Security awareness: A lesson from Tcpdump and Ethereal

Ethernet has survived for several decades as essential media for LAN technology because of its relative inexpensive and reasonably fast. Shared Ethernet uses broadcast technology where CSMA/CD acts as medium access control. CSMA/CD deploys principle of media sharing and the drawback is promiscuous...

Full description

Bibliographic Details
Main Authors: Rohani, Mohd. Fo’ad, Maarof, Mohd. Aizaini, Selamat, Ali
Format: Conference or Workshop Item
Language:English
Published: 2005
Subjects:
Online Access:http://eprints.utm.my/5608/1/Foad2005_SecurityAwarenessLessonTcpdumpEthereal.pdf
_version_ 1825909767185367040
author Rohani, Mohd. Fo’ad
Maarof, Mohd. Aizaini
Selamat, Ali
author_facet Rohani, Mohd. Fo’ad
Maarof, Mohd. Aizaini
Selamat, Ali
author_sort Rohani, Mohd. Fo’ad
collection ePrints
description Ethernet has survived for several decades as essential media for LAN technology because of its relative inexpensive and reasonably fast. Shared Ethernet uses broadcast technology where CSMA/CD acts as medium access control. CSMA/CD deploys principle of media sharing and the drawback is promiscuous mode, whereby network interface device could intercept all packet frames that traveling on the wire. This has a significant impact on the security of Internet application. HTTP, FTP, E-MAIL and TELNET are daily applications, which offer secure transaction or unsecured transaction. However, users do not aware of the security provided by the services. They usually use unsecured transaction because of simplicity or unaware of security awareness. This behavior is vulnerable to packet-sniffing tools, such as sniffit, tcpdump and ethereal. These tools could intercept the traveling packet and extract sensitive information, such as user login and password or unencrypted data payload. This paper explores network security awareness from the perspective of packet-sniffing tools over unsecured application. The study uses tcpdump and ethereal, which are two of the most popular packet-sniffing tools. From the experiment, it is shown that vital information, such as login and password, could be compromised easily from the packet if users do not consider security awareness seriously.
first_indexed 2024-03-05T18:07:04Z
format Conference or Workshop Item
id utm.eprints-5608
institution Universiti Teknologi Malaysia - ePrints
language English
last_indexed 2024-03-05T18:07:04Z
publishDate 2005
record_format dspace
spelling utm.eprints-56082017-08-30T07:38:16Z http://eprints.utm.my/5608/ Security awareness: A lesson from Tcpdump and Ethereal Rohani, Mohd. Fo’ad Maarof, Mohd. Aizaini Selamat, Ali QA75 Electronic computers. Computer science Ethernet has survived for several decades as essential media for LAN technology because of its relative inexpensive and reasonably fast. Shared Ethernet uses broadcast technology where CSMA/CD acts as medium access control. CSMA/CD deploys principle of media sharing and the drawback is promiscuous mode, whereby network interface device could intercept all packet frames that traveling on the wire. This has a significant impact on the security of Internet application. HTTP, FTP, E-MAIL and TELNET are daily applications, which offer secure transaction or unsecured transaction. However, users do not aware of the security provided by the services. They usually use unsecured transaction because of simplicity or unaware of security awareness. This behavior is vulnerable to packet-sniffing tools, such as sniffit, tcpdump and ethereal. These tools could intercept the traveling packet and extract sensitive information, such as user login and password or unencrypted data payload. This paper explores network security awareness from the perspective of packet-sniffing tools over unsecured application. The study uses tcpdump and ethereal, which are two of the most popular packet-sniffing tools. From the experiment, it is shown that vital information, such as login and password, could be compromised easily from the packet if users do not consider security awareness seriously. 2005-05-17 Conference or Workshop Item PeerReviewed application/pdf en http://eprints.utm.my/5608/1/Foad2005_SecurityAwarenessLessonTcpdumpEthereal.pdf Rohani, Mohd. Fo’ad and Maarof, Mohd. Aizaini and Selamat, Ali (2005) Security awareness: A lesson from Tcpdump and Ethereal. In: Proceedings of the Postgraduate Annual Research Seminar 2005 (PARS 05), 17-18 May 2005, FSKSM, UTM.
spellingShingle QA75 Electronic computers. Computer science
Rohani, Mohd. Fo’ad
Maarof, Mohd. Aizaini
Selamat, Ali
Security awareness: A lesson from Tcpdump and Ethereal
title Security awareness: A lesson from Tcpdump and Ethereal
title_full Security awareness: A lesson from Tcpdump and Ethereal
title_fullStr Security awareness: A lesson from Tcpdump and Ethereal
title_full_unstemmed Security awareness: A lesson from Tcpdump and Ethereal
title_short Security awareness: A lesson from Tcpdump and Ethereal
title_sort security awareness a lesson from tcpdump and ethereal
topic QA75 Electronic computers. Computer science
url http://eprints.utm.my/5608/1/Foad2005_SecurityAwarenessLessonTcpdumpEthereal.pdf
work_keys_str_mv AT rohanimohdfoad securityawarenessalessonfromtcpdumpandethereal
AT maarofmohdaizaini securityawarenessalessonfromtcpdumpandethereal
AT selamatali securityawarenessalessonfromtcpdumpandethereal