ScratchMonkey ScratchMonkey at MatureAsskickers.net
Wed Nov 9 18:40:07 EST 2005

--On Wednesday, November 09, 2005 10:59 PM +0100 Jorrit Schippers 
<jorrit at gameparty.net> wrote:

> The golden rule stays: use ethereal to read the communications and
> immitate those communications exactly.

For Linux systems with no display, use this tcpdump command:

tcpdump -w capture.log -s 500 host {ipaddress}

This writes the first 500 bytes of all packets to that log file. Copy the 
result back to your Windows box and load it in Ethereal to analyze.

I use this idiom all the time to analyze suspicious traffic on my gateways. 
If you have a Linksys WRT54G for your home router, you can re-flash it with 
a custom Linux build (I use the one from Sveasoft) and run tcpdump on it. 
Get the newer GS model if you can, as it has more memory so you can use the 
fancier custom builds and log more data.

