> -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of > Clint M. Sand > Sent: Wednesday, July 20, 2005 12:15 PM > To: misc@openbsd.org > Cc: [EMAIL PROTECTED] > Subject: Re: sniffer > > On Tue, Jul 19, 2005 at 11:28:08AM -0500, eric wrote: > > On Tue, 2005-07-19 at 17:20:43 +0300, [EMAIL PROTECTED] proclaimed... > > > > > I need to sniff a network segment and I need to sniff both headers > and > > > data. Because tcpdump captures only headers its unsuitable for the > task. > > > I saw that ports has ettercap and sniffit but I didn' get around to > > > testing them to see if they will do the job I need. Can anyone > recommend > > > other tools that will do the work? > > > > Go read the manpage for tcpdump. Then go get tcpshow or something > similar. > > You don't need tcpshow. See -X for tcpdump.
Speaking of tcpdump and other tools....Anyone know how to capture the entire layer 2 ethernet frame?