tailieunhanh - practical packet analysis using wireshark to solve real world network problems phần 9

(Đối với máy chủ một danh sách đầy đủ của các lệnh có sẵn có thể nhìn thấy trong một gói tin FTP, xem RFC 959.) Chúng ta hãy xem xét một số lệnh FTP được sử dụng trong file ví dụ của chúng tôi, bắt đầu với 15 gói, được thể hiện trong hình bạn có thể thấy, gói 15 cho thấy một CWD | Figure 9-3 All of the SPOOLS traffic is going to the printer. It s easy enough to identify the source of the printing in this case but we still haven t solved the problem. To learn more about what s happening let s view the TCP stream of data being sent to the printer. When you do you ll see that the data is being printed from Microsoft Word and that the username of the person printing the data is csanders Figure 9-4 . Figure 9-4 Viewing the TCP stream of data being sent to a printer can give good insight. Summary While we haven t stopped the influx of SPOOLS packets in this scenario we have used Wireshark to quickly find the source of our mysterious printer problem. Having identified the source we can find out why this information is being sent to the printer. Most likely client on our network has been compromised in some way. An FTP Break-In FTP is one of the most commonly used means of transferring large amounts of data. The company we will be looking at now has an internal FTP server that it uses to maintain all of its pre-release software. Lately the IT technician in charge of maintaining and monitoring this server has noticed a large amount of traffic on the server after hours. Unfortunately the FTP server software doesn t have logging functionality so the only way to get a good grasp of what is going on is to get a packet capture. We want to identify the reason for the server s increase in bandwidth and eliminate the source. 124 Chapter 9 What We Know The FTP server is running very old software with no decent logging functionality. All major developers within the company have usernames and accounts that allow them full access to all files on the server. This server is also configured so that it may be accessed from outside of the network so that developers can work from home. Tapping into the Wire Since this server is on our network installing Wireshark on it may seem like the best method to use. However since the server is .

TỪ KHÓA LIÊN QUAN
crossorigin="anonymous">
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.