3 ms·
Sometimes when no other options exist, and I need to capture untrusted traffic as root, I use 'tcpdump -i eth0 -s0 -n -w some.pcap' to save the packets to a .pc
by rixrax 4y ago
Sometimes when no other options exist, and I need to capture untrusted traffic as root, I use 'tcpdump -i eth0 -s0 -n -w some.pcap' to save the packets to a .pcap. Just recording the frames shouldn't (invoke any parsing code although I have never actually checked). Then I open the .pcap with wire/tshark or even tcpdump in some safer sandbox.
- hamburglar 4y agoYou can also send the pcap to stdout and pipe it to stdin of a tshark running as non-root. And if you provide the right capture filters on tcpdump you can even have the tcpdump in an ssh session piping to a local tshark so you don’t even have to have tshark on the server.
- mr_mitm 4y agoWireshark is also able to capture traffic of remote interfaces over ssh.
- lexh 4y agoI was delighted when I discovered that you can also pipe stdin into Wireshark (GUI). I've not seen a lot of GUI applications that support this flow. e.g. > wireshark -k -i <(ssh -l root remote-host "dumpcap -P -w - -f 'not tcp port 22'") https://wiki.wireshark.org/CaptureSetup/Pipes.md#remote-capture https://wiki.wireshark.org/CaptureSetup/Pipes.md#remote-capt...
- hamburglar 4y agoI prefer a ‘not host <x>’ filter using info found in $SSH_CONNECTION to filtering all port 22 out, but yeah, good stuff.