What is NetMon and why do I care?
NetMon is Microsoft’s Network Monitor. It is a sniffer that runs under NT, and being a sniffer if you have to ask why you care, well, never mind 😉 NetMon is protected by a password scheme on version 3.51 that has nothing to do with regular NT security. In Phrack 48 file 15, AON and daemon9 have not only cracked the encryption scheme, they have written exploits for it as well. Check the resources section for the location of the exploit code (it includes full source including a Unix version in case you do not have an NT compiler). By the way, compared to other commercial sniffers, this early version of NetMon sucks. It would only look at traffic to and from the machine you are running it on. However, newer versions of NetMon supposedly do actual promiscuous sniffing and is a more useful tool. I have not seen this new NetMon but others report good things about it.