Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 5.13 How can I Up: 5 Getting Fancy Previous: 5.11 Is it possible

5.12 How can I use Snort to log HTTP URLs or SMTP traffic?

It can be done with Snort, but you might find it faster to use mailsnarf and urlsnarf from Dug Song's dsniff package. Dsniff is available from:

http://www.monkey.org/~dsong/dsniff/

You can get a win32 port of dsniff at:

http://www.datanerds.net/~mike/dsniff.html