Re: tcpdump wiggin out?
Re: tcpdump wiggin out?
- Subject: Re: tcpdump wiggin out?
- From: Brian Hill <email@hidden>
- Date: Sat, 18 Aug 2001 00:34:30 -0500
On Friday, August 17, 2001, at 11:08 PM, R. Tony Goold wrote:
I know this is getting a bit off topic, but after successfully
building tcpflow on my system (it's worked since Mac OS X PB, I
think) I discovered it was only capturing TCP packets, not UDP
ones. The tcpflow docs weren't very helpful since they seemed to
hint at being TCP only but had large portions copied almost
verbatim from the tcpdump docs, which discuss UDP as well.
I'm hacking together a protocol independent instant messaging and
presence framework (with a service provider interface for protocol
plug-ins -- I love NSBundle!) and this would be incredibly useful
for debugging purposes.
Has anyone made tcpflow show UDP packets, or found a similar
utility with that capability?
I believe snort can (www.snort.org). It compiles easily on OSX.
Brian
email@hidden
http://personalpages.tds.net/~brian_hill
"Why? I came into this game for adventure - go anywhere, travel
light, get in, get out, wherever there's trouble, a man alone.
Now they've got the whole country sectioned off and you can't
move without a form. I'm the last of a breed."
-- Archibald "Harry" Tuttle, Rogue HVAC Repairman