website monitoring on network

Thread Solved

Join Date: Feb 2009
Posts: 3,346
Reputation: sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of 
Solved Threads: 603
Sponsor
sknake's Avatar
sknake sknake is offline Offline
.NET Enthusiast

Re: website monitoring on network

 
0
  #11
Jul 23rd, 2009
I've been having so much fun with photo shop today here is a picture of my desk. I run the identical scenario I have been describing to you. You will see 4 network appliances on my desk that I write software for and I sniff the Ethernet communications to debug comm errors when writing an application.
Attached Thumbnails
my_desk.jpg  
Scott Knake
Custom Software Development
Apex Software, Inc.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 45
Reputation: derekn is an unknown quantity at this point 
Solved Threads: 0
derekn derekn is offline Offline
Light Poster

Re: website monitoring on network

 
0
  #12
Jul 24th, 2009
ok, wow, just got back from walmart and meijer...turns out they don't carry the hubs anymore. I was looking around on Newegg and Tigerdirect and everything is labeled as a "switch", but the same exact product that I used to have (Netgear EN104) I know was a hub. Could you please give me some guidance/recommendations on what kind of "hub" to purchase? And possibly where to get it?

Thanks again,

Derek
Reply With Quote Quick reply to this message  
Join Date: Feb 2009
Posts: 3,346
Reputation: sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of 
Solved Threads: 603
Sponsor
sknake's Avatar
sknake sknake is offline Offline
.NET Enthusiast

Re: website monitoring on network

 
0
  #13
Jul 24th, 2009
I run a neatgear DS104.

$100+: http://www.amazon.com/Netgear-DS104-.../dp/B00000J4LQ
$58: http://www.zdtronic.com/index.php?ma...roducts_id=851


I'm sure you can find it cheaper yet. Search around for that netgear model. Hubs are getting more and more rare because of the unique functionality they provide. I will always hang on to mine
Scott Knake
Custom Software Development
Apex Software, Inc.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 45
Reputation: derekn is an unknown quantity at this point 
Solved Threads: 0
derekn derekn is offline Offline
Light Poster

Re: website monitoring on network

 
0
  #14
Jul 24th, 2009
I grabbed me a cheapie on ebay...money's kinda tight right now. I could just KICK myself for getting rid of that old hub! I grabbed a dynex (???) for 10 bucks. As long as it does the job, I don't care too much about it. Now I just gotta wait for it to get here to try it out....!
Reply With Quote Quick reply to this message  
Join Date: Feb 2009
Posts: 3,346
Reputation: sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of 
Solved Threads: 603
Sponsor
sknake's Avatar
sknake sknake is offline Offline
.NET Enthusiast

Re: website monitoring on network

 
0
  #15
Jul 24th, 2009
Good luck! I'll wait to hear from you
Scott Knake
Custom Software Development
Apex Software, Inc.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 45
Reputation: derekn is an unknown quantity at this point 
Solved Threads: 0
derekn derekn is offline Offline
Light Poster

Re: website monitoring on network

 
0
  #16
Jul 31st, 2009
Originally Posted by sknake View Post
Good luck! I'll wait to hear from you
Well, I got the router. I don't really know that Wireshark is the best option for me. I don't want to go commercial (=$$) but Wireshark is a LOT more advanced than what I need. All I want/need is a program that will simply log/monitor all websites visited. I don't need every single header request and all those inundating communications between the computers. Any thoughts on what might do the job?

Derek
Reply With Quote Quick reply to this message  
Join Date: Feb 2009
Posts: 3,346
Reputation: sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of 
Solved Threads: 603
Sponsor
sknake's Avatar
sknake sknake is offline Offline
.NET Enthusiast

Re: website monitoring on network

 
0
  #17
Jul 31st, 2009
Are you at least seeing all the traffic?

Give me a few minutes and i'll get back to you on the log analysis
Scott Knake
Custom Software Development
Apex Software, Inc.
Reply With Quote Quick reply to this message  
Join Date: Feb 2009
Posts: 3,346
Reputation: sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of 
Solved Threads: 603
Sponsor
sknake's Avatar
sknake sknake is offline Offline
.NET Enthusiast

Re: website monitoring on network

 
0
  #18
Jul 31st, 2009
Hmm you can set the filter http.request == 1 to limit to HTTP GET traffic. To analyze the sites visited do this:

Statistics -- HTTP -- Requests -- in the filter put "http.request == 1"
There you have it. A list of websites visited.
Attached Thumbnails
wireshark.png  
Scott Knake
Custom Software Development
Apex Software, Inc.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 45
Reputation: derekn is an unknown quantity at this point 
Solved Threads: 0
derekn derekn is offline Offline
Light Poster

Re: website monitoring on network

 
0
  #19
Jul 31st, 2009
That does seem to work. Just one more question (ha! will they ever cease!?)...how would I only view from certain host, for example 192.168.0.103? I've been toying around with the filters...in fact, all i really want to CAPTURE is from 2 other hosts....I'm sure you can set it up that way, but I just haven't figured it out yet.

Seriously, you have been SO much help to me. I really appreciate it!

Derek

Edit: Maybe I have it... I changed filter in capture screen to "http.request == 1 and ip.host matches "192.168.0.103"" seems to work...does this look right to you?
Last edited by derekn; Jul 31st, 2009 at 8:32 pm.
Reply With Quote Quick reply to this message  
Join Date: Feb 2009
Posts: 3,346
Reputation: sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of sknake has much to be proud of 
Solved Threads: 603
Sponsor
sknake's Avatar
sknake sknake is offline Offline
.NET Enthusiast

Re: website monitoring on network

 
0
  #20
Aug 1st, 2009
use "ip.addr == 192.168.0.103". You can use the expression editor to help you build filters if you want to filter even more. "tcp.port == 80" is another example for ports. ip.host matches with DNS hostnames and might be a bit ambiguous or more CPU intensive if it tries to resolve. It should give you the same results but may take a bit longer... but yes, it looks right.

Please mark this thread as solved if I have answered all of your questions . This is probably the most involved thread I have posted on to date.
Last edited by sknake; Aug 1st, 2009 at 12:37 am.
Scott Knake
Custom Software Development
Apex Software, Inc.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Network Security Forum
Thread Tools Search this Thread



Tag cloud for Network Security
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC