View Issue Details

IDProjectCategoryView StatusLast Update
0000061Kali LinuxNew Tool Requestspublic2013-08-09 21:36
Reportersaberzaid Assigned Tomuts  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionfixed 
Platformx86OSKaliOS Version1.0
Summary0000061: Please add xplico as a package.
Description

The goal of Xplico is extract from an internet traffic capture the applications data contained.
For example, from a pcap file Xplico extracts each email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn’t a network protocol analyzer. Xplico is an open source Network Forensic Analysis Tool (NFAT).
Xplico is released under the GNU General Public License and with some scripts under Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported (CC BY-NC-SA 3.0) License. For more details see License.
Features

Protocols supported: HTTP, SIP, IMAP, POP, SMTP, TCP, UDP, IPv6, …;
Port Independent Protocol Identification (PIPI) for each application protocol;
Multithreading;
Output data and information in SQLite database or Mysql database and/or files;
At each data reassembled by Xplico is associated a XML file that uniquely identifies the flows and the pcap containing the data reassembled;
Realtime elaboration (depends on the number of flows, the types of protocols and by the performance of computer -RAM, CPU, HD access time, …-);
TCP reassembly with ACK verification for any packet or soft ACK verification;
Reverse DNS lookup from DNS packages contained in the inputs files (pcap), not from external DNS server;
No size limit on data entry or the number of files entrance (the only limit is HD size);
IPv4 and IPv6 support;
Modularity. Each Xplico component is modular. The input interface, the protocol decoder (Dissector) and the output interface (dispatcher) are all modules;
The ability to easily create any kind of dispatcher with which to organize the data extracted in the most appropriate and useful to you;

the site says it can install and free to use in any linux distro

download:

http://www.xplico.org/download

Activities

Viss

Viss

2013-04-24 00:44

reporter   ~0000398

The addition of this package also requires that the current distro of Kali get libc6 2.14, which is a package dependency.

th3flyboy

th3flyboy

2013-04-24 15:10

reporter   ~0000399

This looks very useful for pcap analysis and network forensics.

muts

muts

2013-08-09 21:36

reporter   ~0000670

Xplico added to repositories.

Issue History

Date Modified Username Field Change
2013-03-13 17:52 saberzaid New Issue
2013-03-16 00:32 muts Summary xplico => Please add xplico as a package.
2013-03-16 00:32 muts Description Updated
2013-04-24 00:44 Viss Note Added: 0000398
2013-04-24 15:10 th3flyboy Note Added: 0000399
2013-08-09 21:36 muts Note Added: 0000670
2013-08-09 21:36 muts Status new => closed
2013-08-09 21:36 muts Assigned To => muts
2013-08-09 21:36 muts Resolution open => fixed