CoPacketSniffer 8:@ , packet learning / discovery tool does wireshark like filtering

08/26/2010 02:04 clintonselke#1
CoPacketSniffer 8:@110110110110...

REQUIRES WinPcap:[Only registered and activated users can see links. Click Here To Register...]

Run As ADMIN: Required for using conquer memory for trial & error when solving for the key after DH key exchange.

THIS IS NOT A BOT, ITS A EDUCATIONAL TOOL, PLEASE DON'T ASK ME HOW TO MAKE IT HUNT!!!

Hello Guys and Girls, made a nice little tool for assisting developers out there in finding packets and learning how they work.

Heres a little screenshot
[Only registered and activated users can see links. Click Here To Register...]

This tool will always be 100% free. No advertising links like sharecash, just direct links.

The expressions are similar to wireshark.

Here are some of the variables / functions

DstEther - The destination mac address. (for network interface or router)
SrcEther - The source mac address. (for network interface or router)
DstIP - The destination IP address (for network interface, remote login server, or game server)
SrcIP - The source IP address (for network interface, remote login server, or game server)
DstPort - The destination port (goes with DstIP)
SrcPort - The source port (goes with SrcIP)
Data.StartsWith("AA BB CC DD") - Finds packets that start with AA BB CC DD
Data.Contains("AA BB CC DD") - Finds packets that contain AA BB CC DD

&& - Logical AND, Example: SrcPort==5816 && Data.StartsWith("25 00 1A 27");
|| - Logical OR, Example: SrcIP == "10.1.1.2" || SrcIP == "10.1.1.3"
! - Logical NOT, Example: !Data.Contains("1A 27")
== - EQUAL test, Example: DstPort == 5816
!= - NOT EQUAL test, Example: DstPort != 5816

Downloads:
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]

Tips

- Login spams a lot of packets, and sometimes packets are dropped due to the time it takes to draw them on the screen. If you uncheck the "Enable" checkbox during login and re-check it, then there will be less chance of packets appearing as random data.

ChangeLog

CoPacketSniffer-v1.2.zip

- Fixed a bug when copying packets in filtered mode. (It was copying the wrong packet before)

CoPacketSniffer-v1.1.zip

- Made the Filter Expression TextBox coloured. (green means valid expression, red means invalid expression)
- Made the Font inside the packet list monospaced

CoPacketSniffer-v1.0.zip

- Added C/C++, C#, VB.Net, and Detailed Copy styles (from right click on packets)
- Added IP checksum check. (Ignores errored packets which needs to be resent due to poor network connection)

CoPacketSniffer.zip

- Initial Import
08/26/2010 11:34 Die Schnittstelle#2
AntivirusVersionLast UpdateResult
AhnLab-V32010.08.26.002010.08.25-
AntiVir8.2.4.382010.08.26-
Antiy-AVL2.0.3.72010.08.26-
Authentium5.2.0.52010.08.26W32/Heuristic-KPP!********
Avast4.8.1351.02010.08.25-
Avast55.0.594.02010.08.25-
AVG9.0.0.8512010.08.25-
BitDefender7.22010.08.26-
CAT-QuickHeal11.002010.08.24-
ClamAV0.96.2.0-git2010.08.26-
Comodo58622010.08.26-
DrWeb5.0.2.033002010.08.26-
Emsisoft5.0.0.372010.08.26-
eSafe7.0.17.02010.08.25-
eTrust-Vet36.1.78182010.08.26-
F-Prot4.6.1.1072010.08.26W32/Heuristic-KPP!********
F-Secure9.0.15370.02010.08.26-
Fortinet4.1.143.02010.08.26-
GData212010.08.26-
IkarusT3.1.1.88.02010.08.26-
Jiangmin13.0.9002010.08.26-
Kaspersky7.0.0.1252010.08.26-
McAfee5.400.0.11582010.08.26Suspect-D!F817EDAFAADA
McAfee-GW-Edition2010.1B2010.08.26Heuristic.BehavesLike.Win32.Trojan.H
Microsoft1.61032010.08.26-
NOD3253972010.08.25-
Norman6.05.112010.08.25-
nProtect2010-08-26.012010.08.26-
Panda10.0.2.72010.08.25-
PCTools7.0.3.52010.08.26-
Prevx3.02010.08.26-
Rising22.62.03.012010.08.26-
Sophos4.56.02010.08.26-
Sunbelt67952010.08.26-
SUPERAntiSpyware4.40.0.10062010.08.26-
Symantec20101.1.1.72010.08.26-
TheHacker6.5.2.1.3562010.08.26-
TrendMicro9.120.0.10042010.08.26-
TrendMicro-HouseCall9.120.0.10042010.08.26-
VBA323.12.14.02010.08.25-
ViRobot2010.8.26.40092010.08.26-
VirusBuster5.0.27.02010.08.25-

looks clean
08/26/2010 11:44 clintonselke#3
Thanks .Mio
08/26/2010 11:49 LoSeR1#4
lol i dont even know wat it should be doing
08/26/2010 18:28 Ian*#5
Quote:
Originally Posted by LoSeR1 View Post
lol i dont even know wat it should be doing
it's a sexy packet logger which doesn't require forwarding connections to a proxy :D
08/26/2010 19:19 gabrola#6
Quote:
Originally Posted by Ian* View Post
it's a sexy packet logger which doesn't require forwarding connections to a proxy :D
Indeed, it's sexy.
EDIT: Right click won't work.
EDIT2: Clint you could also use a fixed width font like Courier New for the packets to look "nice"
08/27/2010 08:44 clintonselke#7
Quote:
Originally Posted by gabrola View Post
Indeed, it's sexy.
EDIT: Right click won't work.
EDIT2: Clint you could also use a fixed width font like Courier New for the packets to look "nice"
Will do, the gui was kinda done quickly. Any drawings or pictures of a gui layout would be appreciated as well.

There are a couple of things im working on w/ it atm. One is, since the packets are being sniffed in a raw way, there is a chance they can arrive out of order, or corrupt. If a packet is out of order or corrupt, then I need to ignore the packet, otherwise it will throw the encryption out and you will end up with random bytes for the packets.

Lots of reading to do on Ethernet, IP and TCP packet headers... joy... :P

As for right click, that should be working unless I've zipped the wrong exe. Like ya select a packet, right click it, then go "C/C++ Style Copy", "VB.Net Style Copy", "C# style copy" or "detail style copy", and it should end up on the clipboard in that style.
08/27/2010 17:01 drunkey#8
Greate Job, but I want to use it :)
but: Why the CO and packetsniffer is shutting down when I start CO? don't say nothing just exit. I have windows xp sp2 , I'm using wi-fi.
08/29/2010 04:08 clintonselke#9
Quote:
Originally Posted by drunkey View Post
Greate Job, but I want to use it :)
but: Why the CO and packetsniffer is shutting down when I start CO? don't say nothing just exit. I have windows xp sp2 , I'm using wi-fi.
Atm its doing a Debug Breakpoint Hook on BF_set_key(), to catch the new blowfish key after DH key exchange. And the address of that function is hard coded. That means this tool will only work on the latest English version exe for now.

But later on i'll make it do a memory search for the BF_set_key() function, so it will work for more versions and more languages of conquer.
09/07/2010 02:09 Starburst17#10
Thank you for your hard work!
09/08/2010 11:12 PKDemon#11
i think this is kinda of kewl but for someone like me that dont know a dang thing about packets it is useless haha

but i like the copy functions though

and i test this on a 5095 private server and it was reading the packets

i guess i am gonna have to learn how to do stuff with these packets and what packets are what :P

this is a fun tool to have and you could learn alot from it
10/15/2010 14:24 Matic^#12
will this going to be updated?