sshow(8) - Linux man page
Name
sshow - SSH traffic analysis tool
Synopsis
sshow [-d] [-i interface | -p pcapfile] [expression]
Description
sshow analyzes encrypted SSH-1 and SSH-2 traffic, identifying authentication attempts, the lengths of passwords entered in interactive sessions, and command line lengths.
The following advisory describes the attacks implemented by sshow in detail:
Options
- -d
Enable verbose debugging output.
- -i interface
- Specify the interface to listen on.
- -p pcapfile
- Process packets from the specified PCAP capture file instead of the network.
- expression
- Specify a tcpdump(8) filter expression to select traffic to sniff.
See Also
Authors
Solar Designer <solar@openwall.com> Dug Song <dugsong@monkey.org>