Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] mpls |
|---|---|
| Date: | Thu, 14 Jun 2007 23:08:21 -0700 (PDT) |
Hello,
I need to sniff a link that uses mpls headers. Does
any one have some advice for doing this successfully?
snort can read the packets but it seems like snort
and tcpdump don't see mpls packets containiing IP/TCP
information.
Some captures are below. I updated tcpdump libpap and
snort
tcpdump version 3.9.5
libpcap version 0.9.5
snort version 2.6.1.5
These look like normal packets with 2 byte header
attached to me. Is there a way i can strip this off or
ignore it?
here's some examples of what i see
tcpdump -i eth1
21:16:06.515653 MPLS (label 7259, exp 0, [S], ttl
252), IP, length: 46
21:16:06.515656 MPLS (label 1302, exp 0, [S], ttl
253), IP, length: 46
tcpdump -x
21:16:24.308447 MPLS (label 1972, exp 0, [S], ttl
252), IP, length: 46
0x0000: 007b 41fc 4500 0028 0095 4000 7506
457d
21:16:24.308450 MPLS (label 1432, exp 0, [S], ttl
253), IP, length: 55
0x0000: 0059 81fd 4500 0033 c2c4 0000 7d11
8646
tcpdump -X
21:25:30.604609 MPLS (label 10491, exp 0, [S], ttl
253), IP, length: 46
0x0000: 028f b1fd 4500 0028 16b0 4000 7a06
cbb2 ....E..(..@.z...
21:25:30.604743 MPLS (label 100, exp 0, [S], ttl 253),
IP, length: 481
0x0000: 0006 41fd 4500 01dd 3732 0000 2411
253b ..A.E...72..$.%;
Ty
____________________________________________________________________________________
Sick sense of humor? Visit Yahoo! TV's
Comedy with an Edge to see what's on, when.
http://tv.yahoo.com/collections/222
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
| Previous by Date: | Re: [Snort-users] Sensor overload - Too much traffic for Snort box?, Matthew Watchinski |
|---|---|
| Next by Date: | Re: [Snort-users] mpls, Paul Melson |
| Previous by Thread: | Re: [Snort-users] Sensor overload - Too much traffic for Snort box?, Matthew Watchinski |
| Next by Thread: | Re: [Snort-users] mpls, Paul Melson |
| Indexes: | [Date] [Thread] [Top] [All Lists] |