Solved

Capturing network packets for use in userland application - TCPDUMP?

Posted on 2003-12-09
2
286 Views
Last Modified: 2010-03-18
Hi,

I want to be able to capture packets from my network to use as input for a program i am writing. the program will dessimate the packet and use different parts of it so i need the packet in a usable format.  Can i do this with TCPDUMP?  I tried with  tcpdump -x -s 0 -i lo -w pkt -c 1, but the output from pkt looked like

\324\303\262\241^B^@^D^@^@^@^@^@^@^@^@^@\377^@^@^A^@^@^@\327Y\326?\254.^K^@W

etc

the full output cut & pastes like

Ôò¡

Any pointers?
0
Comment
Question by:dtod
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 2

Accepted Solution

by:
asbharadwaj earned 120 total points
ID: 9910253
Hi
>> i need the packet in a usable format
What do u exactly have in mind?

the -w option causes tcpdump to dump the raw packets to the specified file and exit
You can directly redirect the output of tcpdump to a file and read it later on in your
program
The -v option gives you verbose output and the -vv option gives you even more verbose output

You can also read the packet information from the dump file you generated using the -w
option
inorder to do that you'll have to use the -r filename option.
Your program needs to have a good understanding of the protocol it is looking for
to make good use of the tcpdump output
you'll also have to do a lot of string processing if your program is written in C or something like that
whereas a program written in something like perl will find a lot easier for this purpose

refer the tcpdump man page for more options
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 9913968
tcpdump write packets in a *usable* format. Dot.
The problem seems to be that *your* definition of usable is different to that from tcpdump.
So you first need to define, means: tell us, what a usable format is for you.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to enable SSH in Ubuntu. 7 106
Squid Connection Pools 3 100
looking for a CENTOS ISO to download with x window installed 2 72
CentOS 7 wireless 2 36
I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question