Capturer un port

Capture le trafic sur un port : la réponse la plus fiable à la question de savoir si des paquets arrivent.

SMTP (25)

PowerShell (Windows)

pktmon Natif

pktmon filter remove
pktmon filter add -p 25
pktmon start --capture --pkt-size 0 -f capture.etl
# ... reproduzieren, dann:
pktmon stop
pktmon etl2txt capture.etl -o capture.txt

tcpdump (WSL/Npcap) Outil complémentaire

tcpdump -i eth0 -n -c 200 port 25

Shell Unix (bash)

tcpdump Natif

tcpdump -i eth0 -nn -c 200 port 25

tshark Outil complémentaire

tshark -i eth0 -c 200 -f "port 25"

Submission (587)

PowerShell (Windows)

pktmon Natif

pktmon filter remove
pktmon filter add -p 587
pktmon start --capture --pkt-size 0 -f capture.etl
# ... reproduzieren, dann:
pktmon stop
pktmon etl2txt capture.etl -o capture.txt

tcpdump (WSL/Npcap) Outil complémentaire

tcpdump -i eth0 -n -c 200 port 587

Shell Unix (bash)

tcpdump Natif

tcpdump -i eth0 -nn -c 200 port 587

tshark Outil complémentaire

tshark -i eth0 -c 200 -f "port 587"

pktmon est fourni avec Windows 10/Server 2019 et versions ultérieures et nécessite une session administrateur. Sous Linux, tcpdump nécessite root ou la capacité CAP_NET_RAW.

Capturer un correspondant

Capture uniquement le trafic vers un correspondant, quel que soit le port.

PowerShell (Windows)

netsh trace Natif

netsh trace start capture=yes tracefile=C:\temp\trace.etl maxsize=200 Ethernet.Type=IPv4 IPv4.Address=mail.example.com
# ... reproduzieren, dann:
netsh trace stop

tcpdump (WSL/Npcap) Outil complémentaire

tcpdump -i eth0 -nn -c 200 host mail.example.com

Shell Unix (bash)

tcpdump Natif

tcpdump -i eth0 -nn -c 200 host mail.example.com

tshark Outil complémentaire

tshark -i eth0 -c 200 -f "host mail.example.com"

netsh trace écrit un fichier ETL que vous pouvez ouvrir dans Microsoft Network Monitor, ou dans Wireshark après conversion.

Lire le dialogue SMTP

Affiche la conversation SMTP en clair : commandes, codes de réponse et messages d'erreur du correspondant.

PowerShell (Windows)

pktmon Natif

pktmon filter remove
pktmon filter add -p 25
pktmon start --capture --pkt-size 0 -f smtp.etl
# ... reproduzieren, dann: pktmon stop; pktmon etl2txt smtp.etl -o smtp.txt

tcpdump (WSL/Npcap) Outil complémentaire

tcpdump -i eth0 -nn -A -s 0 port 25

Shell Unix (bash)

tcpdump Natif

tcpdump -i eth0 -nn -A -s 0 port 25

tshark Outil complémentaire

tshark -i eth0 -Y smtp -T fields -e smtp.req.command -e smtp.req.parameter -e smtp.rsp.code

Cela ne fonctionne qu'en clair (port 25 sans STARTTLS). Dès que TLS intervient, le contenu est chiffré et seul le handshake reste visible.

Capturer dans un fichier

Écrit la capture dans un fichier pour l'analyser plus tard (par exemple dans Wireshark).

PowerShell (Windows)

pktmon Natif

pktmon filter remove
pktmon filter add -p 25
pktmon start --capture --pkt-size 0 -f capture.etl
# ... reproduzieren, dann: pktmon stop
pktmon pcapng capture.etl -o capture.pcapng

tcpdump (WSL/Npcap) Outil complémentaire

tcpdump -i eth0 -nn -s 0 -w capture.pcap port 25

Shell Unix (bash)

tcpdump Natif

tcpdump -i eth0 -nn -s 0 -w capture.pcap port 25
tcpdump -r capture.pcap -nn | head -50

tshark Outil complémentaire

tshark -i eth0 -w capture.pcap -f "port 25"

pktmon écrit au format ETL et peut le convertir avec "pktmon pcapng" dans un format lisible par Wireshark.

Connexions ouvertes

Affiche les connexions établies vers un correspondant avec le processus : une alternative rapide quand une capture n'est pas possible.

PowerShell (Windows)

Get-NetTCPConnection Natif

Get-NetTCPConnection -RemoteAddress (Resolve-DnsName mail.example.com -Type A).IPAddress -ErrorAction SilentlyContinue |
  Select-Object LocalPort, RemoteAddress, RemotePort, State, OwningProcess

netstat Natif

netstat -ano | findstr ESTABLISHED

Shell Unix (bash)

ss Natif

ss -tnp state established "dst mail.example.com"

lsof Outil complémentaire

lsof -nP -iTCP -sTCP:ESTABLISHED | grep mail.example.com

Autres domaines