Windows 10: How to get the IPv6 headers on Windows using raw-socket ?

Discus and support How to get the IPv6 headers on Windows using raw-socket ? in Windows 10 Gaming to solve the problem; I would like to implement a sniffer for incident response and forensic investigations, to sniff the traffic and identifying malicious packets and C2... Discussion in 'Windows 10 Gaming' started by Maurice Lambert, Feb 13, 2023.

  1. How to get the IPv6 headers on Windows using raw-socket ?


    I would like to implement a sniffer for incident response and forensic investigations, to sniff the traffic and identifying malicious packets and C2 C&C -Command and Control IP.In incident response i can't install npcap/winpcap or other librairies detected by antivirus softwares and i should use the faster way to sniff the local traffic. So i would like to develop a simple CLI sniffer it must be launched on Windows core servers in a simple executable file to copy/paste it on the server and launch it with admin privileges.Context example: a ransomware is running o

    :)
     
    Maurice Lambert, Feb 13, 2023
    #1

  2. Setting SIO_RCVALL option for windows kernel socket

    I am developing a kernel driver to capture icmp router advertisement message. Following are the steps :

    1. Create a raw socket using WskSocket: CreateSocket(AF_INET, SOCK_RAW, IPPROTO_IP, WSK_FLAG_DATAGRAM_SOCKET);

    2. Bind it to a specific interface and port 0

    3. Invoke Receive from

    I read online that for raw sockets to sniff all IP packets we need to set IOCTL SIO_RCVALL. However I didn't find an equivalent option in Winsock Kernel. From NetMon I see the icmp packet reaching the VM (Windows Hyper V VM), however the driver isn't able
    to intercept. The driver is able to receive udp packets. One more observation, the destination Ethernet for the packets received by the driver is FF-FF-FF-FF-FF-FF. The icmp packets received by NetMon have well defined Ethernet destination.

    a. Kindly let me know if additional steps are needed to make raw sockets sniff all ip packets in kernel mode.

    b. Would NDIS Protocol Drivers be an easier way to go forward?

    I was able to establish icmp communication using raw sockets in user mode (Winsock) and I have replicated exact same steps.
     
    Deepal Dhariwal, Feb 13, 2023
    #2
  3. Error message "missing registry socket"

    Hi Harry,

    Thank you for bringing up your query on Microsoft Community.

    I realize this may be frustrating. Now that you have me with you, let me take care of this.

    Winsock or Windows Sockets is a technical specification that defines how Windows network software should access network services.

    Let us try the following steps and check if it helps.

    Step 1: Perform a Winsock Reset

    • Open the Windows Start Screen or Start Menu and type
      cmd in the search box.
    • Right-click Command Prompt or cmd in the search results and select
      Run as Administrator.
    • Type netsh winsock reset in the Command Prompt window and press
      Enter. Wait for Windows to finish resetting your Winsock configuration.
    • Reboot your computer.

    Step 2: I suggest you to follow the steps suggested by

    Suvarna Govinda
    (replied on February 16, 2016) and check if it helps.

    "Windows Sockets registry entries required for network connectivity are missing" Connectivity Issues in Windows 10

    Redirecting

    Hope it helps.

    Let us know the status, we are glad to assist you further
     
    Abdul_Malik, Feb 13, 2023
    #3
  4. topgundcp Win User

    How to get the IPv6 headers on Windows using raw-socket ?

    Save RAW drive - Don't want data


    Open Admin command prompt, then type:
    1. diskpart
    2. list disk ======> Take note of disk # of the RAW drive
    3. select disk # ======> is the number in step 2
    4. clean
    5. exit
    Open Disk Management and initialize it, Create Simple, format.
     
    topgundcp, Feb 13, 2023
    #4
Thema:

How to get the IPv6 headers on Windows using raw-socket ?

Loading...
  1. How to get the IPv6 headers on Windows using raw-socket ? - Similar Threads - IPv6 headers using

  2. How to force Windows to use ULA as valid IPv6 Internet

    in Windows 10 Gaming
    How to force Windows to use ULA as valid IPv6 Internet: I know ULA is not meant for Routable to Internet, but I have multiple subnet to partition Family, Guest, HomeLab and IoT Device. Thus making other LAN subnet to have IPv6 Internet.however Telekom Malaysia refuse to provide customer at-least /60 prefix:so I end up with...
  3. How to force Windows to use ULA as valid IPv6 Internet

    in Windows 10 Software and Apps
    How to force Windows to use ULA as valid IPv6 Internet: I know ULA is not meant for Routable to Internet, but I have multiple subnet to partition Family, Guest, HomeLab and IoT Device. Thus making other LAN subnet to have IPv6 Internet.however Telekom Malaysia refuse to provide customer at-least /60 prefix:so I end up with...
  4. Windows cannot get IPv6 addr

    in Windows 10 Gaming
    Windows cannot get IPv6 addr: For a long time, my computer may not be able to get IPv6 when connected to any Wi-Fi.I'm 100% sure this this problem of Windows because:Not every Wi-Fi has this problem. But for those doesn't work for the first time, it will never work.My Linux system can always obtain one....
  5. Windows cannot get IPv6 addr

    in Windows 10 Software and Apps
    Windows cannot get IPv6 addr: For a long time, my computer may not be able to get IPv6 when connected to any Wi-Fi.I'm 100% sure this this problem of Windows because:Not every Wi-Fi has this problem. But for those doesn't work for the first time, it will never work.My Linux system can always obtain one....
  6. How to get the IPv6 headers on Windows using raw-socket ?

    in Windows 10 Software and Apps
    How to get the IPv6 headers on Windows using raw-socket ?: I would like to implement a sniffer for incident response and forensic investigations, to sniff the traffic and identifying malicious packets and C2 C&C -Command and Control IP.In incident response i can't install npcap/winpcap or other librairies detected by antivirus...
  7. MAIL application displays the raw email header information

    in Windows 10 Software and Apps
    MAIL application displays the raw email header information: I’m an AOL user and have a problem with the Windows 10 MAIL application. What I found is that when Content-Type attribute in an incoming email is set to text/html, the Windows MAIL application displays the raw email header information but does not display the content of the...
  8. MAIL application displays the raw email header information

    in Windows 10 Gaming
    MAIL application displays the raw email header information: I’m an AOL user and have a problem with the Windows 10 MAIL application. What I found is that when Content-Type attribute in an incoming email is set to text/html, the Windows MAIL application displays the raw email header information but does not display the content of the...
  9. Not getting top header in Settings

    in Windows 10 Customization
    Not getting top header in Settings: Hello, I have a computer running Windows 10 21H2 the latest version of Windows 10 and I am not getting the header in Windows settings. The header that shows Account name, Microsoft 365 and Onedrive is not visible. Only the settings with the search bar is visible, and the...
  10. Is this a phone socket or ethernet socket ?

    in Windows 10 Network and Sharing
    Is this a phone socket or ethernet socket ?: Hi. My brother in law has asked me if I can install broadband in his shed, he has shown me photos of the wired sockets he has but he is unsure what they are and I can't tell for sure from that pic. Could you tell me if that socket in the photo is for a ethernet plug or a...