Penetration Testing mailing list archives

Re: Split Kismet log file


From: Devnull <devnull () iamdevnull info>
Date: Sat, 23 Feb 2008 12:49:33 -0500 (EST)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, 22 Feb 2008, Matheus Michels wrote:
Hey guys,

Is there any way to split up a Kismet (tcpdump/libpcap format) log file in two
or more pieces? I left Kismet sniffing in a high-traffic network and ended up
with a huge 300 MB log file (about 600.000 packets), which freezes Wireshark
if I try to dissect it. I cannot use a faster machine now, so I need to split
this file in, at most, several 30-40 MB files.

Thanks in advance.

I think tcpslice is what you want.
- -
- --
/dev/null
"We are the Pentium of Borg. Division is futile. You will be
approximated."

pubkey 0x88B82870 Sam Rakowski <devnull () iamdevnull info> fingerprint = F2AB 1805 A408 C3E8 17A0  1D91 EF0D DACE 88B8 
2870

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFHwFy47w3azoi4KHARAoXRAKDac+tdyQX//je1gp4kicn63+vieACfZAiC
yih+HjsZrH7ZAwUJm/1Tg7A=
=YqdH
-----END PGP SIGNATURE-----

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: