21.11.2012 Views

3.1 Airscanner Mobile Sniffer

3.1 Airscanner Mobile Sniffer

3.1 Airscanner Mobile Sniffer

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

your preferences. For example, if you are looking for traffic generated by the AIM<br />

protocol, which is used by AOL’s Instant Messenger, you can set up a filter to quickly<br />

parse all AIM data out of the captured data. This can also be done before the capture;<br />

however, post-capture filtering is recommended because it gives you the power to go<br />

back and review everything captured.<br />

To set up a filter before the capture, use the filter option as illustrated in Figure 9.2.<br />

This will open a filter setup window similar to Figure 9.4. To post the filter, use the filter<br />

option at the bottom of the Ethereal window<br />

In this example, we will create a filter for AIM and Quake. Quake is a multiplayer game<br />

whose mastery is an essential prerequisite for any competent security professional.<br />

However, if you are a network administrator, you might desire a way to periodically<br />

monitor your network for Quake packets to make sure no one has set up a rogue Quake<br />

server. To do this, perform the following steps:<br />

1. Click the Filter button.<br />

2. Type Quake in the Filter Name textbox.<br />

3. Click the Add Expression button.<br />

4. Scroll through the list of options and select Quake in the Field Name column<br />

and is present in the Relation column (see Figure 9.5).<br />

5. Click Accept.<br />

6. Click the New button to add the filter to the save list.<br />

7. Click Save to store this filter permanently.<br />

8. Click OK to use the filter.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!