Skip to content

Instantly share code, notes, and snippets.

@luca-m
Last active December 15, 2015 08:39
Show Gist options
  • Select an option

  • Save luca-m/5232573 to your computer and use it in GitHub Desktop.

Select an option

Save luca-m/5232573 to your computer and use it in GitHub Desktop.
A place where to put some bash snippets
#
# TSHARK OUTPUTS HEX-ENCODED DATA IN STDOUT
#
tshark -r capture.pcap -R "tcp.stream eq 3" -T fields -E separator=, -e frame.time -e ip.src -e tcp.srcport -e ip.dst -e tcp.dstport -e data
#[..]
#Mar 23, 2013 00:23:24.689578000,10.13.38.54,33124,10.13.37.54,4444,373030300a
#Mar 23, 2013 #00:23:24.689646000,10.13.37.54,4444,10.13.38.54,33124,426f726f6e206c6576656c20697320746f6f20686967683a203736343020286d61782031303030290a
#[..]
#
# NGREP OUTPUTS ASCII PAYLOADS
#
ngrep -I "conversation.pcap" -W byline
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment