|
@@ -1,6 +1,6 @@
|
|
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
|
|
|
|
|
|
-<!--Converted with LaTeX2HTML 2002-2-1 (1.70)
|
|
|
+<!--Converted with LaTeX2HTML 2002-2 (1.70)
|
|
|
original version by: Nikos Drakos, CBLU, University of Leeds
|
|
|
* revised and updated by: Marcus Hennecke, Ross Moore, Herb Swan
|
|
|
* with significant contributions from:
|
|
@@ -14,7 +14,7 @@ original version by: Nikos Drakos, CBLU, University of Leeds
|
|
|
<META NAME="distribution" CONTENT="global">
|
|
|
|
|
|
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
|
|
|
-<META NAME="Generator" CONTENT="LaTeX2HTML v2002-2-1">
|
|
|
+<META NAME="Generator" CONTENT="LaTeX2HTML v2002-2">
|
|
|
<META HTTP-EQUIV="Content-Style-Type" CONTENT="text/css">
|
|
|
|
|
|
<LINK REL="STYLESHEET" HREF="FAQ.css">
|
|
@@ -28,26 +28,26 @@ original version by: Nikos Drakos, CBLU, University of Leeds
|
|
|
<BODY >
|
|
|
|
|
|
<DIV CLASS="navigation"><!--Navigation Panel-->
|
|
|
-<A NAME="tex2html132"
|
|
|
+<A NAME="tex2html134"
|
|
|
HREF="node3.html">
|
|
|
<IMG WIDTH="37" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="next" SRC="next.png"></A>
|
|
|
-<A NAME="tex2html128"
|
|
|
+<A NAME="tex2html130"
|
|
|
HREF="FAQ.html">
|
|
|
<IMG WIDTH="26" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="up" SRC="up.png"></A>
|
|
|
-<A NAME="tex2html122"
|
|
|
+<A NAME="tex2html124"
|
|
|
HREF="node1.html">
|
|
|
<IMG WIDTH="63" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="previous" SRC="prev.png"></A>
|
|
|
-<A NAME="tex2html130"
|
|
|
+<A NAME="tex2html132"
|
|
|
HREF="node1.html">
|
|
|
<IMG WIDTH="65" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="contents" SRC="contents.png"></A>
|
|
|
<BR>
|
|
|
-<B> Next:</B> <A NAME="tex2html133"
|
|
|
+<B> Next:</B> <A NAME="tex2html135"
|
|
|
HREF="node3.html">2 Bugs, Feature Requests,</A>
|
|
|
-<B> Up:</B> <A NAME="tex2html129"
|
|
|
+<B> Up:</B> <A NAME="tex2html131"
|
|
|
HREF="FAQ.html">Tcpreplay 3.x FAQ</A>
|
|
|
-<B> Previous:</B> <A NAME="tex2html123"
|
|
|
+<B> Previous:</B> <A NAME="tex2html125"
|
|
|
HREF="node1.html">Contents</A>
|
|
|
- <B> <A NAME="tex2html131"
|
|
|
+ <B> <A NAME="tex2html133"
|
|
|
HREF="node1.html">Contents</A></B>
|
|
|
<BR>
|
|
|
<BR></DIV>
|
|
@@ -56,29 +56,29 @@ original version by: Nikos Drakos, CBLU, University of Leeds
|
|
|
<A NAME="CHILD_LINKS"><STRONG>Subsections</STRONG></A>
|
|
|
|
|
|
<UL CLASS="ChildLinks">
|
|
|
-<LI><A NAME="tex2html134"
|
|
|
+<LI><A NAME="tex2html136"
|
|
|
HREF="node2.html#SECTION00021000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">1</SPAN> What is this FAQ for?</A>
|
|
|
-<LI><A NAME="tex2html135"
|
|
|
+<LI><A NAME="tex2html137"
|
|
|
HREF="node2.html#SECTION00022000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">2</SPAN> What tools come with tcpreplay?</A>
|
|
|
-<LI><A NAME="tex2html136"
|
|
|
+<LI><A NAME="tex2html138"
|
|
|
HREF="node2.html#SECTION00023000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">3</SPAN> What tools no longer come with Tcpreplay?</A>
|
|
|
-<LI><A NAME="tex2html137"
|
|
|
+<LI><A NAME="tex2html139"
|
|
|
HREF="node2.html#SECTION00024000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">4</SPAN> How can I get tcpreplay's source?</A>
|
|
|
-<LI><A NAME="tex2html138"
|
|
|
+<LI><A NAME="tex2html140"
|
|
|
HREF="node2.html#SECTION00025000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">5</SPAN> What requirements does tcpreplay have?</A>
|
|
|
-<LI><A NAME="tex2html139"
|
|
|
+<LI><A NAME="tex2html141"
|
|
|
HREF="node2.html#SECTION00026000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">6</SPAN> Are there binaries available?</A>
|
|
|
-<LI><A NAME="tex2html140"
|
|
|
+<LI><A NAME="tex2html142"
|
|
|
HREF="node2.html#SECTION00027000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">7</SPAN> Is there a Microsoft Windows port?</A>
|
|
|
-<LI><A NAME="tex2html141"
|
|
|
+<LI><A NAME="tex2html143"
|
|
|
HREF="node2.html#SECTION00028000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">8</SPAN> How is tcpreplay licensed?</A>
|
|
|
-<LI><A NAME="tex2html142"
|
|
|
+<LI><A NAME="tex2html144"
|
|
|
HREF="node2.html#SECTION00029000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">9</SPAN> What is tcpreplay?</A>
|
|
|
-<LI><A NAME="tex2html143"
|
|
|
+<LI><A NAME="tex2html145"
|
|
|
HREF="node2.html#SECTION000210000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">10</SPAN> What are some uses for tcpreplay?</A>
|
|
|
-<LI><A NAME="tex2html144"
|
|
|
+<LI><A NAME="tex2html146"
|
|
|
HREF="node2.html#SECTION000211000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">11</SPAN> What are some uses for flowreplay?</A>
|
|
|
-<LI><A NAME="tex2html145"
|
|
|
+<LI><A NAME="tex2html147"
|
|
|
HREF="node2.html#SECTION000212000000000000000"><SPAN CLASS="arabic">1</SPAN>.<SPAN CLASS="arabic">12</SPAN> What is the history of tcpreplay?</A>
|
|
|
</UL>
|
|
|
<!--End of Table of Child-Links-->
|
|
@@ -121,7 +121,7 @@ were captured
|
|
|
<LI>tcpprep - a pcap pre-processor for tcpreplay
|
|
|
</LI>
|
|
|
<LI>flowreplay<A NAME="tex2html1"
|
|
|
- HREF="#foot136"><SUP><SPAN CLASS="arabic">1</SPAN></SUP></A> - connects to a server(s) and replays the client side of the connection
|
|
|
+ HREF="#foot153"><SUP><SPAN CLASS="arabic">1</SPAN></SUP></A> - connects to a server(s) and replays the client side of the connection
|
|
|
stored in a pcap file
|
|
|
</LI>
|
|
|
</UL>
|
|
@@ -134,7 +134,7 @@ stored in a pcap file
|
|
|
|
|
|
<P>
|
|
|
Recently, other people and projects have developed better versions
|
|
|
-of two applications that ship with tcpreplay 2.x:
|
|
|
+of two applications that shipped with tcpreplay 2.x:
|
|
|
|
|
|
<P>
|
|
|
|
|
@@ -160,7 +160,7 @@ with Subversion to try checking out the latest code as it often has
|
|
|
additional features and bugfixes not found in the tarballs.
|
|
|
|
|
|
<P>
|
|
|
-svn checkout https://www.synfin.net:444/svn/tcpreplay/trunk tcpreplay
|
|
|
+svn checkout https://www.synfin.net/svn/tcpreplay/trunk tcpreplay
|
|
|
|
|
|
<P>
|
|
|
|
|
@@ -172,11 +172,11 @@ svn checkout https://www.synfin.net:444/svn/tcpreplay/trunk tcpreplay
|
|
|
|
|
|
<OL>
|
|
|
<LI>You'll need recent versions of the libnet<A NAME="tex2html2"
|
|
|
- HREF="#foot36"><SUP><SPAN CLASS="arabic">2</SPAN></SUP></A> and libpcap<A NAME="tex2html3"
|
|
|
- HREF="#foot37"><SUP><SPAN CLASS="arabic">3</SPAN></SUP></A> libraries.
|
|
|
+ HREF="#foot38"><SUP><SPAN CLASS="arabic">2</SPAN></SUP></A> and libpcap<A NAME="tex2html3"
|
|
|
+ HREF="#foot39"><SUP><SPAN CLASS="arabic">3</SPAN></SUP></A> libraries.
|
|
|
</LI>
|
|
|
<LI>To support the packet decoding feature you'll need tcpdump<A NAME="tex2html4"
|
|
|
- HREF="#foot38"><SUP><SPAN CLASS="arabic">4</SPAN></SUP></A> installed.
|
|
|
+ HREF="#foot40"><SUP><SPAN CLASS="arabic">4</SPAN></SUP></A> installed.
|
|
|
</LI>
|
|
|
<LI>You'll also need a compatible operating system. Basically, any UNIX-like
|
|
|
or UNIX-based operating system should work. Linux, *BSD, Solaris,
|
|
@@ -245,7 +245,7 @@ Originally, tcpreplay was written to test network intrusion detection
|
|
|
systems (NIDS), however tcpreplay has been used to test firewalls,
|
|
|
routers, and other network devices. With the addition of flowreplay,
|
|
|
most<A NAME="tex2html5"
|
|
|
- HREF="#foot46"><SUP><SPAN CLASS="arabic">5</SPAN></SUP></A> any udp or tcp service on a server can be tested as well.
|
|
|
+ HREF="#foot48"><SUP><SPAN CLASS="arabic">5</SPAN></SUP></A> any udp or tcp service on a server can be tested as well.
|
|
|
|
|
|
<P>
|
|
|
|
|
@@ -263,7 +263,9 @@ systems (HIDS) as well as captured exploits and security patches when
|
|
|
the actual exploit code is not available. Please note that flowreplay
|
|
|
is still alpha quality code which means it doesn't work very well
|
|
|
(some would argue it doesn't work at all) and is currently missing
|
|
|
-some important features.
|
|
|
+some important features. Feel free to try flowreplay, but unless you're
|
|
|
+willing and able to contribute, don't bother complaining that it doesn't
|
|
|
+work.
|
|
|
|
|
|
<P>
|
|
|
|
|
@@ -284,9 +286,9 @@ was (at least partially) purchased by NFR and development ceased.
|
|
|
|
|
|
<P>
|
|
|
Then in 2001, two people independently started work on tcpreplay:
|
|
|
-Matt Bing of NFR and Aaron Turner. After developing a series of patches
|
|
|
-(the -adt branch), Aaron attempted to send the patches in to be included
|
|
|
-in the main development tree.
|
|
|
+Matt Bing of NFR and Aaron Turner of OneSecure. After developing a
|
|
|
+series of patches (the -adt branch), Aaron attempted to send the patches
|
|
|
+in to be included in the main development tree.
|
|
|
|
|
|
<P>
|
|
|
After some discussion between Aaron and Matt Bing, they decided to
|
|
@@ -300,29 +302,29 @@ Today, Aaron continues active development of the code.
|
|
|
<P>
|
|
|
<BR><HR><H4>Footnotes</H4>
|
|
|
<DL>
|
|
|
-<DT><A NAME="foot136">... flowreplay</A><A
|
|
|
+<DT><A NAME="foot153">... flowreplay</A><A
|
|
|
HREF="node2.html#tex2html1"><SUP><SPAN CLASS="arabic">1</SPAN></SUP></A></DT>
|
|
|
<DD>Flowreplay is still ``alpha'' quality and is not usable for most
|
|
|
situations. Anyone interested in helping me develop flowreplay is
|
|
|
encouraged to contact me.
|
|
|
|
|
|
</DD>
|
|
|
-<DT><A NAME="foot36">... libnet</A><A
|
|
|
+<DT><A NAME="foot38">... libnet</A><A
|
|
|
HREF="node2.html#tex2html2"><SUP><SPAN CLASS="arabic">2</SPAN></SUP></A></DT>
|
|
|
<DD>http://www.packetfactory.net/libnet/
|
|
|
|
|
|
</DD>
|
|
|
-<DT><A NAME="foot37">... libpcap</A><A
|
|
|
+<DT><A NAME="foot39">... libpcap</A><A
|
|
|
HREF="node2.html#tex2html3"><SUP><SPAN CLASS="arabic">3</SPAN></SUP></A></DT>
|
|
|
<DD>http://www.tcpdump.org/
|
|
|
|
|
|
</DD>
|
|
|
-<DT><A NAME="foot38">... tcpdump</A><A
|
|
|
+<DT><A NAME="foot40">... tcpdump</A><A
|
|
|
HREF="node2.html#tex2html4"><SUP><SPAN CLASS="arabic">4</SPAN></SUP></A></DT>
|
|
|
<DD>http://www.tcpdump.org/
|
|
|
|
|
|
</DD>
|
|
|
-<DT><A NAME="foot46">...
|
|
|
+<DT><A NAME="foot48">...
|
|
|
most</A><A
|
|
|
HREF="node2.html#tex2html5"><SUP><SPAN CLASS="arabic">5</SPAN></SUP></A></DT>
|
|
|
<DD>Note the flowreplay does not support protocols such as ftp which use
|
|
@@ -332,31 +334,31 @@ multiple connections.
|
|
|
</DL>
|
|
|
<DIV CLASS="navigation"><HR>
|
|
|
<!--Navigation Panel-->
|
|
|
-<A NAME="tex2html132"
|
|
|
+<A NAME="tex2html134"
|
|
|
HREF="node3.html">
|
|
|
<IMG WIDTH="37" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="next" SRC="next.png"></A>
|
|
|
-<A NAME="tex2html128"
|
|
|
+<A NAME="tex2html130"
|
|
|
HREF="FAQ.html">
|
|
|
<IMG WIDTH="26" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="up" SRC="up.png"></A>
|
|
|
-<A NAME="tex2html122"
|
|
|
+<A NAME="tex2html124"
|
|
|
HREF="node1.html">
|
|
|
<IMG WIDTH="63" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="previous" SRC="prev.png"></A>
|
|
|
-<A NAME="tex2html130"
|
|
|
+<A NAME="tex2html132"
|
|
|
HREF="node1.html">
|
|
|
<IMG WIDTH="65" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="contents" SRC="contents.png"></A>
|
|
|
<BR>
|
|
|
-<B> Next:</B> <A NAME="tex2html133"
|
|
|
+<B> Next:</B> <A NAME="tex2html135"
|
|
|
HREF="node3.html">2 Bugs, Feature Requests,</A>
|
|
|
-<B> Up:</B> <A NAME="tex2html129"
|
|
|
+<B> Up:</B> <A NAME="tex2html131"
|
|
|
HREF="FAQ.html">Tcpreplay 3.x FAQ</A>
|
|
|
-<B> Previous:</B> <A NAME="tex2html123"
|
|
|
+<B> Previous:</B> <A NAME="tex2html125"
|
|
|
HREF="node1.html">Contents</A>
|
|
|
- <B> <A NAME="tex2html131"
|
|
|
+ <B> <A NAME="tex2html133"
|
|
|
HREF="node1.html">Contents</A></B> </DIV>
|
|
|
<!--End of Navigation Panel-->
|
|
|
<ADDRESS>
|
|
|
Aaron Turner
|
|
|
-2005-08-07
|
|
|
+2006-07-17
|
|
|
</ADDRESS>
|
|
|
</BODY>
|
|
|
</HTML>
|