- Performance improved
- nDPI updated
- IRC bug fixed
- HTTP bug fixed
- VoIP (SIP, RTP) bug fixed
- FTP bug fixed
- changed the FaceBook DB tables
- Null/Loopback dissector
- Cisco HDLC dissector
- Libero.it and RossoAlice WebMail decoding
- Yahoo messenger, Web and Mobile (Beta version)
- Dig using file signatures (for unknown flows)
A special thanks to:
- Telecom Italia for its WebMail service Alice
- Italiaonline for its WebMail service Libero
- Yahoo for its Messenger (Web and for Android)
… thank you for not using encryption in the [users] communications.
- nDPI integration
- performace improved
- FTP dissector improved
- Added the prism dissector
- CLI execution bug fixed
- PCAP-over-IP SSL encryption
- IRC dissector improved
- File reconstruction from Fragmented Payloads improved
- FaceBook Chat updated
- FaceBook Message (partial)
- HTTP without initial packets (packets lost)
- RTP dissector improved
- PCAP2WAV, RTP2WAV interface added
Xplico 1.0.0 is now available!
- SQLite dispatcher performance improved
- added the PPI dissector
- added the syslog dissector
- added “Bogus IP length” correction with checksum verification disabled
- new Facebook Chat dissector for the new Facebook chat protocol
- SIP dissector improved
- IMAP dissector improved and bugs fixed
- DNS dissector PIPI improved
- Yahoo Webmail bugs fixed
- Live/Hotmail WebMail Spanish version
- GeoMap improved
Xplico Repository (Ubuntu 11.04 or higher)
To install Xplico in your Ubuntu Server or in your Desktop now you can use the official Xplico repository. With four simple steps you can have Xplico running and updated.
sudo bash -c 'echo "deb http://repo.xplico.org/ $(lsb_release -s -c) main" >> /etc/apt/sources.list'
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 791C25CE
sudo apt-get update
sudo apt-get install xplico
- Stack Overflow users.
- Erika Noerenberg for her analysis in the post “Brief overview of 4 NFATs”
- Victor Oppleman to suggest us to add PCap-over-IP
This version introduces improvement on Webmail sniffing/decoding and the language localization.
- upgraded the XI to Cakephp 1.3
- added the ICMPv6 dissector
- Ethernet dissector improved (for ICMPv6)
- one of two Xplico’s deadlock is solved
- fixed the communication bug between xplico and the manipulators
- SDP dissector bug fixed
- SIP and TCP dissectors improved
- WebMail manipulator and all Python3 scripts improved (ready to new webmail entry… see pol 😉 )
- added pcap file name on CLI report
- capture modules log improved
- new GeoIP version: 1.4.8
- added IPv6 Hop-by-Hop options
- Xplico and all Manipulators with dual stack (IPv4, IPv6)
- XI language localization (each fix is well come): Arabic, Chinese, German, English, French, Hindi, Italian, Japanese, Portuguese, Russian, Spanish, Turkish
- DNS bug fixed
- added the MDNS dissector
- added AOL WebMail
- added Yahoo! WebMail
- added Yahoo! Mail for Andorid Mobile
- added Gmail
- briaeros007 (member of the forum) for his test about IPv6 functionality on Xplico’s applications
- James Fisher, he has found and fixed a bug in the HTTP dissector
This version introduces l7-patterns classifier for all flows not decoded, also there is the improvement of the real time acquisition, new features for the XI (Xplico Interface) and many bugs fixes.
- l7-patterns for all flows/protocols not decoded by xplico
- Xplico Interface (XI) improved
- python3 porting of many scripts
- realtime capture module improved
- facebook chat realtime view
- UTC/localtime bug fixes
- l2tp dissector bug fixes
- cli and lite dispatchers bug fixes
- telnet dissector bug fixes
- trigcap bug fixes
- new script named session_mng.pyc to facilitate the creation of new case and/or new session from command line
We thank naif for his support and his availability.
The decoding performance are:
- from command line: 5.9 MB/s
- from Xplico Interface (XI) with SQLite DB (=> lite dispatcher): 1.76 MB/s
- from Xplico Interface with MySQL DB (=> ximysql dispatcher): 4.09 MB/s
measured on an Aspire 5633WLMi (Intel Core 2 Duo processor T5500 with 1GB RAM an HD IDE controller) with the pcap http://domex.nps.edu/corp/scenarios/2009-m57/net/day11-18.dmp.zip (851 MB).
As always: Enjoy !
In this version new dissectors, new features and obviously many bugfix:
- Paltalk chat dissector
- MSN dissector (beta basic version)
- XI Cookie hijacking
- XI pagination for Images and Web
- XI XSS fixed
- XI bugfix
- Tim Hentenaa for his Paltalk reverse engineering
- Steve-William KISSI to have found various XSS
- Daniele Franchetto for MSN dissector
- Michele Dallachiesa for cookietools
In this version there are bugfix, dissectors improvements and new features:
- XI configuration pages
- XI administator pages
- XI multi-user
- IRC dissector
- ARP/RAP dissector
- radiotap dissector
- GeoMap latitude and longitude selectable from XI
- CLI decoding directory (xdecode) selectable
- Telent dissector with PIPI
- Paltalk Express dissector and aggregator (basic version)
- sftp/scp pcap files upload
Any feedback is welcome.
You can download source code and Ubuntu 10.04 package here.
This release introduces improvements in the SIP and RTP dissectors.
In this version was also added the RTCP dissector, with this dissector Xplico is able to obtain the phone numbers of the caller and called party (obviously only if present in the RTCP packets).
DEFT 5.1 Live distribution contains this version.
You can download source code and Ubuntu 10.04 package here.
- HTTP reconstruction file. ie: files downloaded with tools like DownThemAll
- undecodec UDP and TCP “stream” with textual content
- RTP dissector
- SIP dissector
- SDP dissector
- Improved XI
- many bugfix
This version of the SIP and RTP dissectors is not optimal. The (media) contents currently decoded have the following characteristics (limitations) :
- only audio
- audio codec: G711ulaw, G711alaw, G722, G729, G723 and G726
- only static RTP payload type
We have to thank:
- Michele Dallachiesa, for his wonderful tool rtpbreak and for his papers on VoIP protocols
- UCSniff Team for their tool VideoSnarf
- Carlos Gacimartín, for his help and for Virtualbox Image
- Massimiliano Dal Cero for his help with flash application
- all forum users for their debug
You can download VirtualBox.org image, source code and Ubuntu 9.10 package here.