On Wed, Feb 24, 2010 at 12:35 PM, Eduardo M KALINOWSKI <edua...@kalinowski.com.br> wrote: > On Qua, 24 Fev 2010, Jon Dowland wrote: >> >> What is the actual protocol you are trying to read? You >> probably need to use a friendly protocol dissector to read >> and interpret your packet capture. Wireshark can do this. >> >> # tcpdump src 172.16.4.1 -w output-file >> $ sudo wireshark output-file > > Since wireshark will be only looking at a previously captured file (and not > doing captures itself), it does not need root privileges, right? >
This is correct. I always open previously captured files in wireshark as an unprivledged user. -- Jordan Metzmeier -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/50e5edd51002240955n74321097rbcfefc95854b8...@mail.gmail.com