The simplest way would be to capture the traffic with <something>*,
then reconstitute the TCP sessions in Ethereal (Analyze --> Follow TCP
stream). Of course you could do the same for AIM, but the sniffer I
mentioned earlier is very good at organizing and cleaning up data. You
do not need this for pop, or imap, or irc - of course, as long as they
do not run over TLS ...
Stef
*where something = tethereal, windump, tcpdump, etc.
On Fri, 7 Jan 2005 16:30:25 +0100, Maxime Breitung
<maxime.breitung@xxxxxxxxx> wrote:
> Thanks,
> And have you the same form irc ??
>
> And how can y reconstitute a mail ?? pop and imap ?
> Can I capture with tethereal, and do a live recontitution ???
>
> On Fri, 7 Jan 2005 09:03:25 -0600, Stef <stefmit@xxxxxxxxx> wrote:
> > Not what you've asked for (i.e. utilizing tethereal for this), but if
> > the objective is AIM messages, I would advise you to try:
> >
> > http://freshmeat.net/projects/aimsniff/
> >
> > I have been very pleased with its capabilities ...
> >
> > HTH,
> > Stef
> >
> > On Thu, 6 Jan 2005 17:49:23 +0100, nimp arf <nimp54@xxxxxxxxx> wrote:
> > > Hi,
> > >
> > > I wan't to write a script, to live capture aim packets.
> > >
> > > => tethereal | grep message
> > >
> > > How can i do that ???
> > > The script must run all the time and log into screen or files. But a
> > > just wan't aim.messages and aim.users.
> > >
> > > Is it possible ??
> > > Thanks and sorry for my English.