Listen for Specific Http POST/GET Request on a Linux Box

Be carefull with spaces in the command

POST:
sudo tcpdump -s 0 -A ‘tcp dst port 14001 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x504f5354)’

you can use the following location for tcpdump
sudo /usr/sbin/tcpdump

GET:

sudo tcpdump -s 0 -A ‘tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420’

Leave a comment