Cattura di pacchetti
Cattura di pacchetti e connessioni aperte: vedere che cosa passa davvero sulla rete.
Catturare una porta
Cattura il traffico su una porta: la risposta più affidabile alla domanda se i pacchetti arrivano davvero.
SMTP (25)
- Interfaccia di rete
-
eth0Modifica nel generatore → - Numero di pacchetti
-
200Modifica nel generatore →
PowerShell (Windows)
pktmon Integrato
pktmon filter remove
pktmon filter add -p 25
pktmon start --capture --pkt-size 0 -f capture.etl
# ... reproduzieren, dann:
pktmon stop
pktmon etl2txt capture.etl -o capture.txt tcpdump (WSL/Npcap) Strumento aggiuntivo
tcpdump -i eth0 -n -c 200 port 25 Shell Unix (bash)
tcpdump Integrato
tcpdump -i eth0 -nn -c 200 port 25 tshark Strumento aggiuntivo
tshark -i eth0 -c 200 -f "port 25" Submission (587)
- Interfaccia di rete
-
eth0Modifica nel generatore → - Numero di pacchetti
-
200Modifica nel generatore →
PowerShell (Windows)
pktmon Integrato
pktmon filter remove
pktmon filter add -p 587
pktmon start --capture --pkt-size 0 -f capture.etl
# ... reproduzieren, dann:
pktmon stop
pktmon etl2txt capture.etl -o capture.txt tcpdump (WSL/Npcap) Strumento aggiuntivo
tcpdump -i eth0 -n -c 200 port 587 Shell Unix (bash)
tcpdump Integrato
tcpdump -i eth0 -nn -c 200 port 587 tshark Strumento aggiuntivo
tshark -i eth0 -c 200 -f "port 587" pktmon è incluso in Windows 10/Server 2019 e versioni successive e richiede una sessione da amministratore. Su Linux, tcpdump richiede root o la capability CAP_NET_RAW.
Catturare un interlocutore
Cattura solo il traffico verso un interlocutore, indipendentemente dalla porta.
- Interfaccia di rete
-
eth0Modifica nel generatore → - Host / server
-
mail.example.comModifica nel generatore → - Numero di pacchetti
-
200Modifica nel generatore →
PowerShell (Windows)
netsh trace Integrato
netsh trace start capture=yes tracefile=C:\temp\trace.etl maxsize=200 Ethernet.Type=IPv4 IPv4.Address=mail.example.com
# ... reproduzieren, dann:
netsh trace stop tcpdump (WSL/Npcap) Strumento aggiuntivo
tcpdump -i eth0 -nn -c 200 host mail.example.com Shell Unix (bash)
tcpdump Integrato
tcpdump -i eth0 -nn -c 200 host mail.example.com tshark Strumento aggiuntivo
tshark -i eth0 -c 200 -f "host mail.example.com" netsh trace scrive un file ETL che si può aprire in Microsoft Network Monitor, oppure in Wireshark dopo la conversione.
Leggere il dialogo SMTP
Mostra in chiaro la conversazione SMTP: comandi, codici di risposta e messaggi di errore dell'interlocutore.
- Interfaccia di rete
-
eth0Modifica nel generatore →
PowerShell (Windows)
pktmon Integrato
pktmon filter remove
pktmon filter add -p 25
pktmon start --capture --pkt-size 0 -f smtp.etl
# ... reproduzieren, dann: pktmon stop; pktmon etl2txt smtp.etl -o smtp.txt tcpdump (WSL/Npcap) Strumento aggiuntivo
tcpdump -i eth0 -nn -A -s 0 port 25 Shell Unix (bash)
tcpdump Integrato
tcpdump -i eth0 -nn -A -s 0 port 25 tshark Strumento aggiuntivo
tshark -i eth0 -Y smtp -T fields -e smtp.req.command -e smtp.req.parameter -e smtp.rsp.code Funziona solo senza cifratura (porta 25 senza STARTTLS). Non appena entra in gioco TLS, il contenuto è cifrato e resta visibile solo l'handshake.
Catturare in un file
Scrive la cattura in un file per analizzarla in seguito (ad esempio in Wireshark).
- Interfaccia di rete
-
eth0Modifica nel generatore → - File di destinazione
-
capture.pcapModifica nel generatore →
PowerShell (Windows)
pktmon Integrato
pktmon filter remove
pktmon filter add -p 25
pktmon start --capture --pkt-size 0 -f capture.etl
# ... reproduzieren, dann: pktmon stop
pktmon pcapng capture.etl -o capture.pcapng tcpdump (WSL/Npcap) Strumento aggiuntivo
tcpdump -i eth0 -nn -s 0 -w capture.pcap port 25 Shell Unix (bash)
tcpdump Integrato
tcpdump -i eth0 -nn -s 0 -w capture.pcap port 25
tcpdump -r capture.pcap -nn | head -50 tshark Strumento aggiuntivo
tshark -i eth0 -w capture.pcap -f "port 25" pktmon scrive in formato ETL e può convertirlo con "pktmon pcapng" in un formato leggibile da Wireshark.
Connessioni aperte
Mostra le connessioni stabilite verso un interlocutore con il relativo processo: un'alternativa rapida quando una cattura non è possibile.
- Host / server
-
mail.example.comModifica nel generatore →
PowerShell (Windows)
Get-NetTCPConnection Integrato
Get-NetTCPConnection -RemoteAddress (Resolve-DnsName mail.example.com -Type A).IPAddress -ErrorAction SilentlyContinue |
Select-Object LocalPort, RemoteAddress, RemotePort, State, OwningProcess netstat Integrato
netstat -ano | findstr ESTABLISHED Shell Unix (bash)
ss Integrato
ss -tnp state established "dst mail.example.com" lsof Strumento aggiuntivo
lsof -nP -iTCP -sTCP:ESTABLISHED | grep mail.example.com