Re: Packet analysis and protocol analysis

From: Carlos Fernandez Sanz (cfs-sec-basics_at_securityfocus.com)
Date: 07/27/05

  • Next message: Payton, Zack: "RE: Packet analysis and protocol analysis"
    Date: Wed, 27 Jul 2005 13:27:04 +0200
    To: security-basics@securityfocus.com
    
    

    The output varies from protocol to protocol. I suggest you start with a
    filter that captures only the traffic from/to your own box, and only for
    one protocol. Then play a bit, i.e. if you start with HTTP then browse
    some pages, if you use MSN then chat a bit...

    If you want to write your own sniffer of something, start by looking at
    some source code.

    For MSN, I wrote a small sniffer which is quite easy to understand (in
    code), you can get it here if you want :
    http://sourceforge.net/projects/im-snif/

    Take a look at it. Nothing fancy but you can learn from it.

    Ramki B wrote:

    >I am trying to understand network packet analysis and exprimenting with
    >Etherreal. I have a captured file and i do not to understand the output , is
    >there any references in can look into for packet analysis and protocol
    >analysis?
    >
    >Thanks...
    >
    >
    >
    >
    >
    >


  • Next message: Payton, Zack: "RE: Packet analysis and protocol analysis"

    Relevant Pages

    • Re: Some free utilities for Java, with Hebrew support.
      ... the protocol clearly cannot be ... Open source means that some source code is available for everyone. ... GPL) or patents more or less by definition. ...
      (comp.lang.java.programmer)
    • Re: news link in OE6 wont work with x-usc: prefix
      ... Take a look at the File associations for URL:News Protocol and URL:NNTP ... Looking at its source code, that is exactly how it appears in the ... no extra characters or prefix. ... Where does the mysterious x-usc: prefix come from, why, and how can it ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: how to build a chat server in c
      ... Take a look at the source code to 'ircd', ... you have a specification for the protocol you are using? ... IRC.) ...
      (comp.unix.programmer)
    • Re: Is open sourcing a good idea?
      ... I used the word 'fork' to ... However it wasn't source code that they forked. ... Protocol specifications can be every bit as much open source as code. ... You all think I'm paranoid, ...
      (comp.programming)
    • Re: Some free utilities for Java, with Hebrew support.
      ... the protocol clearly cannot be ... Open source means that some source code is available for everyone. ... GPL) or patents more or less by definition. ...
      (comp.lang.java.programmer)