Skip to content

Instantly share code, notes, and snippets.

@fritschy
Created December 17, 2019 11:01
Show Gist options
  • Save fritschy/ddb2af5ed4fbeef64535d669a24a64e3 to your computer and use it in GitHub Desktop.
Save fritschy/ddb2af5ed4fbeef64535d669a24a64e3 to your computer and use it in GitHub Desktop.
How to disassemble a pcap BPF program
#!/bin/sh
(
echo -n load bpf ""
sudo tcpdump -ilo -ddd "$@" | tr '\n' ','
echo
echo disassemble
) | bpf_dbg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment