Live data from Hacker News

A tcpdump tutorial and primer

danielmiessler.com

31–33 of 33 posts

Re: A tcpdump tutorial and primer

#31
post #27

Earlier quoted context omitted.

It feels like ssldump has been abandoned and is horribly out-of-date. Is anybody maintaining it these days?

I use ssldump all the time; I don't think it's actively maintained, but it's not like it's broken. (The author of ssldump is one of the chairs of the TLS WG).

Last time I used it (quite a few months ago) it wasn't recognizing about half the fields in the SSL negotiation. It wasn't useless, but aside from its decryption-capabilities[1] wireshark had it beat because it could recognize and parse nearly all the fields.

[1] Wireshark might have that, but I haven't checked. I like to keep diversity in the tools I use.

Post reply on HN