regarding linux socket filter and sniffing

Neeraj Kapoor (malhacker@yahoo.com)
Thu, 5 Jul 2001 07:14:30 -0700 (PDT)


Hello friends,
I am right now writing a small sniffer using lsf (linux socket filter).
The question of mine is this that if a bpfcode is attached to the
filter and then detached and reattached. The bettwen these the two
attach operations will the packest which were recvd by the kernel on
this socket will be filtered the new attached expression or not. Here
the packets I am referring to are the one’s which will be buffered on
the socket between the two attach operations.
TIA
mal

=====

Image by FlamingText.com

__________________________________________________
Do You Yahoo!?
Get personalized email addresses from Yahoo! Mail
http://personal.mail.yahoo.com/
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/