Solved

Help with capturing network packet

Posted on 2004-03-30
8
262 Views
Last Modified: 2010-03-18
I run a priviledged BNC service (for IRC) and I would like to monitor the contents of my users. For example, I was sent an email by the IRC network asking for evidence in which a user of my BNC service has spammed in the network. I have heard there is a command called 'tcpdump' which is able to listen and log all network data coming to and from any interface. I have tried it and it logs mostly garbage packets which I do not require and uses up a lot of disk space. I would like to know the command to listen to only certain keywords of phrases and log THAT data in, if possible, and if not then what software out there could I use for this purpose?
0
Comment
Question by:rudyzainal
8 Comments
 
LVL 18

Expert Comment

by:liddler
ID: 10712477
tcpdump has lots of option for narrowing the output down, you can then pipe the output via egrep to match it against certain keywords, before writing it to a file, this should reduce the disk space, and get rid of lots of the rubbish. take a look at the tcpdump manpage.
0
 
LVL 9

Accepted Solution

by:
Alf666 earned 50 total points
ID: 10712499
tcpdump is a network diagnostic tool. It will not log packets content (per design).

For a diagnostic, you can use ethereal or tethereal (the terminal version).

But for doing exactly what you want, you'll have to look inside the hackers section.
It's very bad practise to sniff your users emails or irc sessions.
0
 

Expert Comment

by:givetoprakash
ID: 10712596
There is some programs to capture the packets & it contents .

if you want that programs contact me
<email address removed by sirbounty>

0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 17

Expert Comment

by:owensleftfoot
ID: 10712703
ngrep http://ngrep.sourceforge.net/ is a program like ordinary grep for searching for regular expressions/phrases but ngrep works on network packets instead of files.
0
 
LVL 14

Expert Comment

by:pablouruguay
ID: 10713060
sniffit or ethereal...

have a gui interfaces to discrimine garbage packets
0
 

Author Comment

by:rudyzainal
ID: 10717236
liddler
I have read the MAN page but the options are way too vast for me to actually pinpoint for the results i wanted.

Alf666
It IS bad practice, but before they acually are given a bouncer they have to agree on the policies set which state that all communications to and from the server will be assessed and logged as and when necessary, as in this case whereby this certain user has been accused of breaching. I cannot terminate this user's account due to flamboyant accusations without any proof and as such he was put in (and duely notified of) what's called 'monitor accounts', in which i need this information from here. :)

givetoprakash : your email was removed. You might wish to get in touch with me via email. My email is posted on my profile.

owensleftfoot
thanks ill take a look at it

pablouruguay
my box is not local, its located on a datacenter, and as such GUI isnt that much of an option.
0
 
LVL 18

Expert Comment

by:liddler
ID: 10721018
As Alf666 says ethereal is an excellent tool, hava a look at that
0

Featured Post

Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question