A tcpdump tutorial and primer
danielmiessler.com
danielmiessler.com
[1] Wireshark might have that, but I haven't checked. I like to keep diversity in the tools I use.
-w Write the raw packets to file rather than parsing and printing them out. They can later be printed with the -r option. Standard output is used if file is ``-''. See pcap-savefile(5) for a description of the file format.
--You can then open this file in wireshark on your desktop for easier analysis if you wish.
I think learning to build effective display filters in those tools is more useful than learning to use a capture tool in complex ways.
This can apply to troubleshooting your own problems too, as you can then inspect things in your own time and gather evidence to present later, and even use a capture file to replay traffic.
http://www.tcpdump.org/pcap.html
Lately I have been playing with a Go interface to it, https://github.com/miekg/pcap
Great tool, and lots of fun.
http://hackage.haskell.org/package/pcap-0.2/docs/Network-Pca...
ssh -c arcfour root@myserver tcpdump -nn -U -s0 -w - 'not port 22' | wireshark -k -i -
e.g. -b filesize:100000 -b files:200 -w somefile
This will make a ring buffer of 200 * 100MB files.
After typing this, I realized this may have limited use cases, but I use it almost every day.
e.g. -C 100 -W 200 -w somefile will get you the same circular ring of 200 100MB files.
Also, don't forget to add the -s 0 flag if you want to get the entire payload.
Personally I prefer multilog + pflogd + some other tool to examine the pcap file.
My old favorite is nc-data -d. The entire program fits on one page.
od or xxd -c1 |cut -d: -f2 will work too.
ngrep is fussy about interface types but I use that too.
Filters for nc-data output can be written in lex, sed, awk, lua, whatever.
I've even experimented with snobol4 and spitbol on packets since the output format of nc-data is so simple.
Those were the days. Now all I can complain about is that you need root permissions on OpenBSD merely to read a capture file.
How does that even work? It seems like if you can read the file there is nothing stoping you from trying to parse its contents.
tcpdump -i int -n -w - -l -s 1500 | strings