tldr/pages/common/tcpdump.md

28 lines
626 B
Markdown
Raw Normal View History

2014-03-01 04:25:34 +00:00
# tcpdump
> Dump traffic on a network
- capture the traffic of a specific interface
`tcpdump -i {{eth0}}`
- capture all TCP traffic showing contents (ASCII) in console
`tcpdump -A tcp`
- capture the traffic from or to a host
2014-03-02 07:20:23 +00:00
`tcpdump host {{www.example.com}}`
2014-03-01 04:25:34 +00:00
- capture the traffic from a specific interface, source, destination and destination port
2014-03-01 04:25:34 +00:00
`tcpdump -i {{eth0}} src {{192.168.1.1}} and dst {{192.168.1.2}} and dst port 80`
2014-03-01 04:25:34 +00:00
- capture the traffic of a network
`tcpdump net {{192.168.1.0/24}}`
2014-08-18 10:04:06 +01:00
- capture all traffic except traffic over port 22 and save to a dump file
2014-08-18 10:04:06 +01:00
`tcpdump -w dumpfile.pcap not port 22`