{"id":1193,"date":"2020-06-14T23:11:51","date_gmt":"2020-06-14T13:11:51","guid":{"rendered":"https:\/\/blog.hegars.com\/?p=1193"},"modified":"2021-12-29T13:54:51","modified_gmt":"2021-12-29T03:54:51","slug":"tzsp-to-pcap","status":"publish","type":"post","link":"https:\/\/blog.hegars.com\/?p=1193","title":{"rendered":"TZSP to PCAP"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><a href=\"https:\/\/xn--blgg-hra.no\/2015\/03\/ids-with-mikrotik-and-snort\/\">https:\/\/xn--blgg-hra.no\/2015\/03\/ids-with-mikrotik-and-snort\/<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">tzsp2pcap<\/h2>\n\n\n\n<p><a href=\"https:\/\/github.com\/thefloweringash\/tzsp2pcap\">https:\/\/github.com\/thefloweringash\/tzsp2pcap<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">compile and prereqs<\/h3>\n\n\n\n<p>apt-get install vim curl sudo build-essential libpcap-dev libpcap0.8<\/p>\n\n\n\n<p>git clone https:\/\/github.com\/thefloweringash\/tzsp2pcap.git<\/p>\n\n\n\n<p>make<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Running Wireshark<\/h2>\n\n\n\n<p># .\/tzsp2pcap -f | wireshark -i &#8211;<\/p>\n\n\n\n<p>using this strips the tzsp headers and encapsulation headers<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"697\" src=\"https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/Annotation-2020-06-14-230611-1024x697.png\" alt=\"\" class=\"wp-image-1194\" srcset=\"https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/Annotation-2020-06-14-230611-1024x697.png 1024w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/Annotation-2020-06-14-230611-300x204.png 300w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/Annotation-2020-06-14-230611-768x523.png 768w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/Annotation-2020-06-14-230611-1080x735.png 1080w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/Annotation-2020-06-14-230611.png 1115w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Using wireshark SSH remote capture<\/h3>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"311\" src=\"https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/image.png\" alt=\"\" class=\"wp-image-1197\" srcset=\"https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/image.png 609w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2020\/06\/image-300x153.png 300w\" sizes=\"(max-width: 609px) 100vw, 609px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Debian 11 Notes<\/h2>\n\n\n\n<p>sha1 ciphers are removed by default, need to use dev chain of wireshark with never libssh for sshdump<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Using dumpcap<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-1024x516.png\" alt=\"\" class=\"wp-image-1706\" srcset=\"https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-1024x516.png 1024w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-300x151.png 300w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-768x387.png 768w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-1080x544.png 1080w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-980x494.png 980w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6-480x242.png 480w, https:\/\/blog.hegars.com\/wp-content\/uploads\/2021\/09\/image-6.png 1234w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>\/usr\/bin\/dumpcap -P -w &#8211; -i ztrf25twc4<\/p>\n\n\n\n<p>With Filter Applied<\/p>\n\n\n\n<p>\/usr\/sbin\/dumpcap -i eth0 -f &#8220;host xxx.xxx.xxx.xxx&#8221; -w &#8211;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">MQTT<\/h2>\n\n\n\n<p>-n vs -P n verses old pcap format<\/p>\n\n\n\n<p>\/usr\/bin\/dumpcap -n -w &#8211; -i br0 -f &#8220;port 1883&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/xn--blgg-hra.no\/2015\/03\/ids-with-mikrotik-and-snort\/ tzsp2pcap https:\/\/github.com\/thefloweringash\/tzsp2pcap compile and prereqs apt-get install vim curl sudo build-essential libpcap-dev libpcap0.8 git clone https:\/\/github.com\/thefloweringash\/tzsp2pcap.git make Running Wireshark # .\/tzsp2pcap -f | wireshark -i &#8211; using this strips the tzsp headers and encapsulation headers Using wireshark SSH remote capture Debian 11 Notes sha1 ciphers are removed by default, need to use dev chain [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[6,36,2],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.hegars.com\/index.php?rest_route=\/wp\/v2\/posts\/1193"}],"collection":[{"href":"https:\/\/blog.hegars.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hegars.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hegars.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hegars.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1193"}],"version-history":[{"count":8,"href":"https:\/\/blog.hegars.com\/index.php?rest_route=\/wp\/v2\/posts\/1193\/revisions"}],"predecessor-version":[{"id":1852,"href":"https:\/\/blog.hegars.com\/index.php?rest_route=\/wp\/v2\/posts\/1193\/revisions\/1852"}],"wp:attachment":[{"href":"https:\/\/blog.hegars.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hegars.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hegars.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}