Home > Windows Server Tips > Windows Systems and Network Administration > SmartSniff freeware captures raw sockets, TCP/IP packets
Windows Server Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WINDOWS SYSTEMS AND NETWORK ADMINISTRATION

SmartSniff freeware captures raw sockets, TCP/IP packets


Serdar Yegulalp, Contributor
06.12.2006
Rating: --- (out of 5)


Expert advice on Windows-based systems and hardware
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Packet sniffers are among a network administrator's best friends. They can help pinpoint whether a problem exists with a client, a server, or somewhere in between.

Nir Sofer, author of many other excellent utilities I've covered in the past, has now written a sniffer of his own: SmartSniff.

SmartSniff can work in one of two ways.

  • It can capture packets with Windows' native raw sockets capture system, although this only works on Windows 2000 or better. This method has limitations: You cannot capture outgoing UDP and ICMP packets, and Windows XP Service Pack 1 does not support capture at all.
  • It can capture with WinPcap, a free, open-source packet-capture driver that works on Windows 98 and higher and lets you capture everything.

Each separate ICMP, TCP or UDP connection is broken out individually and referred to as a stream. Multiple conversations on the same connection are aggregated into the same stream. SmartSniff's top panel lists all the streams captured by the application and shows every important piece of data you could need: local and remote address, hosts and ports; service type; number of packets exchanged, total data size and capture time.

Click on one of the conversations and the data in that conversation is displayed in the bottom panel. Data sent from your machine is in blue, while data sent to your machine is in purple.

Note: Remote host name lookups are only resolved after you stop recording (so that traffic doesn't get logged as well), and only 7-bit ASCII data is presented by default. If you select Options | "Display Characters Above ASCII 127," you'll see all the characters, but the color-coding on the display will vanish and the data might not be as coherent.

Nir Sofer's applications have a high degree of consistency in their presentation. For instance, if you double-click on one of the conversations, you get an expanded infobox that's the same as one he's written for other tools. The whole record buffer can be saved in both a native data format and to an HTML report, and both the display results and capture actions can have filters applied to them so you only record what you need to see.

About the author: Serdar Yegulalp is editor of the Windows Insight, (formerly the Windows Power Users Newsletter), a blog site devoted to hints, tips, tricks and news for users and administrators of Windows NT, Windows 2000, Windows XP, Windows Server 2003 and Vista. He has more than 12 years of Windows experience under his belt, and contributes regularly to SearchWinComputing.com and SearchSQLServer.com.

More information on this topic:

  • White Paper: TCP/IP for Windows 2000: Introduction to TCP/IP
  • Topics: Network Management
  • RSS: Sign up for our RSS feed to receive expert advice every day.

    Rate this Tip
    To rate tips, you must be a member of SearchWindowsServer.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Windows System and Network Performance Monitoring
    Quick hits: Troubleshooting service account failure, batch job execution
    Troubleshooting common Windows service failures
    Monitor network bandwidth with CyberGauge
    Optimizing NTFS file system performance
    For Active Directory performance gains, delegate the _MSDCS DNS zone
    Sysinternals TCPView monitors network connections on Windows systems
    Create data collector sets through Vista's Performance Monitor
    Data collector sets simplify monitoring of Vista performance
    Performance monitoring in Windows: An overview
    RRAS utility in Windows Server 2003 traces network problems

    Windows Systems and Network Management Tools and Techniques
    Getting familiar with IPv6 for Windows environments
    Perfmon made easy with PAL utility
    Troubleshooting Windows application crashes or hangs
    Free Windows security tools every admin must have
    Top five Server Core management tips for Windows 2008
    Top free tools for Windows server administration
    A first look at Internet Information Services 7.0
    Windows registry hack improves offline file access for mobile users
    Reducing the size of network backups in Windows
    Monitor network bandwidth with CyberGauge

    Windows Systems and Network Administration
    How to use Group Policy to centralize system configurations
    Troubleshooting Windows application crashes or hangs
    Converting VMware ESX machines to Hyper-V format
    Using DFSR for SYSVOL replication in Windows Server 2008
    Top 25 Windows PowerShell commands for administrators
    Key DFS improvements in Windows Server 2008 R2
    Free Windows security tools every admin must have
    Group Policy makes strides in Windows Server 2008 R2
    Quick tips for troubleshooting NTFS permissions
    Common causes of Windows server security vulnerabilities

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Server Room Design - Planning, Cooling, Maintenance
    HomeTopicsBlogsITKnowledge ExchangeTipsNewsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts