1 |
Jake Moe wrote: |
2 |
> On 08/17/10 20:23, Dale wrote: |
3 |
> |
4 |
>> Adam Carter wrote: |
5 |
>> |
6 |
>>> Is this easy to do? I have no idea where to start except that |
7 |
>>> wireshark is installed. |
8 |
>>> |
9 |
>>> |
10 |
>>> Yep, start the capture with Capture -> Interfaces and click on the |
11 |
>>> start button next to the correct interface, then right click on one |
12 |
>>> of the packets that is to the yahoo box and choose Decode As set the |
13 |
>>> port and protocol then apply. You'll need to understand the semantics |
14 |
>>> of HTTP for it to be of much use tho. |
15 |
>>> |
16 |
>> You had me until the last part. No semantics here. lol May see if |
17 |
>> I can post a little and see if anyone can figure out what the heck it |
18 |
>> is doing. I'm thinking some crazy bug or something. Maybe checking |
19 |
>> for updates not realizing it's Kopete instead of a Yahoo program. |
20 |
>> |
21 |
>> Thanks. Post back what I find when it does it again. |
22 |
>> |
23 |
>> Dale |
24 |
>> |
25 |
>> :-) :-) |
26 |
>> |
27 |
>> |
28 |
> If you do try to send it back to us, you might want to limit what it's |
29 |
> capturing; Wireshark can get a *lot* of data quickly. |
30 |
> |
31 |
> For instance, if you know it's only communicating with a few servers, |
32 |
> after you click on "Capture --> Interfaces", click on the "Options" |
33 |
> button, and in the Capture Filter, put "host 98.136.48.110 or host |
34 |
> 98.136.42.25", which are the two servers you listed at the beginning of |
35 |
> this thread (cs210p2.msg.sp1.yahoo.com and rdis.msg.vip.sp1.yahoo.com). |
36 |
> Or you could assume that Yahoo are using the 98.136.0.0 network only for |
37 |
> this sort of thing, and use a filter of "net 98.136.0.0/16", which would |
38 |
> grab all traffic to or from any host with an IP starting with 98.136.x.x. |
39 |
> |
40 |
> Jake Moe |
41 |
> |
42 |
> |
43 |
|
44 |
I'll keep that in mind. I'm not sure when it will start this mess again |
45 |
tho. Sometimes it starts after a day or so, sometimes it is a week or so. |
46 |
|
47 |
Thanks. |
48 |
|
49 |
Dale |
50 |
|
51 |
:-) :-) |