Delirandom

one monkey between 0 and infinite is lucky

SniffJoke 0.3

SniffJoke is a “connection scrambler” for Linux with the purpose of preventing packet sniffers from reassemble network sessions of the user. The “sniffer evasion” technology is well known since almost 10 years. SniffJoke implements the most efficents techniques. Using a local fake tunnel it is able to manage outgoing and ingoing packets without disturbing the kernel. With the local web interface the user can easily start/stop and configure SniffJoke. At the moment, Wireshark, the most famous packet analyzer, is unable to correctly reconstruct TCP flow mangled by SniffJoke. I would like to update the list of victim sniffers, so please send me a report if you test SniffJoke with other network protocol analyzers.

SniffJoke page

Categories: e-privacy - english - hacking
 
[...] SniffJoke è uno strumento che consente di aggiungere un pizzico di privacy alle nostre connessioni in chiaro, iniettando pacchetti che rendono difficoltosa la ricostruzione della sessione di rete. Rilasciato con licenza GPLv3 e disponibile al momento soltanto per Linux (la futura versione 1.0 dovrebbe aggiungere il supporto anche a Mac OS X), SniffJoke inietta nelle nostre connessioni dei pacchetti in grado di confondere un ipotetico packet sniffer in ascolto, senza però causare problemi al sistema di destinazione. [...]
Have you thought about including traffic that will actually crash sniffers like Wireshark, or at least recent versions?

Like
http://www.milw0rm.com/exploits/8308
http://www.securitytracker.com/alerts/2008/Feb/1019515.html
http://www.securiteam.com/securitynews/5YP0B1PMAW.html
15 April 09 at 16:32
LonerVamp, interesting suggestion, anyway, the vulnerable version is old (Solution: The vendor has issued a fix (0.99.8). ) and mine attacks are not simple strange devel’s bug, but correct packets that could not be so easily fixed by wireshark and other flow reassembler.

Undoubtly the possibility to broke execution in a remote sniffer sounds good, but denial of service had short life, I’m looking for hacks difficult to handle to the sniffer developer.
15 April 09 at 17:32