From owner-freebsd-net@FreeBSD.ORG Wed Jun 11 20:20:43 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D42B41065680 for ; Wed, 11 Jun 2008 20:20:43 +0000 (UTC) (envelope-from tom@tomjudge.com) Received: from s200aog13.obsmtp.com (s200aog13.obsmtp.com [207.126.144.127]) by mx1.freebsd.org (Postfix) with SMTP id EBE918FC19 for ; Wed, 11 Jun 2008 20:20:42 +0000 (UTC) (envelope-from tom@tomjudge.com) Received: from source ([63.174.175.251]) by eu1sys200aob013.postini.com ([207.126.147.11]) with SMTP; Wed, 11 Jun 2008 20:20:41 UTC Received: from [172.17.3.47] (unknown [172.17.3.47]) by bbbx3.usdmm.com (Postfix) with ESMTP id 71251FD02E; Wed, 11 Jun 2008 20:01:46 +0000 (UTC) Message-ID: <48502F2C.7090505@tomjudge.com> Date: Wed, 11 Jun 2008 15:01:48 -0500 From: Tom Judge User-Agent: Thunderbird 2.0.0.14 (X11/20080505) MIME-Version: 1.0 To: Bill Moran References: <20080610120222.9e2760fe.wmoran@collaborativefusion.com> In-Reply-To: <20080610120222.9e2760fe.wmoran@collaborativefusion.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: R J , freebsd-net@freebsd.org Subject: Re: tcpdump/snort to capture chat sessions X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Jun 2008 20:20:43 -0000 Bill Moran wrote: > In response to R J : > >> I am trying to use tcpdump (or snort, but they are both behaving the same >> in this case) to capture all the lines or contents of an msn >> chat session, the actual conversation. I am getting partial output; i.e, >> I'll only get half of a sentence, and I don't see the rest of the lines. >> And ofcourse, alot of it seems to be hex or obfuscated html? >> >> What switches do I need to capture the entire lines of text? > > Don't know about snort, but with tcpdump use -s0 > This is a good start however you are not guaranteed to see the whole chat message in a single TCP packet. If you are looking for something more advanced you will have to write a program around pcap/bpf or similar to read the TCP stream. Tom J