deeejay icon

Bash - Wireshark Remote Packet Capture

deeejay | PRO | 06/17/16 05:16:16 PM UTC | 0 ⭐ | 223 👁️ | Never ⏰ | []
Bash |

910 B

|

None

|

0 👍

/

0 👎

RHEL6 Requirements:
geoip-1.4.6-1.el6.rf.x86_64.rpm
libsmi-0.4.8-4.el6.x86_64.rpm
wireshark-1.10.0-1.el6.rft.x86_64.rpm
wireshark-gnome-1.10.0-1.el6.rft.x86_64.rpm
zlib-1.2.3-29.el6.x86_64.rpm
 
For remote capture readings:
coreutils-8.4-43.el6.x86_64.rpm
coreutils-libs-8.4-43.el6.x86_64.rpm
 
 
Create a named pipe:
mkfifo /tmp/packet_capture
 
Start wireshark from the command line
wireshark -k -i /tmp/packet_capture
 
Run tcpdump over ssh on your remote machine and redirect the packets to the named pipe (find the eth interface):
ssh root@source-hostname "tcpdump -s 0 -U -n -w - -i eth0 not port 22" > /tmp/packet_capture
 
Source: http://blog.nielshorn.net/2010/02/using-wireshark-with-remote-capturing/
 
Filters
===
 
Find duplicate ip addresses:
arp.duplicate-address-detected
 
Exclude a destination ip address
NOT(ip.dst == 10.15.30.114)
 
Exclude a source ip address
NOT(ip.src == 10.15.30.114)

Comments