Richard Sharpe said: > What's wrong with using tcpdump? ...with the "-S" option, otherwise tcpdump *also* maintains state (per-connection state, so it can show relative sequence numbers). (I assume it's not being run when writing to a capture file; if tcpdump is being run with "-w" and a given capture filter, it won't maintain per-connection state, as it doesn't dissect packets - but the same is true of tethereal, so tcpdump vs. tethereal makes no difference in that case).
Powered by MHonArc 2.6.10