[linux] tcpdump statisktiky

Matus UHLAR - fantomas uhlar na fantomas.sk
Pátek Září 9 17:47:40 CEST 2005


On 09.09 17:19, Rasto Fuko wrote:
> neviete o nejakom analyzatore, ktory vie spracovat a urobit statistyky z
> takehoto vystupu z tcpdump?

apt-cache search tcpdump
...
netdude - NETwork DUmp data Displayer and Editor for tcpdump trace files
...
nstreams - network streams - a tcpdump output analyzer
...
tcptrace - Tool for analyzing tcpdump output
...
a mozno este nieco co som prehliadol a zislo by sa ti

btw aky mas balickovaci system? na debiane mas iste apt-cache aj ty a pre
ine distribucie sa iste najdu programy s podobnou funkcionalitou.


> ...
> 01:30:00.255669 11.40.130.67.3389 > 11.59.67.110.2972: P 4006377506:4006377527(21) ack 479115544 win 64381 (DF)
> 01:30:00.304230 11.46.17.43.1408 > 11.40.200.2.domain:  41616+ A? u12.eset.com.vszp.local. (41) [tos 0x60] 
> 01:30:00.304350 11.40.200.2.domain > 11.46.17.43.1408:  41616 NXDomain* 0/1/0 (115)
> 01:30:00.321693 11.47.17.171.2030 > 11.40.170.69.telnet: P 1740805031:1740805032(1) ack 2599150185 win 16558 (DF) [tos 0x60] 
> 01:30:00.321849 11.40.170.69.telnet > 11.47.17.171.2030: P 1:2(1) ack 1 win 65535 (DF)
> 01:30:00.389525 11.47.17.132.1869 > 11.40.60.203.http: . ack 6369518 win 64860 (DF) [tos 0x60] 
> 01:30:00.441503 11.59.67.110.2972 > 11.40.130.67.3389: . ack 21 win 16970 (DF) [tos 0x60] 
> 01:30:00.443015 11.47.17.171.2030 > 11.40.170.69.telnet: P 1:2(1) ack 1 win 16558 (DF) [tos 0x60]  
> .....

-- 
Matus UHLAR - fantomas, uhlar na fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
M$ Win's are shit, do not use it !




Další informace o konferenci linux