tcpdump - dump traffic on a network
tcpdump [-i iface] [-n|-nn] [-c count] [-w file | -r file] [-A] [expression]
Options you will use
-i any- all interfaces (adds interface and direction columns)
-n- do not resolve hosts
-nn- do not resolve hosts or ports
-c N- stop after N packets
-w F- write raw packets to a file
-r F- read a capture file (no root needed)
-A- print payload as ASCII
Examples
$ sudo tcpdump -i any -nn port 53every DNS query
$ sudo tcpdump -nn host 10.0.3.12 and port 5432is the database answering our SYNs
$ tcpdump -nn -r cap.pcap 'tcp[tcpflags] & (tcp-rst) != 0'just the resets
Gotchas
- Flags: [S] SYN, [S.] SYN-ACK, [.] ACK, [P.] data, [F.] FIN, [R] / [R.] reset.
- Capturing needs root (CAP_NET_RAW). Reading a file does not.
Taught in
Try tcpdump in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.