I need a little help with packet sniffing. I'm trying to explain this as best I can. I have a firm working knowledge of TCPIP and network protocols. However, I really don't know how to interprit or decode stuff in a packet sniffer such as Ethereal, Analyzer. I can sense some stuff liike an IPX packet storm.. Duh, but I'm still in the dark about reading packets as a whole.
I want to:
1. Be able to tell if there is a virus moving around on my network causing problems.
2. Tell if I have a faulty NIC
3. Tell if someone is using a hack tool to gain access to my network.
I'm just trying to get a good general understaning of what the symbols mean like ACK, and SYN_SENT, SYN, things of that nature.
When I do a search on the internet, I get very general info. Some places wont say because they think I want to be a hacker. I don't, I just want to be able to interprit a darn packet sniff from a sniffer program.