2014-03-01 04:25:34 +00:00
|
|
|
# tcpdump
|
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
> Dump traffic on a network.
|
2014-03-01 04:25:34 +00:00
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
- Capture the traffic of a specific interface:
|
2014-03-01 04:25:34 +00:00
|
|
|
|
|
|
|
`tcpdump -i {{eth0}}`
|
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
- Capture all TCP traffic showing contents (ASCII) in console:
|
2014-03-01 04:25:34 +00:00
|
|
|
|
|
|
|
`tcpdump -A tcp`
|
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
- Capture the traffic from or to a host:
|
2014-03-01 04:25:34 +00:00
|
|
|
|
2014-03-02 07:20:23 +00:00
|
|
|
`tcpdump host {{www.example.com}}`
|
2014-03-01 04:25:34 +00:00
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
- Capture the traffic from a specific interface, source, destination and destination port:
|
2014-03-01 04:25:34 +00:00
|
|
|
|
2016-01-06 17:00:53 +00:00
|
|
|
`tcpdump -i {{eth0}} src {{192.168.1.1}} and dst {{192.168.1.2}} and dst port 80`
|
2014-03-01 04:25:34 +00:00
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
- Capture the traffic of a network:
|
2014-03-01 04:25:34 +00:00
|
|
|
|
|
|
|
`tcpdump net {{192.168.1.0/24}}`
|
|
|
|
|
2016-01-07 17:31:27 +00:00
|
|
|
- Capture all traffic except traffic over port 22 and save to a dump file:
|
2014-03-27 18:46:32 +00:00
|
|
|
|
2014-08-18 10:04:06 +01:00
|
|
|
`tcpdump -w dumpfile.pcap not port 22`
|