Snoop the incoming TCP packets even no program is listening the port.

Posted on 2005-04-13
Last Modified: 2013-12-27
With snoop, I can capture the TCP packets if there is a program listening to a specific port.
Can I do the capture even if there is no program listening to a specific port.

I want to know if there is some traffic going to a port that no one is using it.
Question by:matchz
    LVL 16

    Accepted Solution

    just use
       snoop port <port>
    with <port> being a port number (as 25) or a service name (as smtp) in /etc/services)

    LVL 16

    Assisted Solution

    by:Hanno Schröder
    To verify, you may do this:
    a) on your server start: snoop port 10500
    b) from any other system try: telnet server 10500

    You should see something like this:
        client -> server  TCP D=10500 S=44386 Syn Seq=2797324187 Len=0 Win=24820 Options=<nop,nop,sackOK,mss 1460>
        server -> client  TCP D=44386 S=10500 Rst Ack=2797324188 Win=0

    LVL 10

    Expert Comment

    Snoop is great.  You might also look at installing Ethereal.  **Very nice** GUI based packet sniffer.  It can even read in snoop packet traces.  And the price is right - its free !!

    Featured Post

    Highfive Gives IT Their Time Back

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Join & Write a Comment

    Installing FreeBSD… FreeBSD is a darling of an operating system. The stability and usability make it a clear choice for servers and desktops (for the cunning). Savvy?  The Ports collection makes available every popular FOSS application and packag…
    I promised to write further about my project, and here I am.  First, I needed to setup the Primary Server.  You can read how in this article: Setup FreeBSD Server with full HDD encryption (…
    Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
    Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now