Wsniff

Info

Wsniff is like dsniff on *nix, except not as advanced yet! It uses a plugin architecture to extend the decoding functionality and uses a Winpcap wrapper to capture the packets.

Features

  • Disable/Enable loaded plugins
  • Export data
  • Dropin plugin architecture
  • Listview sorting to help identify/group data types
  • Text view window to get the full text returned from the packet

Plugins

 

  • Email Address - Extracts email addresses
  • FTP - Extracts FTO login details
  • HTTP - Extracts HTTP requests
  • POP3 - Extracts POP3 login details
  • SNMP - Extracts SNMP community strings
  • SQL Server - Decodes SQL Server logins on the fly
  • Telnet - Extracts Telnet logins

Requirements

 

  • Windows 2000, Windows XP, Windows 2003 Server (Might work on others?)
  • Microsoft .NET Framework v2
  • WinPcap (http://www.winpcap.org/)

Screenshot

Wsniff

Options:

Size

Colors