Sponsored Content
Special Forums Cybersecurity Need Help with this TCPDUMP output... Post 302907989 by 1to1riskcontrol on Wednesday 2nd of July 2014 11:14:37 PM
Old 07-03-2014
You lookup a tool called netwitness - you can import your packet captures and really drill down into them - it's readable and actually rebuild text, images, emails etc so you don't have a lot of cryptic data to sort through.
 

10 More Discussions You Might Find Interesting

1. Programming

How To Use tcpdump

I have two net-card. one is 172.16.24.99(ENG) ,another is 172.16.25.99(ENG-B). Both masks is 255.255.255.0. I will monitor data on the tcp port 8055 in ENG, How do I set option of tcpdump command (2 Replies)
Discussion started by: chenhao_no1
2 Replies

2. UNIX for Dummies Questions & Answers

tcpdump

does anybody know what the -d -dd and -ddd options are used for ? thanks (2 Replies)
Discussion started by: ant04
2 Replies

3. Shell Programming and Scripting

Tcpdump in cron

I wrote a short BASH script to run tcpdump and save the output to a log file for when I'm away from my desk. The script runs fine normally, but fails to start in cron. Any ideas? #!/bin/bash today=`date +%Y%m%d` tcpdump -i eth0 -s 1500 -w ${today}.cap & exit (5 Replies)
Discussion started by: paulzeromi
5 Replies

4. Shell Programming and Scripting

analyzing tcpdump output

hello, i have a lot of pcap files (tcpdump output) that i want to compare. every tcpdump output has two file, server and client. what i want to do is: 1. take timestamp, source address, destination address, and packet id from each file (server and client) 2. find the packets sent from... (0 Replies)
Discussion started by: slumpia
0 Replies

5. Cybersecurity

i would like to know about tcpdump

i would like to know about tcpdump i would like to use tcpdump to get information about these - Date - time - source hostname - source mac address - source ip address - destination ip address - see outbound only then i use command like this tcpdump -i le0 -n -q -tttt -e src net... (0 Replies)
Discussion started by: chamnanpol
0 Replies

6. IP Networking

i would like to know about tcpdump

i would like to know about tcpdump i would like to use tcpdump to get information about these - Date - time - source hostname - source mac address - source ip address - destination ip address - see outbound only then i use command like this tcpdump -i le0 -n -q -tttt -e src net... (2 Replies)
Discussion started by: chamnanpol
2 Replies

7. Shell Programming and Scripting

write a script to parse some tcpdump output

i am trying to write a script to parse some tcpdump output, in each line of the tcpdump output, I know for sure there are 3 keywords exist: User{different usernamehere} NAS_ipaddr{different ip here} Calling_station{ip or dns name here} But the positions for these 3 keywords in the... (4 Replies)
Discussion started by: fedora
4 Replies

8. IP Networking

tcpdump vs. wireshark

Hi, I am trying to capture manually crafted IP packets, created using Scapy, to a pcap file that can later be replayed using tcpreplay. When using wireshark, I can successfully capture these packets and view them in wireshark. However, when using tcpdump, these packets are then shown in... (2 Replies)
Discussion started by: yotamhc
2 Replies

9. Debian

Tcpdump Help !

Hi. Need Help with TcpDump Trying to sniff associatio-request with tcpdump but when i run this tcpdump -i eth0 wlan subtype assoc-req i get this error can anyone help me with this error ? Thanks alot !!:) (1 Reply)
Discussion started by: SoulZB
1 Replies

10. IP Networking

TCPdump

I've recently started learning to use TCPdump, and I find it pretty interesting. There's one thing I don't understand. When I tell it to capture packets on, say, the WiFi interface en1, it often captures packets sent or received by other hosts on the network. How can it do this? My... (3 Replies)
Discussion started by: Ultrix
3 Replies
drill(1)						      General Commands Manual							  drill(1)

NAME
drill - get (debug) information out of DNS(SEC) SYNOPSIS
drill [ OPTIONS ] name [ @server ] [ type ] [ class ] DESCRIPTION
drill is a tool to designed to get all sorts of information out of the DNS. It is specificly designed to be used with DNSSEC. The name drill is a pun on dig. With drill you should be able get even more information than with dig. If no arguments are given class defaults to 'IN' and type to 'A'. The server(s) specified in /etc/resolv.conf are used to query against. name Ask for this name. @server Send to query to this server. If not specified use the nameservers from /etc/resolv.conf. type Ask for this RR type. If type is not given on the command line it defaults to 'A'. Except when doing to reverse lookup when it defaults to 'PTR'. class Use this class when querying. SAMPLE USAGE
drill mx miek.nl Show the MX records of the domain miek.nl drill -S jelte.nlnetlabs.nl Chase any signatures in the jelte.nlnetlab.nl domain. This option is only available when ldns has been compiled with openssl-sup- port. drill -TD www.example.com Do a DNSSEC (-D) trace (-T) from the rootservers down to www.example.com. This option only works when ldns has been compiled with openssl support. drill -s dnskey jelte.nlnetlabs.nl Show the DNSKEY record(s) for jelte.nlnetlabs.nl. For each found DNSKEY record also print the DS record. OPTIONS
-D Enable DNSSEC in the query. When querying for DNSSEC types (DNSKEY, RRSIG, DS and NSEC) this is not automaticly enabled. -T Trace name from the root down. When using this option the @server and the type arguments are not used. -S Chase the signature(s) of 'name' to a known key or as high up in the tree as possible. -V level Be more verbose. Set level to 5 to see the actual query that is sent. -Q Quiet mode, this overrules -V. -f file Read the query from a file. The query must be dumped with -w. -i file read the answer from the file instead from the network. This aids in debugging and can be used to check if a query on disk is valid. If the file contains binary data it is assumed to be a query in network order. -w file Write an answer packet to file. -q file Write the query packet to file. -v Show drill's version. -h Show a short help message. QUERY OPTIONS -4 Stay on ip4. Only send queries to ip4 enabled nameservers. -6 Stay on ip6. Only send queries to ip6 enabled nameservers. -a Use the resolver structure's fallback mechanism if the answer is truncated (TC=1). If a truncated packet is received and this option is set, drill will first send a new query with EDNS0 buffer size 4096. If the EDNS0 buffer size was already set to 512+ bytes, or the above retry also results in a truncated answer, the resolver struc- ture will fall back to TCP. -b size Use size as the buffer size in the EDNS0 pseudo RR. -c file Use file instead of /etc/resolv.conf for nameserver configuration. -d domain When tracing (-T), start from this domain instead of the root. -t Use TCP/IP when querying a server -k keyfile Use this file to read a (trusted) key from. When this options is given drill tries to validate the current answer with this key. No chasing is done. When drill is doing a secure trace, this key will be used as trust anchor. Can contain a DNSKEY or a DS record. -o mnemonic Use this option to set or unset specific header bits. A bit is set by using the bit mnemonic in CAPITAL letters. A bit is unset when the mnemonic is given in lowercase. The following mnemonics are understood by drill: QR, qr: set, unset QueRy (default: on) AA, aa: set, unset Authoritative Answer (default: off) TC, tc: set, unset TrunCated (default: off) RD, rd: set, unset Recursion Desired (default: on) CD, cd: set, unset Checking Disabled (default: off) RA, ra: set, unset Recursion Available (default: off) AD, ad: set, unset Authenticated Data (default: off) Thus: -o CD, will enable Checking Disabled, which instructs the cache to not validate the answers it gives out. -p port Use this port instead of the default of 53. -r file When tracing (-T), use file as a root servers hint file. -s When encountering a DNSKEY print the equivalent DS also. -u Use UDP when querying a server. This is the default. -w file write the answer to a file. The file will contain a hexadecimal dump of the query. This can be used in conjunction with -f. -x Do a reverse loopup. The type argument is not used, it is preset to PTR. -y <name:key[:algo]> specify named base64 tsig key, and optional an algorithm (defaults to hmac-md5.sig-alg.reg.int) -z don't randomize the nameserver list before sending queries. AUTHOR
Jelte Jansen and Miek Gieben. Both of NLnet Labs. REPORTING BUGS
Report bugs to <ldns-team@nlnetlabs.nl>. BUGS
COPYRIGHT
Copyright (c) 2004-2008 NLnet Labs. Licensed under the revised BSD license. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. SEE ALSO
dig(1), RFC403{3,4,5}. 28 May 2006 drill(1)
All times are GMT -4. The time now is 05:55 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy