Archive

Archive for April, 2009

How to Monitor Internet Traffic with Colasoft Packet Sniffer

April 27th, 2009 Colasoft 10 comments

Internet traffic is the flow of data around the Internet. It includes web traffic, which is the amount of that data that is related to the World Wide Web, along with the traffic from other major uses of the Internet, such as electronic mail and peer-to-peer networks.

In case we want to monitor internet traffic generated or is generating in LAN, here is a detailed process how we can monitor internet traffic with Colasoft Packet Sniffer – Capsa.

We must make sure the packet sniffer software is correctly implemented so we can capture all the traffic in LAN, if you don’t know how to do it, please make sure you read how to implement a packet sniffer.

First let’s launch a new project with Colasoft Packet Sniffer, then do some online activities, such as chatting, browsing a website, sending and receiving emails, downloading some files. All these activities will generate different kinds of internet traffic. We may keep the project running to continuously monitor internet traffic or stop the project to do some analysis.

To monitor internet traffic, we’d better first select the “Internet Addresses” in the “Explorer” on the left window:

Monitor Internet Traffic Screenshot1

Monitor Internet Traffic Screenshot1

We can see that all the internet addresses are listed by countries, to monitor internet traffic of a specific country, we just need click on it; If we want to monitor internet traffic of a specific IP address within one country, we need to expand the country node and select the IP address in it.

Also we can monitor internet traffic aggregated or internet traffic in real-time

Monitor Internet Traffic Screenshot2

Monitor Internet Traffic Screenshot2

To view what online activities have generated or are generating internet traffic, we need to use the “Protocols” Tab.

Monitor Internet Traffic Screenshot1

Monitor Internet Traffic Screenshot1

We can see there are protocols which separately stand for different internet activities:

HTTP – Website browsing
MSN – online chatting with Live Messenger
POP3 – Email
HTTPS – Website browsing via a secure link
QQ- online chatting with QQ
DNS – Domain Name System

Categories: Tips & How-tos Tags: , ,

How to Monitor http Traffic with Packet Sniffer

April 23rd, 2009 Colasoft 2 comments

Hypertext Transfer Protocol (HTTP) is an application-level protocol for distributed, collaborative, hypermedia information systems. Its use for retrieving inter-linked resources led to the establishment of the World Wide Web.

In order to monitor http traffic, we will need a packet sniffer (or a protocol analyzer) software. Here is a detail process how we can monitor http traffic in LAN with Colasoft Packet Sniffer – Capsa.

Again let’s launch Colasoft Packet Sniffer and start a new project. Don’t forget one thing, we have to deploy the packet sniffer to the mirror port of the core switch in order to monitor all http traffic in LAN, if not, we can only monitor http traffic of our own computer.

Then let’s start browsing a website, for example, www.colasoft.com, to generate some http traffic. Now let’s get back to the packet sniffer and see if there is http traffic. OK, we can see the packet sniffer has already captured some http traffic in the “Protocols” Tab

Monitor http Traffic Screenshot 1

Monitor http Traffic Screenshot 1

We can see both the aggregated http traffic since start capturing and the real-time http traffic in this tab.

If we want to do a deeper analysis on http traffic, we will need to use the “Locate” function to locate http protocol in the Explorer to let the packet sniffer display only the data that is http protocol. Right click on the protocol and select “Locate Explorer Node” in the pop-up menu.

Locate Explorer Node

Locate Explorer Node

If we want to know who are using http protocol and what they are actually browsing, we are going to use two tabs, the “Endpoints” Tab and “Logs” Tab.

Let’s see who are using http protocol:

Who is Using http Protocol

Who is Using http Protocol

And what they are actually browsing:

Monitor http Traffic Screenshot 4

Monitor http Traffic Screenshot 4

Categories: Tips & How-tos Tags: , ,

Tips: How to Sniff All Images of a Webpage

April 15th, 2009 Colasoft 12 comments

In case we want to sniff all images of a webpage, here is a detailed process how we can do it with Colasoft Capsa’s “Logs” feature. I will take the CNN.com home page as an example.

Step 1. Open Log Settings

Log settings allows us to set up some conditions or exceptions whether or not record some logs in the Logs tab. If we want to display just images in the Logs tab, we must enable the HTTP Log conditions.

How to Sniff Images Screenshot 1

How to Sniff Images Screenshot 1

Step 2. Enable Http Log Conditions

We must tick before Conditions to enable it

How to Sniff Images Screenshot 2

How to Sniff Images Screenshot 2

Step 3. Input “Image” into Content Type

On the right hand, lets’ input the content type in order to filter contents

How to Sniffer Images Screenshot 3

How to Sniffer Images Screenshot 3

Here is an explanation of Content Type

How to Sniff Images Screeshot 4

How to Sniff Images Screeshot 4

Step 4. “OK” to Activate the Setting

Now we’ve done with the Log Settings, let’s see whether we can sniff all images of CNN.com index page. First of all, let’s start capturing with Colasoft Capsa, then let’s input the URL into the address bar and start browsing.

Results start showing in the Logs Tab – Http Request Option, we can see all results are in image formats. We have successfully sniffed all the images on this webpage.

How to Sniff Images Screeshot 5

How to Sniff Images Screeshot 5

To view the image, we can click on the record, and it will be shown in a browser.

How to Sniff Images Screenshot 6

How to Sniff Images Screenshot 6