Question and Answer Collection

Using tcpdump

Which option can you pass to tcpdump yo write captured packets out to a file?

-w


Using tcpdump, list all the available interfaces. What number is 'nflog' listed as?

5


Which option can be passed to tcpdump to display the ASCII and hex representation of the packet contents?

-X


Using tcpdump, read the packets from tcpdump.pcap and filter packets to include IP address 88.221.88.59 only. What is the time shown on the final packet? (HH:MM:SS)

07:32:57


Using tcpdump, read the packets from tcpdump.pcap and filter packets to include IP address 184.107.41.72 and port 80 only. Write these packets to a new file and MD5sum that file. What is the MD5sum shown?

8e4b92724d9034a49cf10f6b147ac482