Metasploit mailing list archives

Re: Question on Sniffer Extension


From: ricky-lee birtles <mr.r.birtles () gmail com>
Date: Tue, 7 Sep 2010 10:57:20 +0100

to quote HD on a very smiler question:

"The filtering language in the extension is somewhat tedious right now
(raw BPF asm, not nice syntax yet), but this is something we hope to
improve on."

Regards,
-- Mr R Birtles



On 7 September 2010 05:06, John Nash <rootsecurityfreak () gmail com> wrote:
Hello List,
Is it possible to add filters in the sniffer extension?
I tried remote sniffing, the major issue I am hitting is that most of the
traffic is local ARP and other broadcast packets. These are good to
understand which hosts are up in a passive way, but nothing more.
I would want to add specific filters like "tcp.port == 21" etc. to be able
to fine grained control on what i capture.
I could find this in the extension options anywhere ... is it somewhere
else?
thx
jn
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: