Whistle Master Posted April 25, 2012 Posted April 25, 2012 (edited) Hi everyone ! I present my new module for our pineapple, a tcpdump interface Module will be available through module system. Still need more test but if some of you want to beta test, ask me by PM and I will send you the test version Features - Dump history - Tcpdump options selection - Filter creation Edited August 7, 2012 by Whistle Master Quote
MarcusW Posted April 25, 2012 Posted April 25, 2012 Hi everyone ! I present my new module for our pineapple, a tcpdump interface :) Wheee! Thanks :) Quote
Marlboro Filter Posted April 26, 2012 Posted April 26, 2012 Hoooorrraaayy,.....Thank you WM for your effort Quote
Isolot Posted April 26, 2012 Posted April 26, 2012 whistle master your a king amongst men! any chance of the same thing for sslstrip? Quote
MarcusW Posted April 26, 2012 Posted April 26, 2012 (edited) ...and it's been published. Playing with it while I write this. Lovely. Thanks! Edit: Been having success with this filter to capture all http posts, but admittedly my tcpdump-fu is weak: tcpdump -i 3g-wan2 'port 80 and (tcp[20:4] = 1347375956 or tcp[24:4] = 1347375956 or tcp[28:4] = 1347375956 or tcp[32:4] = 1347375956 or tcp[36:4] = 1347375956 or tcp[40:4] = 1347375956 or tcp[44:4] = 1347375956 or tcp[48:4] = 1347375956 or tcp[52:4] = 1347375956 or tcp[56:4] = 1347375956 or tcp[60:4] = 1347375956)' Based on this post: http://superuser.com/questions/286062/practical-tcpdump-examples Edited April 26, 2012 by MarcusW Quote
telot Posted April 27, 2012 Posted April 27, 2012 Ask and you shall receive! FROM WM! Thanks dude! telot Quote
WatskeBart Posted April 29, 2012 Posted April 29, 2012 P.S. Don't forget to update the wiki ;) I wanted to add the module but i don't have rights to do so :) Quote
krasmussen Posted August 16, 2013 Posted August 16, 2013 Hopefully I am posting this in the right location if not mods feel free to move this. I noticed with the tcpdump infusion it spits out that it fails to load libpcap.so.1.3 With a little browsing around the system I noticed that libpcap.so.1.3 isn't on there... however libpcap.so.1.1.1 is. Anyone who runs into this issue should be able to symlink libpcap.so.1.3 to libpcap.so.1.1.1 and it should work (or atleast did for me) by doing the following over either ssh or from the "Execute Commands" menu in the gui. ln -s /usr/lib/libpcap.so /usr/lib/libpcap.so.1.3 NOTE: /usr/lib/libpcap.so is itself linked to libpcap.so.1.1.1 on my pineapple. Quote
Whistle Master Posted August 16, 2013 Author Posted August 16, 2013 Thanks for your report ! It relates to the firmware itself, I suggest that you create a new bug report as well. Quote
blueAlien Posted September 12, 2013 Posted September 12, 2013 Is there a way to send the dump file over an ssh connection so that you don't have to worry about filling up the Pineapple's onboard storage? Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.