LinuxQuestions.org
Visit the LQ Articles and Editorials section
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 05-09-2005, 06:12 PM   #1
jrochamtz
LQ Newbie
 
Registered: Apr 2005
Location: México
Distribution: fedora
Posts: 12

Rep: Reputation: 0
msn sniffer


i'd like to know the available options for a msn messenger sniffer under linux. preferable in perl.

i have tried several, but i'd prefer if it creates a log with a file for each local ip address or something. i appreciate your attention. Thanks!
 
Old 05-15-2005, 06:56 PM   #2
a5an0
LQ Newbie
 
Registered: May 2005
Distribution: Debian, Ubuntu, OpenBSD (UNIX), Solaris 10 (UNIX), Fedora Core 3
Posts: 4

Rep: Reputation: 0
Its not Perl, but Ethereal is a great sniffer, especially if you need to do any analysis on traffic or individual packets. I havn't tried it for MSN, but it works great on AIM, as it sniff every packet going over the wires. You can also set up filters based on protocols, which should help keep your logs nice and clean.
 
Old 05-15-2005, 10:28 PM   #3
Gibsonist
Member
 
Registered: Mar 2004
Location: Meersburg (GER)
Distribution: Cygwin,RH 7.2 7.3, SuSe 6.4 8.2 9.1,TinyLinux, Debian Sarge, Knoppix 3.*, Knoppicilin, Knoppix STD
Posts: 191

Rep: Reputation: 30
I agree with a5an0

ethereal (tetherreal) work fine with IMs - tried it on MSN was very "interesting" specially with the proper filter set. Only problem were files that are transmitted as MSN encrypts these and it gives you some weird stuff.
But otherwise you can lit. see the chat nicely formatted like in the orig client
 
Old 05-17-2005, 01:04 PM   #4
jrochamtz
LQ Newbie
 
Registered: Apr 2005
Location: México
Distribution: fedora
Posts: 12

Original Poster
Rep: Reputation: 0
what i mean, is a daemon working and create a log for each internal ip addres.

Maybe it's not done now, and i have to find some one who modify the script i already have.

Thanks!!
 
Old 05-17-2005, 02:39 PM   #5
Gibsonist
Member
 
Registered: Mar 2004
Location: Meersburg (GER)
Distribution: Cygwin,RH 7.2 7.3, SuSe 6.4 8.2 9.1,TinyLinux, Debian Sarge, Knoppix 3.*, Knoppicilin, Knoppix STD
Posts: 191

Rep: Reputation: 30
Well why don't you scripped one?

All you probably need would be a daemon that watches your network for packages using the msg protocol (can't remember the name)
Perhaps this could be written as a extension for iptables (similar to snort inline)
this again calls the sniffer
as soon as the connection is dropped (no more of these packages)
parse the sniffers log and create the different log files

Doesnt sound to hard - does it. My advice start at the back in parsing the (t)ethereal log file.

If you get something working or need help with the (t)ethereal let me know

PS I assume with internal IP you mean the local IPs in your LAN
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Which is the best sniffer? abefroman Linux - Security 3 05-07-2005 03:56 AM
wireless sniffer barrythai Linux - Software 1 02-28-2005 02:41 AM
sniffer detection? groovin Linux - Security 2 04-14-2004 12:58 PM
MSN to break Linux connection used with msn I think read maximalred Linux - General 1 08-24-2003 12:40 PM
CAN WINE be made to run MSN 8 and MSN Messager maximalred Linux - Software 3 08-24-2003 07:56 AM


All times are GMT -5. The time now is 05:46 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration