Home > Security > Extracting Files from a tcpdump
Extracting Files from a tcpdump
Posted on 3 Juli 2011 by c0decstuff
Occasionally I have to analyze tcp-streams, and occasionally I came to a point where i had to extract files out of huge dumps. What I found during my last research about a year ago was not really usable - i hacked together a few lines of perl to extract exactly what i wanted - this didn't deliver exact files, but was enough to help me solve a problem.
Jim Clausing, one of the more practical guys over at ISC described the same problem recently and asked the readers of the ISC-Blog for software that is able to extract files from pcap-dump. People came out with a load of promising solutions:
* NetworkMiner http://networkminer.sourceforge.ne/
* tcpxtract http://tcpxtract.sourceforge.net/)
* bro http://www.bro-ids.org/
* foremost http://foremost.sourceforge.net/
* Chaosreader http://chaosreader.sourceforge.net/
* tcptrace http://www.tcptrace.org/
* tcpick http://tcpick.sourceforge.net/
* xtract.py http://www.malforge.com/npeid/xtract.py
Not all of them might do exactly what you want - but this is defintely the best overview on pcap-file-extractors I ever came across.
Category Article Security
One Response to “c0decstuff”
Total Pageviews
Labels
- Android (1)
- Aplication (14)
- ARP (1)
- Backdoored (2)
- Browser (1)
- Cloud (1)
- Exploitation (1)
- Exploits (7)
- Facebook (2)
- forensics (3)
- Hacking (11)
- Hijacking (1)
- Honeypot (1)
- HTML5 (1)
- ios (2)
- Jailbreak (2)
- Linux (1)
- Malware (5)
- metasploit (2)
- Meterpreter (1)
- Movie (1)
- Networking (1)
- News (2)
- password attack (2)
- Penetration Test (2)
- Python (1)
- reverse engineering (1)
- Rootkits (1)
- Security (12)
- shellcode (2)
- Stuxnet/Duqu (2)
- Uncategories (1)
- Virus (1)
- Vulnerability (8)
- Web (5)
- Wifi (1)
- Windows (5)
Blog Archive
-
▼
11
(51)
-
▼
Jul
(11)
- Breaking MailEnable 2.34: A lesson in security fea...
- Meterpreters new reverse_http and reverse_https op...
- Capture all metasploit input/output
- Pwning Mac OS X with evilgrade + MacPorts
- reverse engineering the google +1 button-using-fir...
- Advanced Nmap
- Fiddling with Chromium's new certificate pinning
- Journey into Exploitation: awbo2.exe
- Extracting Files from a tcpdump
- How security-teams deal with leaking passwords
- Transfer Files and Data via DNS-Requests
-
▼
Jul
(11)
Friendlist
Security Resources
-
-
-
This feed contains no entries
-
-
-
-
-
-
-
-
-
Extracting Files From A Tcpdump >>>>> Download Now
>>>>> Download Full
Extracting Files From A Tcpdump >>>>> Download LINK
>>>>> Download Now
Extracting Files From A Tcpdump >>>>> Download Full
>>>>> Download LINK gh