5 ms·
One of my favs, a tcpdump filter for HTTP including request headers: sudo tcpdump -s 0 -A 'tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420' This is useful for t
by magoon 11y ago
One of my favs, a tcpdump filter for HTTP including request headers:
sudo tcpdump -s 0 -A 'tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420'
This is useful for troubleshooting outbound requests that your backends are making. I've had the interesting logic explained to me but can't remember the details.
- aardvark179 11y agoIt's good to have things like that in your toolbox, but it's probably also a good idea to figure out how they work and what their limitations are going to be, otherwise you'll may hit situations where they don't work and you don't understand why. So, start with the magik number. If you look up those 8-bit ASCII codes you'll see that it spells out GET followed by a space, which should give a clue as to how it's working. So it will capture a lot of HTTP requests, but it may not be getting them all.