Tcpdump Examples
hackertarget.com
hackertarget.com
Tshark (nee Wireshark) I believe does decode packet fragments into streams, and allows you to use more advanced Wireshark protocol filters. My suggestion is to start a pcap capture, and at the same time replay it using Tshark with the filters you want. This way you can re-analyze the same live traffic both now and later.
Packet stream is dumped into some perl which keeps across the sequence number looking for out of sequence packets, summarise output every second into an elastic stack. Also have it comparing multiple streams for dual streaming and comparing skew.
Ironically I rarely use tcpdump to look at tcp packets - about the only interesting thing to me there is the SYN packets to see if the packet is getting through the firewall!
BTW I really recommend unbuffer from expect, if you are using tcpdump and pipes.
Only HTTP traffic, you can process decrypted HTTPS traffic (like some devices do, i.e. IXIA network devices) which is transformed into HTTP traffic. Regarding HTTPS or HTTP2 etc. The current approach is to correlate the application information from log events against traffic measurements.
~$ sudo tcpdump -s 0 -A -vv 'tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420'
There should be a better way to do that. Ideally I would want a tool shows Request Method, Headers, Query String, POST Payload of requests as they come in (and let's me filter on those). It should support HTTP2 and know how to stitch together the payload from multiple packets.HTTPS is a difficult topic. I think it's fair for a tool like this, not to mess with encrpytion. Usually you don't want to had a precious private key file to a command line tool for debugging. A better way seems to be to terminate SSL on a separate host, and analyze the un-encrypted traffic.
I don't want to change the data path in any way. I just want to listen in.
1. Use `-i any` -- just in case the traffic you want to look at is not on the interface you think it is. Also doesn't put the interface(s) into promiscuous mode, which can be preferable.
2. Read the `pcap-filter` man page.
Also sometimes I reach for ngrep if it is installed:
sudo stdbuf -oL -eL /usr/sbin/tcpdump -A -s 10240 \
"tcp port 4080 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)" | \
grep -a --line-buffered ".+(GET |HTTP\/|POST )|^[A-Za-z0-9-]+: " | \
perl -nle 'BEGIN{$|=1} { s/.*?(GET |HTTP\/[0-9.]* |POST )/\n$1/g; print }'Additionally, it's always better to always use "-p" if you don't want to accidentally attract additional traffic to the host (additional VLAN on a 802.1q interface, or additional multicast traffic).
If anyone is interested I've made some notes here: https://null.53bits.co.uk/index.php?page=tcpdump-notes
For example, imagine spanning/mirroring a 10G backbone link, how many people are pinging 8.8.8.8 all the time. I can ping with a specific DSCP value set to isolate my pings from anyone elses, looking into the reported issue of 8.8.8.8 latency, then apply a filter to tcpdump on my mirrored port that matches ICMP traffic to a specific IP, with a specific DSCP value, inside specific L3 VPN (specific MPLS labels) etc.
sudo tcpdump -nlASX -s 65535 -vvv -i eth3 '(mpls 52634 and (ip and (ip[1] & 0xfc) >> 2 > 0x01) and host 11.22.33.44 and icmp)'
I love tcpdump's filtering capabilities.
https://linux.die.net/man/1/tcpflow
If you are looking to do TCP level protocol analysis it is one of the simplest and easiest linux command line tools out there.
It's biggest strength is that it can take a payload split over multiple packets and spit it out as a file with the whole payload
I tend to end up using wireshark for analysis of more complicated SIP issues but I always start with tcpdump.
> https://en.m.wikipedia.org/wiki/Apropos_(Unix)
Also, of course see: