pen-test
[Top] [All Lists]

Re: dissect TCP/IP flow

To: fake@mailinator.com
Subject: Re: dissect TCP/IP flow
From: Chris Eagle <cseagle@redshift.com>
Date: Sat, 21 Jul 2007 09:06:23 -0700
Cc: João Henrique Ferreira de Freitas <joaohf@gmail.com>, pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <5e01c29a0707201819g15add7d7j75488a366c37f367@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <1184964634.29441.1.camel@jhf-notebook> <5e01c29a0707201819g15add7d7j75488a366c37f367@mail.gmail.com>
Resent-date: Sat, 21 Jul 2007 12:31:52 -0600 (MDT)
Resent-from: pen-test-return-1078484659@securityfocus.com
Resent-message-id: <20070721183152.285A52379DC@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 2.0.0.5 (Windows/20070716)
wireshark is okay if you want to extract one stream at a time from many.

For multiple streams, you might try Chaosreader:
http://chaosreader.sourceforge.net/ or tcpflow:
http://www.circlemud.org/~jelson/software/tcpflow/

Each can split out all of the streams in a set of packets. Unfortunately
they do not seem to be actively maintained.

Chris


silky wrote:
> well what you want is a packet anaylser.
> 
> try wireshark: http://www.wireshark.org/
> 
> 
> 
> 
> On 7/21/07, João Henrique Ferreira de Freitas <joaohf@gmail.com> wrote:
>> Hello,
>>
>> Anybody have a good how to, tutorial or papers about dissect a TCP/IP
>> flow?
>>
>> The background is: I have a client/server application and need
>> decode/dissect the communication. The goal is make a tool to interact
>> with
>> the server application, send commands and request operations.
>>
>> How I make this? Its possible?
>>
>> Thanks.
>>
>> -- 
>> -------------------------------------------------------------
>> João Henrique Freitas - joaohf_at_gmail.com
>> Americana-SP-Brasil
>> BSD051283
>> LPI 1
>> http://paginas.terra.com.br/informatica/joaohf
>> http://www.livejournal.com/users/joaohf/
>>
>>
>> ------------------------------------------------------------------------
>> This List Sponsored by: Cenzic
>>
>> Swap Out your SPI or Watchfire app sec solution for
>> Cenzic's robust, accurate risk assessment and management
>> solution FREE - limited Time Offer
>>
>> http://www.cenzic.com/c/wf-spi
>> ------------------------------------------------------------------------
>>
>>
> 
> 


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>