Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Newbies » need full packet payload, not just header

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

need full packet payload, not just header


Posted by jmh on March 16, 2005 06:44:52

Hi,

I used snort to sniff a HTTP request for a particular web page and also the resonse to the request. I was expecting to see all the HTML source code of the web page in the HTTP response packet(s). The response packet was there and it contained a load of HTTP stuff but the actual HTML source code e.g. "This the is body of my web page" wasn't visible in the packet payload, evem with the Application Layer, ascii output etc. options turned on. Should I be able to see the HTML source code in the packets? If so, is there an option I need to specify?

Many thanks,

jmh

Posted by roesch on March 19, 2005 17:23:16

It should be in there, what output options do you have enabled? Which version of Snort on which platform? Have you thought about using tagging to record follow-on packets on the same session?

-Marty