October 2, 2026
What is Network Sniffing: Can Someone Read Your Network Traffic?
How Packets Are Captured, Analysed, and Exploited โ Understanding Encryption and Real-World Attacks
By Krish Gupta
5 min read
How Packets Are Captured, Analysed, and Exploited โ Understanding Encryption and Real-World Attacks
1. What Is Network Sniffing?
Imagine sending a letter. If it is open, someone who gets access to it may read the message. If it is locked, they may still see where it is going, but not easily read its contents.
Network sniffing works in a similar way.
Network sniffing is the process of capturing and analysing data packets travelling across a network.
It can help us understand:
- Which devices are communicating.
- Which protocols and ports are being used.
- How much data is transferred.
- Whether communication is suspicious.
- Whether an application or network connection is failing.
Sniffing is a legitimate technique used by network administrators and security analysts. Attackers may also misuse it to collect information from networks they have compromised.
2. How Does Sniffing Work?
When you open a website, your device exchanges small units of data called packets with a server.
A packet may contain source and destination IP addresses, ports, protocol information, and application data.
A packet-capture tool can collect traffic that the network interface is able to observe.
Device A --------\
Switch -------- Router -------- Internet
Device B --------/
|
| (if traffic is visible)
v
Wireshark / tcpdumpDevice A --------\
Switch -------- Router -------- Internet
Device B --------/
|
| (if traffic is visible)
v
Wireshark / tcpdumpOne important point: on a modern switched network, a normal computer usually cannot see all unicast traffic between other devices. This is where techniques such as port mirroring become relevant.
3. Passive vs Active Sniffing
Passive sniffing: Observing traffic without changing how it travels. For example, capturing traffic from an authorised monitoring point.
Active sniffing: Influencing traffic flow to make it observable. ARP spoofing is one technique that may be used to position an attacker between two devices.
Remember:
- Sniffing means capturing and analysing traffic.
- ARP spoofing manipulates IP-to-MAC address information.
- MITM means positioning between communicating parties.
These concepts can be connected, but they are not the same.
4. What Is Port Mirroring (SPAN)?
Port mirroring is a feature in managed switches that copies traffic from selected ports or VLANs to a monitoring port.
Cisco commonly calls it SPAN (Switched Port Analyzer).
PC-A --------\
Switch -------- PC-B
|
| Mirrored copy
v
Monitoring PC
WiresharkPC-A --------\
Switch -------- PC-B
|
| Mirrored copy
v
Monitoring PC
WiresharkThe original communication continues normally. The switch sends an additional copy to the monitoring system.
Administrators use port mirroring for troubleshooting, security monitoring, and packet analysis.
Can attackers abuse it? Yes. If attackers gain sufficient access to a network device, they may try to create an unauthorised mirroring session. Port mirroring itself is not malicious; unauthorised use is the concern.
5. What Can an Attacker See?
It depends on whether the traffic is encrypted.
Unencrypted Traffic
Older or insecure protocols may expose readable information, such as usernames, commands, URLs, or application data.
Examples include unencrypted HTTP, Telnet, and FTP.
Encrypted Traffic
HTTPS uses TLS to protect communication. With correctly configured encryption, a passive observer generally cannot read the protected application content.
However, some metadata may remain visible:
- Source and destination IP addresses.
- Port numbers.
- Packet sizes and timing.
- Communication patterns.
- Some connection metadata.
Capturing traffic does not automatically mean decrypting it. Encryption protects the contents, but it does not make packet capture impossible.
6. Tools Used for Packet Analysis
Security professionals use different tools for capturing and analysing network traffic.
Wireshark
A graphical protocol analyser used to inspect packets, troubleshoot connections, and investigate network activity.
Basic workflow in an authorised lab:
- Open Wireshark.
- Select your lab network interface.
- Start capturing.
- Generate test traffic.
- Stop the capture and apply a filter.
Useful display filters:
dns
tcp
tls
ip.addr == 192.168.1.10dns
tcp
tls
ip.addr == 192.168.1.10
tcpdump
A command-line packet-capture tool commonly used on Linux.
Capture traffic on an interface:
sudo tcpdump -i eth0sudo tcpdump -i eth0Capture DNS traffic:
sudo tcpdump -i eth0 port 53sudo tcpdump -i eth0 port 53Save a capture:
sudo tcpdump -i eth0 -w lab-capture.pcapsudo tcpdump -i eth0 -w lab-capture.pcapRead a saved capture:
tcpdump -r lab-capture.pcaptcpdump -r lab-capture.pcapInterface names may differ on your system.
Other Useful Tools
- TShark: Wireshark's command-line version.
- NetworkMiner: Helps analyse network forensic artefacts.
- ngrep: Searches captured traffic for patterns.
- tcpflow: Reconstructs TCP streams from packet captures.
These tools do not magically decrypt properly encrypted traffic.
7. Capture Filters vs Display Filters
Beginners often confuse these two.
TypePurposeExampleCapture filterControls what gets capturedport 53Display filterControls what is shown after capturedns
Capture filter = what gets collected. Display filter = what gets displayed.
8. Can Sniffing Still Work With Encryption?
Yes. Capturing packets and reading their contents are different things.
Even when traffic is encrypted, an observer may identify communication patterns, connection timing, packet sizes, and destination addresses.
Sensitive data may still be exposed if an endpoint or server is compromised, encryption is misconfigured, or secrets and keys are stolen.
So, encryption is essential โ but it must be correctly implemented and supported by secure endpoints and network devices.
9. Recent Real-World Example
A joint cybersecurity advisory published by CISA and partner agencies on September 3, 2025 described Chinese state-sponsored actors compromising network devices and using packet-capture and traffic-mirroring capabilities, including SPAN, RSPAN, and ERSPAN.
The advisory described collection of authentication-related network traffic, including TACACS+ traffic used for network-device administration. It also explained how captured traffic could become useful when a shared secret was known or could be recovered.
This shows that sniffing is not limited to someone capturing traffic on public Wi-Fi. Compromised network infrastructure can provide attackers with much greater visibility.
Another FBI advisory, published on August 20, 2025, described Russian government cyber actors targeting networking devices and critical infrastructure.
10. How Can Organisations Detect and Prevent Sniffing?
Security teams should monitor for unexpected packet-capture activity and unauthorised network-device changes.
Important protections include:
- Use HTTPS, SSH, SFTP, and secure management protocols.
- Restrict administrative access to switches and routers.
- Monitor new or modified SPAN/RSPAN/ERSPAN sessions.
- Disable unused services and update network-device firmware.
- Use network segmentation to limit access.
- Monitor device logs centrally.
- Use controls such as Dynamic ARP Inspection where supported.
- Enable multi-factor authentication for management access.
No single control prevents every form of sniffing. A layered security approach is needed.
11. Safe Beginner Lab
You can learn packet analysis using your own computer or an authorised virtual lab.
- Open Wireshark and select your lab interface.
- Start a capture.
- Run a DNS lookup:
nslookup example.comnslookup example.com- Apply the Wireshark display filter:
dnsdns- Inspect the query, response, and source/destination addresses.
- Save the capture as a
.pcapngfile for later analysis.
Only capture traffic from systems and networks you own or are authorised to test.
Final Takeaway
Network sniffing is an important cybersecurity concept used for troubleshooting, monitoring, and investigations. It can also be misused by attackers who gain access to a network or its devices.
The most important lesson is:
Capturing traffic and reading traffic are not the same thing.
Encryption protects data contents, but metadata may still be visible. The 2025 CISA advisory also shows why securing network devices and monitoring traffic-mirroring configurations remain important.
Learn how packets travel, what tools can reveal, and how defenders can detect unauthorised monitoring.
References
- CISA โ Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System (September 3, 2025).
- FBI โ Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure (August 20, 2025).
- MITRE ATT&CK โ Network Sniffing (T1040).
- Wireshark and tcpdump official documentation.
Disclaimer: This article is for educational and defensive cybersecurity learning. Capture traffic only on networks and devices you own or are authorised to assess.
Let's Connect!
If you found this article helpful, feel free to share your thoughts, questions, or experiences in the comments.
Cybersecurity is a continuous learning journey, and I'd love to connect with fellow learners, security enthusiasts, and professionals.
Let's learn, share, and grow together!
๐ Connect with me on LinkedIn: Krish Gupta
If you enjoyed reading this article, consider giving it a clap and following me on Medium for more content on networking, cybersecurity, and ethical hacking.
Keep learning. Keep exploring. Stay curious! ๐