[Snort-users] How can I view the packet payload if the packet is SMTP

Frank Knobbe fknobbe at ...652...
Wed Dec 11 07:41:08 EST 2002


On Wed, 2002-12-11 at 00:42, Atul Shrivastava wrote:
> I want to know that how can I view the captured packet payload if the
> packed is SMTP. Actually I have made a rule for Conternt Inspection
> for SMTP for some specific word, the sensor is also getting alerts but
> when I want to see the mail which it has captured then it shows a very
> hard to read mail. So I want a frontend which will act such that I can
> be able to read the packed payload according to the application in
> which the packet is made by the source station and I can also view the
> attachments if the Viewing station is having that required software to
> view that attachment. Can anyone help me in this regard.


This is a great idea. Why don't you write such a front end for us?
Please let us know when you release it.

Thanks,
Frank



PS: You weren't soliciting us to write one for you, were you?

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 305 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20021211/98c044e4/attachment.sig>


More information about the Snort-users mailing list