We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

Help with capturing network packet

rudyzainal
rudyzainal asked
on
Medium Priority
294 Views
Last Modified: 2010-03-18
I run a priviledged BNC service (for IRC) and I would like to monitor the contents of my users. For example, I was sent an email by the IRC network asking for evidence in which a user of my BNC service has spammed in the network. I have heard there is a command called 'tcpdump' which is able to listen and log all network data coming to and from any interface. I have tried it and it logs mostly garbage packets which I do not require and uses up a lot of disk space. I would like to know the command to listen to only certain keywords of phrases and log THAT data in, if possible, and if not then what software out there could I use for this purpose?
Comment
Watch Question

Commented:
tcpdump has lots of option for narrowing the output down, you can then pipe the output via egrep to match it against certain keywords, before writing it to a file, this should reduce the disk space, and get rid of lots of the rubbish. take a look at the tcpdump manpage.
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION
There is some programs to capture the packets & it contents .

if you want that programs contact me
<email address removed by sirbounty>

ngrep http://ngrep.sourceforge.net/ is a program like ordinary grep for searching for regular expressions/phrases but ngrep works on network packets instead of files.
CERTIFIED EXPERT
Top Expert 2006

Commented:
sniffit or ethereal...

have a gui interfaces to discrimine garbage packets

Author

Commented:
liddler
I have read the MAN page but the options are way too vast for me to actually pinpoint for the results i wanted.

Alf666
It IS bad practice, but before they acually are given a bouncer they have to agree on the policies set which state that all communications to and from the server will be assessed and logged as and when necessary, as in this case whereby this certain user has been accused of breaching. I cannot terminate this user's account due to flamboyant accusations without any proof and as such he was put in (and duely notified of) what's called 'monitor accounts', in which i need this information from here. :)

givetoprakash : your email was removed. You might wish to get in touch with me via email. My email is posted on my profile.

owensleftfoot
thanks ill take a look at it

pablouruguay
my box is not local, its located on a datacenter, and as such GUI isnt that much of an option.

Commented:
As Alf666 says ethereal is an excellent tool, hava a look at that
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.