3.1 Airscanner Mobile Sniffer
3.1 Airscanner Mobile Sniffer
3.1 Airscanner Mobile Sniffer
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
your preferences. For example, if you are looking for traffic generated by the AIM<br />
protocol, which is used by AOL’s Instant Messenger, you can set up a filter to quickly<br />
parse all AIM data out of the captured data. This can also be done before the capture;<br />
however, post-capture filtering is recommended because it gives you the power to go<br />
back and review everything captured.<br />
To set up a filter before the capture, use the filter option as illustrated in Figure 9.2.<br />
This will open a filter setup window similar to Figure 9.4. To post the filter, use the filter<br />
option at the bottom of the Ethereal window<br />
In this example, we will create a filter for AIM and Quake. Quake is a multiplayer game<br />
whose mastery is an essential prerequisite for any competent security professional.<br />
However, if you are a network administrator, you might desire a way to periodically<br />
monitor your network for Quake packets to make sure no one has set up a rogue Quake<br />
server. To do this, perform the following steps:<br />
1. Click the Filter button.<br />
2. Type Quake in the Filter Name textbox.<br />
3. Click the Add Expression button.<br />
4. Scroll through the list of options and select Quake in the Field Name column<br />
and is present in the Relation column (see Figure 9.5).<br />
5. Click Accept.<br />
6. Click the New button to add the filter to the save list.<br />
7. Click Save to store this filter permanently.<br />
8. Click OK to use the filter.