Avoiding promiscuous mode
Use the -p option to avoid putting the interface into promiscuous mode
sudo ngrep -p -W byline port 80
When observing raw or unknown protocols to show sub-protocol numbers along with single-character identifier, use the -N option with ngerp command:
sudo ngrep -N -W byline man ngrep
Ngrep – Network Packet Analyzer for Linux
Ngrep a network packet analyzer that is similar to the grep command, but ngrep grep the package on the network layer. This tool grep the traffic going to coming on the network interface.ngrep allow us to specify an extended regular or hexadecimal expression to match against data payloads of packets.ngrep can work on protocols like IPv4/6, TCP, UDP, ICMPv4/6, IGMP as well as Raw on a number of interfaces.
Contact Us