Re: Best sniffer?
John Galt <firstname.lastname@example.org> wrote:
>Ethereal (sp) is good and provides a lot of information, but I have an
>aversion to throwing X into the picture when running a packet sniffer
>because it's using system resources that could be processing packets...
You could always capture from tcpdump and use ethereal to read the
capture files, then.
tcpflow is excellent if I need to read a short protocol transaction
quickly, which is the usual reason I find myself resorting to a packet
Colin Watson [email@example.com]