Re: [tcpdump-workers] TCP/UDP Data Streams - Packet Reassembly

From: Guy Harris (guyat_private)
Date: Fri Dec 20 2002 - 11:15:23 PST

  • Next message: Ali: "RE: TCP/UDP Data Streams - Packet Reassembly"

    On Fri, Dec 20, 2002 at 07:39:09AM -0500, Paul Van Gurp wrote:
    > Just a question...why not get Ethereal...it is freeware, works great,
    > and keeps track of all sessions for you.  It is easy to use and does a
    > really nice job.  I don't know about exporting the data though.
    
    I do.
    
    It *won't* export the word attachment.  At best, it can reassemble the
    data streams on both sides of a TCP conversation and let you save one
    side, the other side, or both sides to a file; extracting attachments
    from mail, or extracting the file from an HTTP GET transaction, is left
    as an exercise for the user.
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Dec 24 2002 - 01:17:18 PST