finds.dev← search

// the find

brendangregg/Chaosreader

★ 239 · updated Aug 2021

An any-snarf program that processes application protocols (HTTP/FTP/...) from tcpdump or snoop files and stores session and file data

Chaosreader is a Perl script that reads tcpdump or snoop capture files, reassembles TCP sessions and IP fragments, and pulls out what was sent over unencrypted protocols: HTTP files, FTP transfers, telnet, X11, VNC, and SMTP mail. It writes an HTML index linking each session and extracted file, and generates replay scripts for telnet, rlogin, and IRC. It suits security analysts doing forensics and people teaching how plaintext protocols leak, not anyone who needs a maintained library.

It reassembles TCP streams and IP fragments from the raw capture binaries itself, so it does not depend on Wireshark or tshark. The dependency list is short and mostly core Perl modules. The HTML index links every session, extracted file, and image report, which makes a large capture browsable without reading raw output. The replay scripts let you watch a recorded telnet or IRC session at real or altered speed, which demonstrates the exposure far better than a byte dump. Standalone mode can invoke tcpdump or snoop directly, so a live interface works without a separate capture step.

The last push was August 2021, and nothing in the visible tree points to a test suite, so regressions on newer captures would go unnoticed. Anything over TLS comes out as an opaque session with no content, and the README's framing is entirely about plaintext protocols, which covers less traffic than it did when the tool was written. The README says no CPAN modules are needed, then admits later versions added some, so the install story is less clean than advertised. It also has no architecture notes, so adding a protocol means working through the whole script.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →