Termshark – A terminal UI for tshark, inspired by Wireshark
termshark.io
termshark.io
ssh root@sniff_server_ip -p port tcpdump -U -s0 'not port 22' -i eth0 -w - | wireshark -k -i -
Source: https://serverfault.com/questions/362529/how-can-i-sniff-the...It works very well on low volume captures.
BTW, for anyone new to tcpdump, you can also specify selectors/filtering on the command line, to reduce the traffic. The filtering in Wireshark is on top of that.
It's one of best guarded secrets in gaming industry.
ssh root@remotehost "tcpdump -i eth1 -s0 -l -w - 'udp'" | /mnt/c/Program\ Files/Wireshark/Wireshark.exe -k -i -- On Linux, flush buffer at wrong places, breaking last (few) packet(s);
- On Windows, flush buffer after every byte (which gives acceptable result, but is very inefficient).
With "-w", always use "-U" instead.
wirelive.sh:
#!/bin/bash
if [[ -z "$1" ]]; then
echo -e "Usage: $(basename $0) <host[:port]> <interface> [filters]"
exit
fi
ssh_host=$(echo $1 | cut -d: -f1)
ssh_port=$(echo $1 | cut -s -d: -f2)
[[ -z "$ssh_port" ]] && ssh_port=22
[[ -z "$2" ]] && tcpdump_interface="any" || tcpdump_interface="$2"
[[ ! -z "$3" ]] && tcpdump_filters="and \($3\)"
ssh root@${ssh_host} -p ${ssh_port} \
tcpdump -U -s0 "not port ${ssh_port} ${tcpdump_filters}" -i ${tcpdump_interface} -w - \
| wireshark -k -i -[0] https://openwrt.org/docs/guide-user/firewall/misc/tcpdump_wi...
https://etherape.sourceforge.io
I remember using that as well many years ago. Fun times.
> EtherApe now is a pure GTK 3 application, with canvas supplied by GooCanvas.
It's still in active development! Will have some fun with it :).
Having this integrated in some tool would be great.
For wider monitoring, at key points on the network I use ntop [2] to see what's
If I want a quick overview of a given machine I load up iftop [3], which isn't very thrilling on my desktop at the moment
[0] https://i.imgur.com/O9ekuPt.png [1] https://i.imgur.com/x9l0UNd.png [2] https://i.imgur.com/gFXAxwa.png [3] https://i.imgur.com/vmpgR6i.png
All of these are trivial to install (except for the RTP perl script which I have as a custom apt-gettable package) and don't require non-standard interpreters and package managers.
Nethertheless I went to get this. I had to install 540MB of support files just to run "go get github.com/gcla/termshark/cmd/termshark". Still it compliles. Then I run it, and it shows bugger all, I suspect I need to find and install more libraries (tcell, gowid), which themselves require massive downloads.
It's simply not worth it, it's like going back in time 20 years.
It runs, just doesn't look like it's reading anything from "sudo ./termshark -i eno1 icmp". Works fine when reading a pcap file, works fine when launching from a root session (rather than via sudo)
Next time you need to build a golang project you most likely won't have to download all of those libs again, unless you remove them for some reason.
[0] https://www.riverbed.com/gb/products/steelcentral/steelcentr...
I recently used this method (wireshark/windows) [1] with the cam vendors app on an old iPhone to get more insight into what was going on (particularly outside the HTTP space).
[1]https://blog.jjhayes.net/wp/2019/02/28/capture-iphone-networ...
The more we do of this kind of tool in a memory-safe language, the better.
For a while, it seemed like Wireshark dissectors were second only to 2D image format libraries, for memory exploits. I joked that one way to locate and compromise a network admin's workstation would be to create a simple network anomaly that would prompt them to fire up Wireshark. :)
It's not retrofitting. If you make it work for the terminal it will always work from now on.
It comes outside the reaches from the graphical designers. Nothing with a graphical design survives more than 10 years.
I typically write my code as a library that can then be called by an interface (or other program) rather than as a monolithic unit. Also makes it easier to run on diferent devices.
A lot of the students are already feeling stretched, as this is their first deep dive into the terminal. Though I do teach them how to run a remote capture through SSH, I can imagine them finding some relief in this.
This went immediately to my personal /bin/
But handles custom rules well :)