top of page

Author: Net Equity Alliance (S. Ajideh) Research Initiative

Date: FEB, 2025

Here is an infographic illustrating the equipment required for the network traffic capture setup.

To set up this capture tool, a standard Ethernet network interface card (NIC) and a custom two-conductor twisted-pair cable are all you need. You can easily modify a standard patch cable or crimp one from scratch using bulk networking components.

The key is isolating the RX (Receive) pair—specifically pins 1 and 2. On one end of the cable, terminate these two conductors into a standard RJ-45 connector, which plugs directly into the attacker's network card to listen to the traffic.

Android natively recognizes many external Ethernet adapters, meaning that with root access, setup is entirely plug-and-play. Testing this configuration proved highly effective: the phone successfully captured unilateral traffic flowing from one laptop to another.

To access the internal signals, carefully score the cable's outer jacket longitudinally using a utility knife, ensuring the internal twisted pairs remain undamaged. There is no need to strip the insulation from the individual conductors. Instead, use insulation-piercing alligator clips (or bed-of-nails clips) that bite through the plastic cladding to establish electrical contact with the copper core.

he monitoring environment features a split configuration: one terminal displays live packet capture via , while the other runs to automatically parse credentials from the transit data. Our proof of concept successfully recovered a NetNTLM hash at the precise moment of network share authentication, underscoring the vulnerability of clear-text physical mediums to rudimentary interception techniques."tcpdumpnet-creds

bottom of page