[dns-operations] Tools to assemble fragments

Francis Dupont Francis.Dupont at fdupont.fr
Wed May 18 15:59:35 UTC 2016


 In your previous mail you wrote:

>  I am doing a data analysis work for the queries and responses captured in my
>  recursive server. I find the DNS data has some fragments due to large DNS
>  package and it is tricky to assemble them. Would anyone tell me any works of
>  assembling IP layer fragments or any tools to parse DNS message from
>  tcpdump/dnscap data?

=> there were some scripts to perform IP reassembly or even TCP stream
recovery on tcpdump output but today the simpler is to use wireshark
which can read pcap capture files too (or tshark if you don't want
a graphical tool).

Regards

Francis.Dupont at fdupont.fr



More information about the dns-operations mailing list