Metasploit mailing list archives
Re: Question on Sniffer Extension
From: ricky-lee birtles <mr.r.birtles () gmail com>
Date: Tue, 7 Sep 2010 10:57:20 +0100
to quote HD on a very smiler question: "The filtering language in the extension is somewhat tedious right now (raw BPF asm, not nice syntax yet), but this is something we hope to improve on." Regards, -- Mr R Birtles On 7 September 2010 05:06, John Nash <rootsecurityfreak () gmail com> wrote:
Hello List, Is it possible to add filters in the sniffer extension? I tried remote sniffing, the major issue I am hitting is that most of the traffic is local ARP and other broadcast packets. These are good to understand which hosts are up in a passive way, but nothing more. I would want to add specific filters like "tcp.port == 21" etc. to be able to fine grained control on what i capture. I could find this in the extension options anywhere ... is it somewhere else? thx jn _______________________________________________ https://mail.metasploit.com/mailman/listinfo/framework
_______________________________________________ https://mail.metasploit.com/mailman/listinfo/framework
Current thread:
- Question on Sniffer Extension John Nash (Sep 06)
- Re: Question on Sniffer Extension ricky-lee birtles (Sep 07)
- Re: Question on Sniffer Extension HD Moore (Sep 07)