Created
February 16, 2017 13:49
-
-
Save korc/30760df61d501ebe67be60a1274293be to your computer and use it in GitHub Desktop.
Convert $SSH_CONNECTION to pcap filter
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/bin/sh | |
test -n "$SSH_CONNECTION" || { | |
echo "No SSH_CONNECTION defined." >&2 | |
echo "Example usage: ssh host dumpcap -P -i eth0 -f '\"not \$(${0##*/})\"' -w - | wireshark -k -i -" >&2 | |
exit 1 | |
} | |
read h1 p1 h2 p2 <<EOF | |
$SSH_CONNECTION | |
EOF | |
echo "((host $h1 and port $p1) and (host $h2 and port $p2))" |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment