Capture HTTP traffic with TCPDump

Capture HTTP traffic on port 80 that is designated for a specific hostname.
created by on 2014-04-10
tcpdump -A -s 0 'src example.com and tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)'

Links

Tags:
Fork allmark on GitHub