Capture the first few packets of a session?

4 views
Skip to first unread message

richard...@gmail.com

unread,
Nov 6, 2017, 6:33:54 PM11/6/17
to netsniff-ng
Hi, is it possible to configure netsniff-ng to capture just the first few bytes of a session? Maybe like the first 10K bytes. Usually I don't need the entire payload (especially on encrypted traffic) but having the first few 10K bytes will give me the IPs/ports/cert info. I know that it is possible to only capture the header info with a BPF. Thanks in advance!
Reply all
Reply to author
Forward
0 new messages