Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Yahoo and strange traffic.
Date: Tue, 17 Aug 2010 11:26:40
Message-Id: 4C6A71CE.7080609@gmail.com
In Reply to: Re: [gentoo-user] Yahoo and strange traffic. by Jake Moe
1 Jake Moe wrote:
2 > On 08/17/10 20:23, Dale wrote:
3 >
4 >> Adam Carter wrote:
5 >>
6 >>> Is this easy to do? I have no idea where to start except that
7 >>> wireshark is installed.
8 >>>
9 >>>
10 >>> Yep, start the capture with Capture -> Interfaces and click on the
11 >>> start button next to the correct interface, then right click on one
12 >>> of the packets that is to the yahoo box and choose Decode As set the
13 >>> port and protocol then apply. You'll need to understand the semantics
14 >>> of HTTP for it to be of much use tho.
15 >>>
16 >> You had me until the last part. No semantics here. lol May see if
17 >> I can post a little and see if anyone can figure out what the heck it
18 >> is doing. I'm thinking some crazy bug or something. Maybe checking
19 >> for updates not realizing it's Kopete instead of a Yahoo program.
20 >>
21 >> Thanks. Post back what I find when it does it again.
22 >>
23 >> Dale
24 >>
25 >> :-) :-)
26 >>
27 >>
28 > If you do try to send it back to us, you might want to limit what it's
29 > capturing; Wireshark can get a *lot* of data quickly.
30 >
31 > For instance, if you know it's only communicating with a few servers,
32 > after you click on "Capture --> Interfaces", click on the "Options"
33 > button, and in the Capture Filter, put "host 98.136.48.110 or host
34 > 98.136.42.25", which are the two servers you listed at the beginning of
35 > this thread (cs210p2.msg.sp1.yahoo.com and rdis.msg.vip.sp1.yahoo.com).
36 > Or you could assume that Yahoo are using the 98.136.0.0 network only for
37 > this sort of thing, and use a filter of "net 98.136.0.0/16", which would
38 > grab all traffic to or from any host with an IP starting with 98.136.x.x.
39 >
40 > Jake Moe
41 >
42 >
43
44 I'll keep that in mind. I'm not sure when it will start this mess again
45 tho. Sometimes it starts after a day or so, sometimes it is a week or so.
46
47 Thanks.
48
49 Dale
50
51 :-) :-)