tcpdump -w flagdump 'tcp[tcpflags] & (tcp-syn|tcp-fin) != 0'
Wednesday, May 5, 2010
Using tcpdump to only capture SYN and FIN packets
Sometimes with a network capture, all you want to know is when a session starts and when it finishes. So you don't actually want to capture anything beyond the session start and finish handshakes. Here's how to do it:
Subscribe to:
Post Comments (Atom)
Followers
About Me
![My photo](http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBNwmdq-RYjbhHT063mUlVIBWMkDuoZ2eqYv6JKBxAiRR-qzxx8UBj2IJYlwyVnDfJfmGfaEvMK1smoS65y74stCBBY-lEXHRY0H_gh01oCYlbkR86WdndmC2pzY6UtA/s1600-r/regis-w-camera.jpg)
- regis
- Regis has worked as a network engineer since 1994 for small companies and for large companies.
No comments:
Post a Comment