9 More Discussions You Might Find Interesting
1. IP Networking
I've recently started learning to use TCPdump, and I find it pretty interesting. There's one thing I don't understand. When I tell it to capture packets on, say, the WiFi interface en1, it often captures packets sent or received by other hosts on the network. How can it do this? My... (3 Replies)
Discussion started by: Ultrix
3 Replies
2. Shell Programming and Scripting
I'm new to the Unix/Linux world. I have taken classes and played with a few simple scripts but never had a real world application. Here is my problem.
What I need to do is every 15min between 8am and 5pm, run
tcpdump -s 2000 -w flowroute-0000.pcap
where the "0000" is the current time.
... (4 Replies)
Discussion started by: Nasasdge
4 Replies
3. UNIX for Dummies Questions & Answers
Hi Everyone,
anyone face "tcpdump -i any" does not work? i mean if i use -i eth0, can capture eth0, or use -i eth1 also can. but then tcpdump -i any, seems cannot capture packets. :confused:
please advice, thanks (2 Replies)
Discussion started by: jimmy_y
2 Replies
4. Linux
Hi,
I want to capture TCPDUMP of traffic, I tried doing this but did not find success..can anyone plz correct it.
# tcpdump -s0 -vv -w /home/osuresh/test_tcp_dump host 10.12.10.22 && port 161
bash: tcpdump: command not found
# tcpdump -s0 -vv -w /home/osuresh/test_tcp_dump host... (5 Replies)
Discussion started by: sureshcisco
5 Replies
5. IP Networking
i would like to know about tcpdump
i would like to use tcpdump to get information about these
- Date
- time
- source hostname
- source mac address
- source ip address
- destination ip address
- see outbound only
then i use command like this
tcpdump -i le0 -n -q -tttt -e src net... (2 Replies)
Discussion started by: chamnanpol
2 Replies
6. Cybersecurity
i would like to know about tcpdump
i would like to use tcpdump to get information about these
- Date
- time
- source hostname
- source mac address
- source ip address
- destination ip address
- see outbound only
then i use command like this
tcpdump -i le0 -n -q -tttt -e src net... (0 Replies)
Discussion started by: chamnanpol
0 Replies
7. IP Networking
Hi, I got the following question regarding tcpdump and I would appreciate your help/feedback:
--Scenario
I am instructed to capture the network traffic by getting the tcpdump data/files of our network for every hour.
--Problem
Some of the connections are still open when the capture is done... (1 Reply)
Discussion started by: jinsunnyvale
1 Replies
8. UNIX for Dummies Questions & Answers
does anybody know what the -d -dd and -ddd options are used for ?
thanks (2 Replies)
Discussion started by: ant04
2 Replies
9. Programming
I have two net-card. one is 172.16.24.99(ENG) ,another is 172.16.25.99(ENG-B). Both masks is 255.255.255.0.
I will monitor data on the tcp port 8055 in ENG, How do I set option of tcpdump command (2 Replies)
Discussion started by: chenhao_no1
2 Replies
SC_WARTS2PCAP(1) BSD General Commands Manual SC_WARTS2PCAP(1)
NAME
sc_warts2pcap -- write packets included in warts object to a pcap file.
SYNOPSIS
sc_warts2pcap [-o outfile] [-s sort] [file ...]
DESCRIPTION
The sc_warts2pcap utility provides the ability to extract packets embedded in the tbit, sting, and sniff warts objects and write them to a
pcap file, which can be read by tcpdump and wireshark. The options are as follows:
-o outfile
specifies the name of the output file. If no output file is specified, it will be written to the standard output, provided that it
is not a tty.
-o sort
specifies how the pcap records (packets) are sorted before being written out. By default, no sorting is applied; the packets are
grouped as they are in the warts file. If packet sorting is specified, the packets are written out in timestamp order. Note that
this operation requires the packets to be read into memory to be sorted, so it will require a corresponding amount of memory to com-
plete.
EXAMPLES
The command:
sc_warts2pcap -o output.pcap file1.warts file2.warts
will read the packet objects from file1.warts, and then file2.warts, and write them to output.pcap.
The command:
gzcat file1.warts.gz | sc_warts2pcap -s packet >file1.pcap
will read the contents of the uncompressed warts file supplied on stdin, sort the packets by their timestamp, and then write the output to
file1.pcap.
SEE ALSO
scamper(1), tcpdump(1)
AUTHORS
sc_warts2pcap is written by Stephen Eichler and Matthew Luckie.
BSD
October 15, 2010 BSD