Re: [K12OSN] Logging IM traffic

I found 2 references in my email archive.  I've tried neither of these

"Try msgsnarf from dsniff suite (http://www.monkey.org/~dugsong/dsniff/)" 

And here is a snort rule that purports to log all aim traffic

alert tcp any any -> any 5190 (msg:"AIM Message"; content:"HTML";)

Logging or blocking ALL of the traffic is harder than it seems.  The
client code is pretty adept about finding new ways through the firewall.
And it usually is not acceptable to blackhole *.aol.com

Jim Wildman, CISSP                                      jim rossberry com
614-404-1897                                     http://www.rossberry.com

On Thu, 18 Apr 2002 john meissen org wrote:

> A little off-topic perhaps, but,...
> I recently found out that a close friend's 13-year old daughter was
> sexually molested by someone she met using one of the Instant Messenger
> clients available on the 'net. This has encouraged me to try to 
> manage closer monitoring of my own daughters' IM activities. It's
> occurred to me that someone may have already implemented something to
> do this.
> Does anyone know if this is something Squid can accomplish, or if
> there is something else available that can log specific traffic
> for later review?
> john-
