packet sniffer linux
MacSniffer 1.0b1
MacSniffer allows you to view all of the traffic on a network connection more>>
MacSniffer includes a filter editing interface and a filter library to easily construct and reuse packet filters to view a subset of all the traffic on the connection, such as just that destined for a specific host or port.
You can choose the level of detail you want captured, from just the minimal packet headers (showing source and destination hosts and ports) up to a full hex and ASCII dump of the packet contents.
MacSniffer can be useful for diagnosing many network problems, debugging client/server programs, and scanning for particular network exploits in real time.

Cocoa Packet Analyzer 0.66
It has come as a native Mac OS X implementation of a network protocol analyzer and packet sniffer. more>> <<less
packet sniffer, which supports the industry-standard PCAP packet capture format for reading ... analyzer and packet sniffer, which supports the industry-standard PCAP packet captureLicense:Freeware
native Mac OS X implementation of a network protocol analyzer and packet sniffer. Cocoa Packet ... protocol analyzer and packet sniffer. CPA supports the industry-standard PCAP packetLicense:Freeware
License:Freeware
OS X implementation of a network protocol analyzer and packet sniffer. Cocoa Packet Analyzer 0 ... of a network protocol analyzer and packet sniffer. CPA supports the industry-standard PCAPLicense:Freeware
Jens Francke - Network protocol analyzer and packet sniffer. Cocoa ... Cocoa Packet Analyzer 0.61 comes as a network protocol analyzer and packet sniffer for Mac OS XLicense:Freeware

Packet Peeper 17.8.2008
Packet Peeper offers you a comprehensive network protocol analyzer (or packet sniffer), its features include TCP stream reassembly, privilege separation, simultaneous capture sessions, filters, Python plugins, and support for pcap capture files. more>> Packet Peeper 17.8.200 offers you a comprehensive network protocol analyzer (or "packet sniffer"), its features include TCP stream reassembly, privilege separation, simultaneous capture sessions, filters, Python plugins, and support for pcap capture files.
Requirements: Mac OS X 10.4 or later.
Packtory 1
Packtory - Command line packet construction tool more>>
Equipped with a packet database manager and a checksum calculator, Packtory is a must have for any computer geek.
Packtory 1.0 is a tool for you to construct and send your TCP/IP packets. It gives you the ability ... Equipped with a packet database manager and a checksum calculator, Packtory is a must have forPacketForward 0.7.1
PacketForward - IP packet capture/forward application based on libpcap and libnet more>>
PakcetForward is a very useful command line tool that listens on one network interface for UDP and TCP packets and then injects them on the same or another network interface changing the destination address.
In order to get PacketForward to work, you have to have libpcap, libnet 1.0.2a and Nemesis installed on your system. BSD systems like Mac OS X have libcap preinstalled.
Enhancements:
- The makefile now uses the libpcap that is preinstalled on Mac OS X.
- The distributed Mac OS X (Intel) binary is now compiled to use the libpcap that is preinstalled on Mac OS X.
- Corrected minor errors in the readme file related to usage of PacketForward.
- Added a script to ease usage of PacketForward.
Justniffer 0.5.2
Free and open source TCP packet sniffer more>> Free and open source TCP packet sniffer
Justniffer captures TCP packets, reassembles and reorders them, performs IP packet defragmentation and displays the tcp flow in the standard output.
Justniffer is useful for logging network traffic in a standard (web server like) or in a customized way.
Justniffer can log timings, for example it can log the response time). It is very useful for tracking network services performances (e.g. application server, web server, etc.).
The main differences with other sniffers are:
- Justniffer captures tcp/ip traffic and handle all tcp/ip stuff (reordering, retrasmissions, defragmentation). The tcp flow adjustment is performed using linux kernel code included in a slightly modified version of the nids library.
- Justniffer reports timing informations. So it can be usefull for tracking network system performances
Enhancements
- fixed compilation issues with gcc 3.3.3
- added connection.timestamp
- fixed idle.time.0 formatting
- fixed documentation
- more adherence to RFC 2616: looking for headers in case insesitive mode
- new HTTP headers added

AirGrab Network Packet Analyzer 0.9
A professional network analyzer (also known as protocol analyzer and packet sniffer). more>>
A professional network analyzer (also known as protocol analyzer and packet sniffer), AirGrab Network Packet Analyzer performs real-time packet capturing, network monitoring, advanced protocol analyzing, in-depth packet decoding. It allows you to get a clear view of the complex network, conduct packet level analysis, and troubleshoot network problems. You can Analyze Network events, Network protocols, Packet details (packet decoding), Network conversations. No training needed, no profound background required, data are displayed in intuitive tables and graphs.
RUMpacket 1.3.2
RUMpacket is a simple program for Packet Radio for European TNCs more>>
t works with TNCs with "The Firmware" (TF) installed, using the Host Mode.
An autorouter is integrated, but there is no support for read or write files yet.
Enhancements:
- An other Bug fixed (Program did not response anymore)
- To do: Spy function works not satisfied.
Mac-on-Linux 0.9.72.2
Mac-on-Linux - Run Mac OS in parallel with Linux more>>
Mac-on-Linux is intended to be used by peoplewho run linux/ppc as their main operating system but still want to be able to run that occasional Mac OS application.
Other possible applications include:
development
hardware simulation
server applications
compatibility testing
Technology:
No CPU emulation
very fast!
No ROM image needed
Complete MMU virtualization
Idle sleep (8.6 or later)
Very compatible
Multi-session support
603, 604, G3 and G4 support
Device support:
Full screen video (fbdev, xdga)
MMU accelereaded X11 video
CD burners
Generic SCSI
Generic USB
Audio
Networking
AltiVec support.
Switzerland 0.1
Free and open source tool for testing networks more>> Free and open source tool for testing networks
Switzerland is a tool for testing networks, ISPs and firewalls developed by the Electronic Frontier Foundation (www.eff.org).
Switzerland will spot IP packets which are forged or modified between clients, inform you, and give you copies of the modified packets.
Enhancements
Lots of bugfixes and some new features:
- Make the messages that Switzerland gives users less cryptic and more informative! Especially
- Improve on the notification of modified/forged packets in versions 0.0.x. In the case of modifications, provide specific reports of which packet fields have been modified, from what and to what. In the case of injections/forgeries, provide tcpdump-style representations of the packets.
- Include a new command line tool, study-switzerland-pcaps, to perform the above analysis based on the -in and -out pcap modification/forgery logs produced by Switzerland. This will be useful both for old logfiles from 0.0.7 and for newly created logs.
- Reduce the incidence and duration of the "you cant connect, because we already have a connection from your IP" problem.
- Fix several internal bugs in the server, which 0.0.7 "handled" by catching exceptions and trying to ignore them.
- When modified/forged packets are observed, dont tell other parties what your NIC and routers MAC addresses are
Internal improvements and adjustments:
Refactor things out of Switzerland.py:
- Matchmaking is now separated and easier to understand
- Forgery context operations are now part of SwitzerlandLink.py
- There are some minor but incompatible changes to the wire protocol, in which reports on forgeries are passed around with the fo-context and forged-details messages.
- We have some traceroute collection infrastructure now, although were not using it yet

TV-Snooper 2.4.1
TV-Snooper 2.4.1 is a convenient,accessible,friendly dashboard widget that is a shameless makeover of TV-Sniffer by Stefan Joos (itself inspired by Annuaire) adapted to the french TV programmes. It is based on TV listings more>> TV-Snooper 2.4.1 is a convenient, accessible, friendly dashboard widget that is a shameless makeover of TV-Sniffer by Stefan Joos (itself inspired by Annuaire) adapted to the french TV programmes. It is based on TV listings
Enhancements:
- Progress redraw after visiting preferences since bug since not fixed in 10.4.2
- "Maintenant" correctly works after midnight
- TV5 now displays whenever selected in the preference pane
Requirements:
- Mac OS X 10.4 or later.
AccTail 2.0
AccTail shows all processes that have exited together with all its resource usages more>>
Note: When using this program with Linux, you must have BSD-accounting enabled in the kernel!
Cocoa Iax Ping 1.0
This is actually the cocoa port of the lax ping file. more>>
Cocoa Iax Ping 1.0 is specially designed for Mac users. It improves your Internet experience because it is actually a cocoa port of the lax ping file. It basically sends a IAX ping message (a POKE packet) to the Asterisk server. If you get a reply, your firewall is correctly configured.
<<lessEthernal 1.2
Ethernal - visualize all incoming & outgoing Ethernet packets more>>
I wanted to learn how to read raw Ethernet packets on MacOS X. After going through several examples, I ended up writing this little piece of software. It uses the Berkeley Packet Filter device to read all incoming and outgoing Ethernet packets. I have wrapped the whole thing in a Cocoa GUI using the new bindings features of Mac OS 10.3.
Main features:
- Reads all incoming/outgoing Ethernet packets
- Displays the packet content in hexadecimal/ascii
- Finds any string in packet
- Filters packets
- Dynamic display width
- Save/load packets to disk.
OpenH323 Gatekeeper 2.3.0.1
Full featured H.323 gatekeeper under GPL license OpenH323 Gatekeeper includes Radius and database support and many VOIP routing functions more>> Full featured H.323 gatekeeper under GPL license
OpenH323 Gatekeeper includes Radius and database support and many VOIP routing functions.
OpenH323 Gatekeeper forms the basis for a free IP telephony system (VOIP).The GNU Gatekeeper is very stable and it is being used commercially by many organizations to provide VOIP services.
Main features:
- executables for Mac OS X, Linux, Windows, FreeBSD and Solaris
- can be run as a Windows service
- accounting and call authorization via SQL database, Radius, file or external application
- flexible call routing
- number rewriting (calling and called)
- support for NAT traversal
- full H.323 proxy
- TCP interface to applications
- CTI functions (eg. VOIP call-center, call transfers)
- gatekeeper clustering support (neighbors, parent/child, alternates)
- H.235 security
- graphical user interface
- its free, including source code
Enhancements
- new RadAcct attribute: RewriteE164
- enable multiple failover routes with sql routing policy
- BUGFIX(RasTbl.*) %{last-cdr} was wrong if last call succeeded
- forward the destCallSignalAddress in ARQs to the parent gatekeeper (set [Endpoint]ForwardDestIp=0 to get the old behavior)
- BUGFIX(RasTbl.cxx) never overwrite dialed_number after is has been set
- BUGFIX(RasSrv.cxx) add check to avoid crash on GRQ
- BUGFIX(ProxyChannel.cxx) fix reading of fragmented TPKT packets
- new switches Called/CallingPlanOfNumber in [RoutedMode] and [EP:...] to set numbering plan
- enable SRV policy for all OpenH323 versions as lonng as DNS services are available
- global switches for TranslateReceivedQ931Cause and TranslateSentQ931Cause in [RoutedMode], similar to those in [EP:...]
- BUGFIX(ProxyChannel.cxx) supress 2nd acct start event for 2nd Setup with same callid
- allow outbound number rewrite through SQL/RADIUS modules
- rewrite also aliases of type partyNumber (public and private), dont change alias type during rewrite
- BUGFIX(MakeCall.cxx) MakeCall didnt work on Windows
- implemented status port gai/gci commands for SQLAcct, SQLAuth, SQLPasswordAuth and SQLAliasAuth modules
- BUGFIX(capctrl.cxx) added a missing lock during config reload for CapacityControl module
- BUGFIX InternalPolicy should set a reject reason to something like gatewayResources/resourcesUnavailable instead of calledPartyNotRegistered when terminating gateways were found, but there was no capacity
- BUGFIX(gksql.cxx) SQL reconnect thread-safety fixes
- new q931cause variable in SQLAuth module
- status port connection can now be closed with Ctrl-D (instead of exit)
- selective reload on the status port: Reload
- BUGFIX(radauth.cxx) fixed crash in processing h323-redirect-ip when no h323-redirect-number is present
- BUGFIX (RasTbl.cxx) read GWPrefixes even if there is an EP: section for this endpoint
- BUGFIX (GkStatus.cxx) make sure status port threads dont share string memory with other threads
- new compile option COMPILE_AS_SERVICE to create a native Windows service
- new config options [Logfile]Filename=, [Gatekeeper:Main]TraceLevel= (same as -o and -t on cmd line)
- BUGFIX (ProxyChannel.cxx) always check m_call in H.450.2 call transfer emulator
- allow mutiple results per query from MySQL (and ignore all after the first) needed for using strored procedures (patch by Matteo Piscitelli)
- Added Bind INI setting to set the default interface for multihomed virtual servers.
- BUGFIX (Toolkit.cxx) on reload, check if new config is not empty (Fortytwo=42)
- BUGFIX (ProxyChannel.cxx) add NULL pointer checks to avoid crashes
- CapacityControl H.323 Id rules work now also for SetupUnreg calls
- BUGFIX (ProxyChannel.cxx) make sure Q.931 cause is included in generated ReleaseComplete
- new ^= and /= RewriteCLI rules for H.323 ID only rewritting
- new getauthinfo/getacctinfo status port commands
- Changed P2Pnat from H.460 OID to the standard allocated H.460.23/24
- BUGFIX(RasTbl.cxx): dynamically registered prefixes are added with the GatewayPriority
- BUGFIX(GkClient.cxx): use [Endpoint] Type= setting for GRQ, not only for RRQ
- merged P2Pnat support
- added first cut of Presence support
- set radius release-source attribute in stop accounting packet, like %r in sqlacct
- ./configure support for Windows
- new database driver SQLite
- new database driver ODBC
- auto-reconnect on database errors (for all database drivers)
- allow setting a reject reason when rejecting using the sql policy
License:GPL
