From owner-freebsd-net@FreeBSD.ORG Wed Jun 11 20:42:22 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id EFC96106564A for ; Wed, 11 Jun 2008 20:42:22 +0000 (UTC) (envelope-from wmoran@collaborativefusion.com) Received: from mx00.pub.collaborativefusion.com (mx00.pub.collaborativefusion.com [206.210.89.199]) by mx1.freebsd.org (Postfix) with ESMTP id 947818FC23 for ; Wed, 11 Jun 2008 20:42:22 +0000 (UTC) (envelope-from wmoran@collaborativefusion.com) Received: from vanquish.ws.pitbpa0.priv.collaborativefusion.com (vanquish.ws.pitbpa0.priv.collaborativefusion.com [192.168.2.162]) (SSL: TLSv1/SSLv3,256bits,AES256-SHA) by wingspan with esmtp; Wed, 11 Jun 2008 16:42:21 -0400 id 00056428.485038AD.0001210C Date: Wed, 11 Jun 2008 16:41:25 -0400 From: Bill Moran To: Tom Judge Message-Id: <20080611164125.ac5b7312.wmoran@collaborativefusion.com> In-Reply-To: <48502F2C.7090505@tomjudge.com> References: <20080610120222.9e2760fe.wmoran@collaborativefusion.com> <48502F2C.7090505@tomjudge.com> Organization: Collaborative Fusion X-Mailer: Sylpheed 2.4.8 (GTK+ 2.12.9; i386-portbld-freebsd7.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Cc: R J , freebsd-net@freebsd.org Subject: Re: tcpdump/snort to capture chat sessions X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Jun 2008 20:42:23 -0000 In response to Tom Judge : > Bill Moran wrote: > > In response to R J : > > > >> I am trying to use tcpdump (or snort, but they are both behaving the same > >> in this case) to capture all the lines or contents of an msn > >> chat session, the actual conversation. I am getting partial output; i.e, > >> I'll only get half of a sentence, and I don't see the rest of the lines. > >> And ofcourse, alot of it seems to be hex or obfuscated html? > >> > >> What switches do I need to capture the entire lines of text? > > > > Don't know about snort, but with tcpdump use -s0 > > > This is a good start however you are not guaranteed to see the whole > chat message in a single TCP packet. If you are looking for something > more advanced you will have to write a program around pcap/bpf or > similar to read the TCP stream. He could use wireshark. -- Bill Moran Collaborative Fusion Inc. http://people.collaborativefusion.com/~wmoran/ wmoran@collaborativefusion.com Phone: 412-422-3463x4023