Metasploit mailing list archives

pcaprub module


From: jeffs at speakeasy.net (jeffs)
Date: Mon, 06 Apr 2009 23:27:22 -0400

Got it.

I see now that the filter uses Berkeley packet filtering syntax.  Good.  
Is the screen output saved anywhere for later use or is it just existing 
for the session on the screen.  Can it be dumped do you think?

Thanks.

hdm wrote:
On Mon, 2009-04-06 at 23:15 -0400, jeffs wrote:
  
It seems to sniff http by default and I'm having difficulty killing
it.  Keeps saying type exit to exit but there is no prompt and I have
to either ctr-c kill it with many attempts or kill -9 it.

What is the syntax for filtering?  Anything I put in there just seems
to default to sniffing http traffic...
    


The kill bug is something we should look into; there are a few other
cases where that happens and its really annoying. The test/capture
module just sniffs http, thats it, its meant be an example you can
customize and not necessarily a useful module on its own.

-HD

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


  

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.metasploit.com/pipermail/framework/attachments/20090406/3de973ee/attachment.htm>


Current thread: