Mastering Xplico
In this recipe, we will use Xplico. Xplico is an Internet traffic capture tool that has the ability to capture data from many different applications including FTP, e-mail, VoIP, and many more. Xplico is also useful as a Network Forensic Analysis Tool (NFAT).
Getting ready
The following requirements need to be fulfilled:
You will need an Internet or intranet connection to complete this recipe
You will also need SIP or PBX devices on your network
How to do it...
Let's begin by installing Xplico:
Open a terminal window and update your local repositories:
apt-get update
Next, run the install command for Xplico:
apt-get install xplico
Xplico will be placed in the BackTrack | Digital Forensics | Forensic Analysis menu.
Open a terminal window and navigate to the folder containing Xplico:
cd /opt/xplico/bin
Launch Xplico to reveal its help file.
Finally, we will execute our command to decode conversations in real time:
./xplico -m rltm -i eth0
-m
: This option allows us to set our mode....