RE: learning sniffer skills

From: Beauford, Jason (jbeauford_at_EightInOnePet.com)
Date: 12/09/04

  • Next message: Matias Rollan: "Re: learning sniffer skills"
    Date: Thu, 9 Dec 2004 17:12:03 -0500
    To: <cmora@gigax.org>, <security-basics@securityfocus.com>
    
    

    Let me recommend a book to you: Network Intrusion Detection (Third
    Edition) by Stephen Northcutt and Judy Novak. Its awesome. Later
    chapters provide detailed insight into processing TCPDUMP and WINDUMP
    parameters. A definite must when you talk about sniffing networks.

    Here's a link to some Google Print online version of the book.. Better
    to purchase.

    http://print.google.com/print?id=xWVSnrlakL4C&lpg=3&prev=http://print.go
    ogle.com/print%3Fq%3DNetwork%2BIntrusion%2BDetection&pg=0_1&sig=gpF5JaqV
    WvvxbnmBPTFUBGNbwGg

    But to answer your question, download Ethereal and open the TCPDUMP
    file, from there you can right click and choose FOLLOW TCP STREAM. This
    should give you the results you're looking for.

    Kind Regards,

    JMB

    -----Original Message-----
    From: Carlos Mario Mora (c4y0) [mailto:c4y0@yahoo.com.mx]
    Sent: Thursday, December 09, 2004 1:01 PM
    To: security-basics@securityfocus.com
    Subject: learning sniffer skills

    hi!

    Im starting to learn use a sniffer, but now im stopped with the method
    to read the sniffer output.

    Im trying read with tcpdump or snort the mail messages downloaded by
    pop3. But can see the message content. How can "assembly" the
    message readed with the sniffer?

    Thanks in advance.

    -- 
    Carlos Mario Mora (c4y0) <c4y0@yahoo.com.mx>
    GiGaX
    

  • Next message: Matias Rollan: "Re: learning sniffer skills"

    Relevant Pages

    • Re: Linux link monitoring tool
      ... do not need a sniffer. ... I need a program that will run as a daemon and monitor the health if ... > You can use tcpdump also, ... > The post originated from Linux Forum: ...
      (comp.os.linux.networking)
    • Re: allow user not root to tcpdump
      ... I need to allowed a user not root to make tcpdump in a server with ... When I try to use the sniffer I receive the error ...
      (comp.sys.sun.admin)
    • Re: learning sniffer skills
      ... I think you have to play a little bit with the tcpdump options. ... Have a look at the manpage for tcpdump. ... Florian ... > to read the sniffer output. ...
      (Security-Basics)
    • Re: learning sniffer skills
      ... On Thu, 9 Dec 2004, Carlos Mario Mora (c4y0) wrote: ... > to read the sniffer output. ... It is quite possible to make sense of content using -X in tcpdump: ... -X Print each packet in hex and ASCII. ...
      (Security-Basics)

  • Quantcast