Showing posts with label network interface. Show all posts
Showing posts with label network interface. Show all posts

Monday, November 4, 2013

Important NetScanTools Pro v11.53 Release

NetScanTools Pro v11.53 (installed) was released on November 1, 2013. This is a very important release because of the type of fixes that are in it. These fixes affect any of the tools that use WinPcap for capturing or sending packets. The WinPcap fixes are important if you use NetScanTools Pro on a machine where the network interface does not support promiscuous mode (normally WiFi 802.11) or you have more than one network interface on the machine.

If your network interface does not support promiscuous mode, all versions prior to 11.53 will not be able to open the interface resulting in a message similar to this one: "Error: Cannot open interface for packet sending. Please exit and restart NetScanTools Pro".

This means you cannot fully utilize tools that depend on WinPcap - for example the WinPcap ICMP mode of Traceroute will not work. The change in 11.53 allows the interface to be automatically opened in non-promiscuous mode if the open in promiscuous mode fails. If an adapter can be opened in promiscuous mode, all packets passing by it are passed along to the host system, however, if it is opened in 'normal' mode, then only packets intended for the system are passed to the host system. This mostly affects WiFi adapters so now you may find that NetScanTools Pro works much better with your WiFi network interface. Error message reporting has been significantly improved at the same time.

If you have more than one network interface on the system running NetScanTools Pro, all versions prior to 11.53 will only be able to send packets to the local network associated with the secondary interface. In other words if a packet sent out the secondary interface is intended for a destination beyond the default gateway, it will not get there because the default gateway mac address was not being obtained correctly. It now is obtained correctly so packets will go out the secondary interface default gateway as intended.

The WinPcap related changes affected ARP Ping, ARP Scan, Duplicate IP Address Scanner, OS Fingerprinting, Packet Capture Playback, Packet Generator, Ping, Port Scanner, Promiscuous Mode Scanner, Traceroute, Connection Monitor, Packet Capture, Passive Discovery, SNMP Dictionary Attack and SNMP Scanner.

Other changes include:
  1. The improvement of administrator privileges detection which affects TimeSync - doing a clock synchronization and DNS Tools Core Edit Hosts File. Some portions of Network Connection Endpoints are also affected.
  2. Addition of a column showing the DHCP Server MAC Address to the DHCP Server Discovery Tool.
  3. Packet Capture Playback now supports sending .pcap files in addition to .cap files.
  4. Ping Enhance/TCP Ping now correctly send the number of packets you designate.
  5. SQLite was updated to 3.8.1 and the database files were updated.

Version 11.53 is available to all those will active maintenance plans. Click on Help/Check for New Version to obtain it.

Wednesday, May 9, 2012

IPv6 Network Neighbors in NetScanTools Pro 11.30

We introduced a new tool for IPv6 called Network Neighbors. This tool provides information similar to what the ARP Cache tool does for IPv4: a mapping of IPv6 addresses to physical addresses. Unlike the ARP Cache tool a physical address can be not only a MAC address, but it can also be an IPv4 address associated with a tunneling interface. You can see that in the image below.

Interesting things in this image are the global IPs that start with 2001: - one on those is the local address and the others are target addresses. Note also the large number of permanent multicast entries starting at the top with the ff02::c SSDP, ff02::16 All MLDv2-capable routers, ff02::1:2 All-dhcp-agents and finally the ff02::1:ffxx:xxxx solicited node address (RFC 4291).

You can see the lone fe80:: link local address attached to the only real physical network interface (NIC) in the computer. And you can even see the VMware player interfaces.

What you cannot see in the image is the interface alias, type and ifIndex (Scope ID).

This is new in NetScanTools Pro v11.30.