LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-27-2007, 02:41 PM   #1
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Rep: Reputation: 15
capturing packets of tools such as bearshare,limewire,Ares


i friends,

what tool can i used to capture packets of p2p clients such as bearshare,limewire,Ares.

i tried tcpdump but i really did not understand it. what exactly am i supporse to watch out for. Any help would be appreciated.

Thanks in Advance.
 
Old 06-27-2007, 02:47 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
tcpdump is still the right tool to capture traffic whether you understand it or not you can also capture the data in wireshark, which is realistically probably what you actually want to hear.

in terms of what you're looking out for... well you're the one trying to capture traffic, you tell us what you want to look out for... why are you doing it?
 
Old 06-27-2007, 05:29 PM   #3
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Original Poster
Rep: Reputation: 15
Thanks for the reply, i am really new to tcpdump. i want to capture packet of a particular p2p client. what do i watch out for. THANKS
 
Old 06-28-2007, 02:17 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well in wireshark just filter with an expression like "ip.addr == a.b.c.d" to filter after capture. or use an input filter on wireshark or tcpdump of somethign like "host a.b.c.d". still short on details of what you want to get out of this though. i doubt you'll be able to make much sense of the raw ip data...
 
Old 06-28-2007, 03:11 PM   #5
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Original Poster
Rep: Reputation: 15
Thanks for for reply acid_kewpie. let me give you a full load-down of exactly what i want to acheive. You see, recently my network has really been granded by users who are constantly using p2p clients such as Bearshare, Imesh, Ares, etc.

How ever i have been doing a lot of research on this 2p2 clients and i found this site http://www.lowth.com/rope/BlockingGnutella that describes how i could patch my kernel and iptables with a module called rope and then successfully block 2p2 clients. pls take a look at this, http://www.lowth.com/rope/BlockingBittorrent. from this you will note that the packet of bittorrent was identified.

Secondly,same go for p2p clients that use Gnutella protocol. they are identified by this strings GNUTELLA CONNECT/digit(s).digit(s)\r\n

The main problem now is i want to write a rope script to block Ares and i need to capture its packets just the same way bittorrent packets was captured and used to block it.

Thanks
 
Old 06-28-2007, 04:04 PM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
ok, well you don't block the program, you block the protocol, i.e. gnutella, bittorrent etc..., so the provided example in that link stands.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Capturing, modifying and injecting packets flukebox Linux - Networking 2 07-03-2007 08:07 AM
Capturing packets from my WAN/Router {O_o} Linux - Security 4 10-12-2005 04:56 PM
VoIP Packets capturing in linux fastian Linux - Networking 1 03-25-2005 11:34 AM
capturing ethernet packets shrike_912 Programming 5 08-02-2004 01:46 PM
Capturing packets in ethereal as non-root user? maxor Linux - Software 6 08-27-2003 03:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration