Jump to content

Linux Tools For Extracting Files From Pcap Files


Recommended Posts

Posted

Hi,

in episode 902 of hak5, snubs does a walkthru of the CCC challange for Feb 27. One of the tools used was networkminer. She was able to extract a file from a pcap file called kerberos.jpg using networkminer. The file came out perfectly fine. I have not tried networkminer myself but am sure that I would get the same results.

However I tried using linux tools such as foremost, tcpxtract, dsniff suit to carry out the same funtion. But when I look at the kerberos.jpg file for example its corrupted. See the attached pic to see what I mean.

My question is are there any reliable linux tools for parsing a pcap file and dumping any files found. Foremost and tcpxtract seem to do a good job of the parsing bit, but as from seen here somehow the pics are corrupted.

post-16262-0-44987100-1301338102_thumb.j

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...