What does it do?
It can reassemble TCP packets back into the FULL body of the original message sent. e.g. if you make a HTTP GET request, it will show you the full text in a file stamped with the time, source and dest ips and port.
Things I've found it REALLY useful for:
- migrating a data center
- for some reason, connection works fine on the old DC but seems to time out in weird ways in the new DC
- No one can figure it out
- I suggest using tcpflow
- Turn out there was a setting in the new DC network hardware that was truncating larger packets and the authorization message was just over the threshold
People always say "yeah, but Wireshark" which is true, that's a good tool too. That being said, there is just something about seeing the "raw" text of a message sent by a machine over the wire and being able to see it in text from the command line.