

  4. #4
    SinnerG's Avatar Member
    Reputation
    6
    Join Date
    Aug 2006
    Posts
    78
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    TOM_RUS has something like that, but I forgot the link.

  5. #5
    XTZGZoReX's Avatar Active Member
    Reputation
    32
    Join Date
    Apr 2008
    Posts
    173
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    (This post has been resolved; I spoke to Boogie on IRC.)

  6. #6
    bluez31's Avatar Member
    Reputation
    5
    Join Date
    Feb 2009
    Posts
    56
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Forgive me for being somewhat off topic, but can someone send me some decrypted captures? I'd like to take a peek at what kind of data can be read and utilized. Thanks.

  7. #7
    miceiken's Avatar Contributor Authenticator enabled
    Reputation
    209
    Join Date
    Dec 2007
    Posts
    401
    Thanks G/R
    7/9
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by bluez31 View Post
    Forgive me for being somewhat off topic, but can someone send me some decrypted captures? I'd like to take a peek at what kind of data can be read and utilized. Thanks.
    Err, what do you think? All data comes from server to client...

  8. #8
    Robske's Avatar Contributor
    Reputation
    305
    Join Date
    May 2007
    Posts
    1,062
    Thanks G/R
    3/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I hooked all packet handlers, am I crazy?
    "Always code as if the guy who ends up maintaining your code will be a violent psychopath who knows where you live." - Martin Golding
    "I cried a little earlier when I had to poop" - Sku

  9. #9
    BoogieManTM's Avatar Active Member
    Reputation
    52
    Join Date
    May 2008
    Posts
    193
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Robske View Post
    I hooked all packet handlers, am I crazy?
    Indeed you are.

    I'm much more interesting in Client->Server packets, anyways

  10. #10
    caytchen's Avatar Contributor
    Reputation
    138
    Join Date
    Apr 2007
    Posts
    162
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by BoogieManTM View Post
    Indeed you are.

    I'm much more interesting in Client->Server packets, anyways
    That would be one function only then

  11. #11
    Jadd's Avatar 🐸 Premium Seller
    Reputation
    1515
    Join Date
    May 2008
    Posts
    2,433
    Thanks G/R
    81/336
    Trade Feedback
    1 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Send me some telehacks?

Similar Threads

  1. Looking for packet sniffer
    By danabe in forum WoW Bots Questions & Requests
    Replies: 3
    Last Post: 05-05-2011, 12:38 AM
  2. Packets sniffer
    By N1ghtmaree in forum WoW Memory Editing
    Replies: 9
    Last Post: 03-16-2011, 03:57 AM
  3. Safe to use packet sniffers?
    By nilum in forum World of Warcraft General
    Replies: 0
    Last Post: 06-05-2009, 12:22 PM
All times are GMT -5. The time now is 11:32 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search