An lsof Primer
danielmiessler.com
danielmiessler.com
$ lsof | grep Flash
plugin-co 1038 naner 16w REG 254,2 4442164 7602188 /tmp/FlashXXfHeQqB (deleted)
$ mplayer /proc/1038/fd/16
Oftentimes the output will give you duplicates for the same temporary flash file (FlashXXfHeQqB in this case) with an extra number after the process id, you can ignore all of that. I'm assuming those are child processes. All you need is the process id (1038) and the file descriptor (16). You can safely ingore the character (w) after the file descriptor.Back in the day (Flash 9 or so?) the flash player used to just dump temporary flash video files in /tmp and delete them after you close the browser tab. I guess they figured it was too easy to copy the files out of /tmp so the newer flash player deletes the /tmp file immediately after it creates them. This is why we have to go and grab the open file descriptor.
This will work with most but not all websites. Some websites (Hulu) will use a streaming protocol (rtsp) among other things to make the content harder to get at outside of flash.
This works on Linux, I'm not sure about OSX or BSD.
#!/bin/sh
IFS='\
'
for i in `ls -dLtr \`lsof -c plugin-containe -a -u $USER -X +L1 | awk -F ' +' '/\/tmp\/Flash/{ print "/proc/" $2 "/fd/" gensub("[^0-9]", "", "g", $4); }'\``; do
PLAY="$PLAY $i"
done
IFS=' '
mplayer -osdlevel 3 -fs $PLAY
I have it bound to a shortcut key in my window manager and I installed http://userscripts.org/scripts/show/13333 to automatically pick 720p videos, and pause them.So I go to youtube in a tab, let it buffer for a bit, hit the shortcut key and enjoy.
Note that it's only semi-recent versions of flash that automatically delete the videos, if not remove the +L1
If you get an error relating to gensub ("function gensub never defined"), you need to install gawk.
lsof +L1 shows you all open files that have a link count less than 1,
often indicative of a cracker trying to hide something
On OS X, lsof +L1 returns tons of files, this is normal.From the manpage:
When +L is followed by a number, only files having a link count less than that number will be listed. (No number may follow -L.) A specification of the form ``+L1'' will select open files that have been unlinked. A specification of the form ``+aL1 <file_system>'' will select unlinked open files on the specified file system.
On my MBP (SL) at least, all the files listed with +L1 are from /private/var/folders/
A quick search seems to hint that this is the location to store secure caches and temp files for Snow Leopard.
$ sudo lsof -i 4:443
$ sudo lsof -i 6:443
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
httpd 12345 apache 6u IPv6 987654321 TCP *:https (LISTEN)
If you see this, the fix is to disable IPv6 by setting "options ipv6 disable=1" via modprobe.I noticed your contact link is broken in this article (and perhaps all?). The HREF points to:
http://danielmiessler.com/var/www/localhost/htdocs/includes/...
Similarly, most versions of lsof support built-in filtering of TCP ports by status:
lsof -iTCP -sTCP:LISTEN -P
will show you the open TCP ports without having to use grep (which discards the header.) lsof -i -P
This shows all the open Internet connections and port numbers.