How to convert Tcpdump output file to a Pcap format?
Hi All,
How to convert Tcpdump output file to a Pcap format? Is there such way? This is what i mean: tcpdump -i eth0 >> test.out Now i want to convert test.out to Pcap so It's readable via Wireshark. Thanks in advance for your help :) |
Quote:
Code:
tcpdump -i eth0 -w test.pcap |
Use tcpdump's -w option:
tcpdump -i eth0 -w test.out |
output of tcpdump is plain text generated by SOME of the fields in the header, thus many informations about a packet have been lost and total reconstruction is impossible. If you want to compare output of two programs, capture packets with tcpdump and log them as binaries.
Code:
sudo tcpdump -i eth0 -w test.out Code:
sudo tcpdump -i eth0 -r test.out Code:
sudo tcpdump -i eth0 -w test.out -s 65535 |
Thanks Heaps guys
|
All repped!
|
I have a small how to on this topic, i hope it will be help for others:
Use tcpdump to capture pcap wireshark dump file http://linuxexplore.com/2012/06/07/u...ireshark-dump/ |
All times are GMT -5. The time now is 06:52 PM. |