Socat

From Leo's Notes
Revision as of 02:40, 24 September 2019 by Leo (talk | contribs) (Created page with "socat is a utility to create and interface with unix sockets. == Intercepting Unix Socket Data == If you want to see data sent to and from a Unix socket, one way is to proxy...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
This page was last edited on 24 September 2019, at 02:40.

socat is a utility to create and interface with unix sockets.

Intercepting Unix Socket Data

If you want to see data sent to and from a Unix socket, one way is to proxy the socket on a TCP port, then create a new socket that forwards to this port, and then use tcpdump to capture any traffic.

For example:

## Say we want to see all traffic to /var/socket.sock
## Move the original socket elsewhere
# mv /var/socket.sock /var/socket-org.sock
## Make socat listen on 8888 for the original socket
# socat TCP-LISTEN:8888,reuseaddr,fork UNIX-CONNECT:/var/socket-org.sock &
## Create a new socket with the original name and proxy all traffic to port 8888, which then gets redirected to the original socket with the first socat
# socat UNIX-LISTEN:/var/socket.sock,fork TCP-CONNECT:127.0.0.1:8888 &
## Dump all traffic on port 8888
# tcpdump -i lo -netvvvXSs 1514 port 8888