Hello My Friends, I need to extract TCP Flows with their content from dump file and then save their flow into other file each flow separately, does any one know a tool for processing this?
I really appreciate for any Help
Hanieh Rajabi.
Hello My Friends, I need to extract TCP Flows with their content from dump file and then save their flow into other file each flow separately, does any one know a tool for processing this?
I really appreciate for any Help
Hanieh Rajabi.
Wire shark maybe? It can be used to filter sessions and I think you can then save them seperatly.
If you're only doing a few, Wireshark can do this.
Steps:
Alternate steps, for HTTP only:
This is with Wireshark 1.2.1 on Linux/GTK. The 'follow TCP stream' option has been moved around between versions, so it may be somewhere else if you have an older version. But its always been called Follow TCP Stream so you should be able to find it.
Quick searching also reveals several other options if Wireshark doesn't work for you: ngrep, tcpick, chaosreader, and tcpflow.
Thanks All Dear, since I am processing so many dump files,I need a tool to do saving automatically not manually way and, The problem of using tcpick and tcpflow is I am not sure whether they can open the dump file or they can just do sniffing themself and then save the dump file.
I'm really appreciated with Regards, Hanieh