Re: TCP Dump Filters

From: Derek Walker (derwalke@cisco.com)
Date: 12/21/01


Date: Fri, 21 Dec 2001 09:05:40 -0800 (PST)
From: Derek Walker <derwalke@cisco.com>
To: Mark Coleman <mcoleman@uniontown.com>

TCP dump can be given arguments as to how much of each packet to capture.
With a snaplen of 1500 for instance, you will always capture pretty much
the whole packet.

D.

On Thu, 20 Dec 2001, Mark Coleman wrote:

> I believe that TCPDump just grabs packet headers, so it can't watch for
> anything in the payload, thus making it a poor choice for IDS beyond layer
> 4.
>
> I have seen it used to detect connections to boxen that should never happen
> for example, but NOT to see that an email attachment is called README.EXE.
>
> I may be wrong on this one, but I don't think I am. You need something like
> Snort for any good payload monitoring.
>
> -Mark
>
>
> ----- Original Message -----
> From: <JCFontelera@SolanoCounty.com>
> To: <focus-ids@securityfocus.com>
> Sent: Wednesday, December 19, 2001 4:25 PM
> Subject: TCP Dump Filters
>
>
> > Does anyone know a good web site that explains how
> > to create TCPDUMP or windump filters to detect all sorts of
> > attack signatures ?
> >
> > Thanks,
> > Jaime
>
>



Relevant Pages

  • IP protocol checksum errors
    ... Frame 3484 ... Time delta from previous packet: ... Capture Length: 254 bytes ... Fragment offset: 0 ...
    (comp.os.linux.embedded)
  • RE: Snort + (OpenBSD or Linux)
    ... Snort + (OpenBSD or Linux) ... >on the same packet. ... Regarding OpenBSD vs. Linux packet capture performance (this is a really old ...
    (Focus-IDS)
  • [TOOL] WinPcap, the Free Packet Capture Architecture for Windows
    ... the Free Packet Capture Architecture for Windows ...
    (Securiteam)
  • Re: How to go about developing a TCP Packet Filter
    ... You can modify and capture packets in LSP's, TDI filters and NDIS IM ... thus you don't know that there was an attempt to send packet. ... Volodymyr M. Shcherbyna, blog: http://www.shcherbyna.com/ ...
    (microsoft.public.win32.programmer.kernel)
  • Re: DHCP issue switching scopes
    ... Here is a text file dump of a discover/offer packet pair ... I can send the entire capture file ... Time since reference or first frame: ... User Datagram Protocol, Src Port: bootps, Dst Port: ...
    (microsoft.public.windows.server.networking)