LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 03-11-2010, 09:19 PM   #1
mattseanbachman
Member
 
Registered: Feb 2010
Posts: 40

Rep: Reputation: 15
Tcpdump decode Gzip packets


Does gzip have the capability to decode gzipped traffic? I have been beating my head against the wall with this issue. What I'm trying to do is capture traffic between a web server and clients, and I've got it set up where it's redirected to a file for ease of grepping, however it's seemingly incapable of decoding gzipped encoding. I know I can do this with tshark, I'm curious as to whether tcpdump has this capability (i.e. only using tcpdump, and not some additional tool like tcpshow or what-not).

I can't find much on this issue in the man page for tcpdump, but it is fairly lengthy, so it's possible that I missed something, but I don't see that as especially likely.

Help would be appreciated.

Thanks,
Matt
 
Old 03-11-2010, 10:23 PM   #2
estabroo
Senior Member
 
Registered: Jun 2008
Distribution: debian, ubuntu, sidux
Posts: 1,126
Blog Entries: 2

Rep: Reputation: 124Reputation: 124
I'd guess not, but you could always load the tcpdump captured packets into tshark
 
Old 03-12-2010, 02:06 AM   #3
mattseanbachman
Member
 
Registered: Feb 2010
Posts: 40

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by estabroo View Post
I'd guess not, but you could always load the tcpdump captured packets into tshark
Yeah, I knew I could decode with tshark. More than anything else this was just one of those things that I was curious if it could be done or not (i.e. with tcpdump).

I rescanned the man page on tcpdump, still can't see anything, nor can I get much out of google searching. Might just have to call it quits, just seems like it'd be plausible for tcpdump to have it, but no dice.

Thanks for the input, I've got confirmation on what I was thinking.

-Matt
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
tcpdump version 4.0.0 decode Agent-Information Option 82 robel Linux - Software 1 03-28-2009 11:40 AM
tcpdump does not capture all packets logicalfuzz Linux - Networking 1 03-19-2007 12:47 PM
How to modify tcpdump packets? chinmays Linux - Security 3 09-24-2006 01:31 PM
How to Capture Raw Packets (no Decode) with PCAP kidskc Programming 1 11-02-2005 04:54 PM
tcpdump and dropped packets Blindsight Linux - Networking 5 07-14-2003 10:41 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 02:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration