Hi,
~
I was wondering how could you run wireshark just before and after
downloading a payload, without snooping in anyone else's actual
payloads
~
The only needed metrics would be:
~
1) timing down to the milliseconds (or nanoseconds?)
~
2) the IP address of the initiating client's request
~
3) the IP address of the server's response
~
4) the used protocol
~
Then you, say, go "wget <some package out there>" and wireshark would
stop doing it and just do the data payload
~
and after finishing the download it would do the initial (1,2,3,4)
for some time
~
Thanks
lbrtchx