Results 1 to 2 of 2
  1. #1
    Newbie
    Join Date
    May 2012
    Posts
    1

    Default Extracting messages in NetworkMiner

    Ok so im pretty new to network miner. basically, i have a cap file, and i want to analyse the contents of this file. So far with wireshark, ive managed to download a whole lot of images/ css files for a site that someone has been on, but i know there is more inside, such as messages 2 people have been senduing to eachother. With the keyword search in NetworkMiner, i have been able to pull up short sections of some of the messages, but i have not been able to see the full messages. I also know attachments have been sent.

    I have the Source host ip address and the Destination host ip address, and i also have the username of the person who has been sending the information out (as its one of the users of a computer)...

    It shows the person has been on myspace.com and aussiemail.com.au, so this might be where they are sending the messages from, but they could be using something else, im not sure.

    Is there any way, either by using networkminer, or any similar tool, that i can view all the messages that these 2 people have been sending to each other?

    I would really appreciate it.

  2. #2
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,682

    Default

    I'd try wireshark.

    Just open up the capture file, add a filter on only the IPs you are interested in (you will have to learn the syntax)

    Then find the relevent tcp streams and click on "View TCP Stream"
    You'll see a bunch of jibberish for the binary data, but usually you can see enough in the clear to see whats going on.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2