1
0
Fork 0
mirror of https://github.com/tldr-pages/tldr.git synced 2025-07-09 00:25:23 +02:00
tldr/pages/common/tcpdump.md

37 lines
904 B
Markdown
Raw Normal View History

2014-03-01 01:25:34 -03:00
# tcpdump
> Dump traffic on a network.
> More information: <https://www.tcpdump.org>.
2014-03-01 01:25:34 -03:00
2017-12-03 08:22:45 -08:00
- List available network interfaces:
`tcpdump {{[-D|--list-interfaces]}}`
2017-12-03 08:22:45 -08:00
- Capture the traffic of a specific interface:
2014-03-01 01:25:34 -03:00
`sudo tcpdump {{[-i|--interface]}} {{eth0}}`
2014-03-01 01:25:34 -03:00
- Capture all TCP traffic showing contents ([A]SCII) in console:
2014-03-01 01:25:34 -03:00
`sudo tcpdump -A tcp`
2014-03-01 01:25:34 -03:00
- Capture the traffic from or to a host:
2014-03-01 01:25:34 -03:00
`sudo tcpdump host {{www.example.com}}`
2014-03-01 01:25:34 -03:00
- Capture the traffic from a specific interface, source, destination and destination port:
2014-03-01 01:25:34 -03:00
`sudo tcpdump {{[-i|--interface]} {{eth0}} src {{192.168.1.1}} and dst {{192.168.1.2}} and dst port {{80}}`
2014-03-01 01:25:34 -03:00
- Capture the traffic of a network:
2014-03-01 01:25:34 -03:00
`sudo tcpdump net {{192.168.1.0/24}}`
2014-03-01 01:25:34 -03:00
- Capture all traffic except traffic over port 22 and [w]rite to a dump file:
`sudo tcpdump -w {{dumpfile.pcap}} port not {{22}}`
2017-12-03 08:22:45 -08:00
- [r]ead from a given dump file:
2017-12-03 08:22:45 -08:00
`tcpdump -r {{dumpfile.pcap}}`