Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,32 @@
The release notes on GitHub are taken from this file: the section whose
heading is the version number.

## 1.5.2

Fixes
- Client and server were swapped for half of many TCP connections: exported
records (NetFlow, IPFIX, local capture, pcap files) carry the flags of all
their packets together, so a client's SYN followed by ACKs looked like a
server's SYN+ACK and its upload was counted the wrong way round. The flags
now decide only for single packets (sFlow samples, lone SYNs); local
capture and pcap files use the first packet of each connection; other
records go by the ports. Data stored before stays as it is; pcap files are
right once imported again.

Offline pcap analysis
- One file at a time, each in a database of its own: **Analyse** on a
file's row shows that file on every page; the bar at the top switches to
another. Deleting a file no longer re-imports the others.

Interfaces
- Interface check explains that local capture has nothing to compare (no
device interfaces or counters), and the interface picker is hidden when
there are no interfaces.

Docs
- README: the Windows commands for local capture (`traffic66.exe interfaces`,
`traffic66.exe -capture Wi-Fi`).

## 1.5.1

- The web UI's scripts and styles are no longer kept by the browser across
Expand Down
20 changes: 15 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -324,8 +324,10 @@ sampling.
**Offline pcap analysis** shows packet captures (pcap, pcapng) with the same
pages, apart from the live data: `traffic66 a.pcap b.pcapng` starts on
127.0.0.1 and opens the browser (up to 3 files, 3 GB; Ctrl+C deletes the
imported data), or upload up to 3 files of 50 MB on that page. It works on
flows, not packet contents.
imported data), or upload up to 3 files of 50 MB on that page. One file is
analysed at a time, each in a database of its own: **Analyse** on a file's
row shows it on every page, and the bar at the top switches to another. It
works on flows, not packet contents.

![Offline analysis: capture files with their packets, flows and time](docs/images/sandbox.png)

Expand All @@ -340,9 +342,17 @@ in a browser, q quit; `-lang` picks the language.

**Local capture** builds flows from a local interface, best a port
connected to a switch's mirror port: `traffic66 interfaces` lists them,
`-capture eth1` (or a Windows name or number) captures. Linux needs root or
`setcap cap_net_raw,cap_net_admin+ep`, macOS root, Windows
[Npcap](https://npcap.com). Captured flows come from the device `127.0.0.1`.
`-capture eth1` captures. On Windows:

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

Linux needs root or `setcap cap_net_raw,cap_net_admin+ep`, macOS root,
Windows [Npcap](https://npcap.com). Captured flows come from the device
`127.0.0.1`. Local capture has no device interfaces or counters, so
**Interface check** has nothing to compare for it.

## 10. Options and data

Expand Down
20 changes: 15 additions & 5 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -343,7 +343,9 @@ NetFlow/IPFIX بقدر تأخر الأجهزة في التصدير (دقيقتا
يعرض **تحليل pcap دون اتصال** ملفات التقاط الحزم (pcap وpcapng) بالصفحات نفسها،
بمعزل عن البيانات الحية: يبدأ `traffic66 a.pcap b.pcapng` على 127.0.0.1 ويفتح
المتصفح (حتى 3 ملفات، 3 GB؛ يحذف Ctrl+C البيانات المستوردة)، أو ارفع حتى 3
ملفات بحجم 50 MB في تلك الصفحة. يعمل على التدفقات، لا على محتوى الحزم.
ملفات بحجم 50 MB في تلك الصفحة. يُحلَّل ملف واحد في كل مرة، ولكل ملف قاعدة
بيانات خاصة به: يعرض **تحليل** في صف الملف بياناته في كل الصفحات، ويبدّل
الشريط في الأعلى إلى ملف آخر. يعمل على التدفقات، لا على محتوى الحزم.

![التحليل دون اتصال: ملفات الالتقاط مع حزمها وتدفقاتها ووقتها](images/sandbox.png)

Expand All @@ -357,10 +359,18 @@ NetFlow/IPFIX بقدر تأخر الأجهزة في التصدير (دقيقتا
![الواجهة الطرفية: محادثات أعلى 66](images/tui-topn.png)

**الالتقاط المحلي** يبني التدفقات من واجهة محلية، ويُفضَّل منفذ موصول بمنفذ
المرآة في مبدّل: يسردها `traffic66 interfaces`، ويلتقط `-capture eth1` (أو اسم
أو رقم في Windows). يحتاج Linux إلى root أو
`setcap cap_net_raw,cap_net_admin+ep`، وmacOS إلى root، وWindows إلى
[Npcap](https://npcap.com). تأتي التدفقات الملتقطة من الجهاز `127.0.0.1`.
المرآة في مبدّل: يسردها `traffic66 interfaces`، ويلتقط `-capture eth1`. على
Windows:

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

يحتاج Linux إلى root أو `setcap cap_net_raw,cap_net_admin+ep`، وmacOS إلى
root، وWindows إلى [Npcap](https://npcap.com). تأتي التدفقات الملتقطة من
الجهاز `127.0.0.1`. لا واجهات ولا عدّادات جهاز للالتقاط المحلي، لذا ليس لدى
**مطابقة الواجهات** ما تقارنه فيه.

<a id="10-options-and-data"></a>

Expand Down
20 changes: 15 additions & 5 deletions docs/README.bn.md
Original file line number Diff line number Diff line change
Expand Up @@ -351,8 +351,10 @@ export করে ততটা (সর্বোচ্চ 2 মিনিট)। 6
**অফলাইন pcap বিশ্লেষণ** প্যাকেট ক্যাপচার (pcap, pcapng) একই পেজে দেখায়, লাইভ
ডেটা থেকে আলাদা রেখে: `traffic66 a.pcap b.pcapng` 127.0.0.1-এ চালু হয় এবং
browser খোলে (সর্বোচ্চ 3টি ফাইল, 3 GB; Ctrl+C ইমপোর্ট করা ডেটা মুছে দেয়),
অথবা ওই পেজে 50 MB পর্যন্ত 3টি ফাইল আপলোড করুন। এটি flow নিয়ে কাজ করে,
প্যাকেটের বিষয়বস্তু নিয়ে নয়।
অথবা ওই পেজে 50 MB পর্যন্ত 3টি ফাইল আপলোড করুন। একবারে একটি ফাইল বিশ্লেষণ
করা হয়, প্রতিটি নিজস্ব আলাদা ডেটাবেসে: কোনো ফাইলের সারিতে **বিশ্লেষণ**
সেটিকে প্রতিটি পেজে দেখায়, আর ওপরের বার অন্য ফাইলে বদলে দেয়। এটি flow নিয়ে
কাজ করে, প্যাকেটের বিষয়বস্তু নিয়ে নয়।

![অফলাইন বিশ্লেষণ: ক্যাপচার ফাইল, তাদের প্যাকেট, ফ্লো ও সময়](images/sandbox.png)

Expand All @@ -367,9 +369,17 @@ browser-এ খুলুন, q বেরিয়ে যান; `-lang` ভা

**Local capture** একটি local interface থেকে flow তৈরি করে, সবচেয়ে ভালো হয়
switch-এর mirror port-এ যুক্ত একটি port: `traffic66 interfaces` সেগুলোর তালিকা
দেয়, `-capture eth1` (অথবা Windows-এর নাম বা নম্বর) capture করে। Linux-এ root
বা `setcap cap_net_raw,cap_net_admin+ep` লাগে, macOS-এ root, Windows-এ
[Npcap](https://npcap.com)। capture করা flow ডিভাইস `127.0.0.1` থেকে আসে।
দেয়, `-capture eth1` capture করে। Windows-এ:

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

Linux-এ root বা `setcap cap_net_raw,cap_net_admin+ep` লাগে, macOS-এ root,
Windows-এ [Npcap](https://npcap.com)। capture করা flow ডিভাইস `127.0.0.1`
থেকে আসে। Local capture-এ ডিভাইসের interface বা counter নেই, তাই
**ইন্টারফেস মিলানো**-তে এর জন্য তুলনা করার কিছু নেই।

<a id="10-options-and-data"></a>

Expand Down
21 changes: 16 additions & 5 deletions docs/README.es.md
Original file line number Diff line number Diff line change
Expand Up @@ -360,7 +360,10 @@ los escaneos muy pequeños pueden ocultarse tras el muestreo.
las mismas páginas, aparte de los datos en vivo: `traffic66 a.pcap b.pcapng`
arranca en 127.0.0.1 y abre el navegador (hasta 3 archivos, 3 GB; Ctrl+C
borra los datos importados), o suba en esa página hasta 3 archivos de 50 MB.
Trabaja con flujos, no con el contenido de los paquetes.
Se analiza un archivo a la vez, cada uno en su propia base de datos:
**Analizar** en la fila de un archivo lo muestra en todas las páginas, y la
barra superior cambia a otro. Trabaja con flujos, no con el contenido de los
paquetes.

![Análisis offline: archivos de captura con sus paquetes, flujos y tiempo](images/sandbox.png)

Expand All @@ -375,10 +378,18 @@ tiempo, w abrir en un navegador, q salir; `-lang` elige el idioma.

**Captura local** construye flujos desde una interfaz local, idealmente un
puerto conectado al puerto espejo de un switch: `traffic66 interfaces` las
lista y `-capture eth1` (o un nombre o número de Windows) captura. Linux
necesita root o `setcap cap_net_raw,cap_net_admin+ep`, macOS root, Windows
[Npcap](https://npcap.com). Los flujos capturados provienen del equipo
`127.0.0.1`.
lista y `-capture eth1` captura. En Windows:

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

Linux necesita root o `setcap cap_net_raw,cap_net_admin+ep`, macOS root,
Windows [Npcap](https://npcap.com). Los flujos capturados provienen del
equipo `127.0.0.1`. La captura local no tiene interfaces ni contadores del
equipo, así que **Verificación de interfaces** no tiene nada que comparar
para ella.

<a id="10-options-and-data"></a>

Expand Down
23 changes: 17 additions & 6 deletions docs/README.fr.md
Original file line number Diff line number Diff line change
Expand Up @@ -369,8 +369,11 @@ l'échantillonnage.
pcapng) avec les mêmes pages, à part des données en direct :
`traffic66 a.pcap b.pcapng` démarre sur 127.0.0.1 et ouvre le navigateur
(jusqu'à 3 fichiers, 3 Go ; Ctrl+C supprime les données importées), ou
importez sur cette page jusqu'à 3 fichiers de 50 Mo. L'analyse porte sur
les flux, pas sur le contenu des paquets.
importez sur cette page jusqu'à 3 fichiers de 50 Mo. Un seul fichier est
analysé à la fois, chacun dans sa propre base de données : **Analyser** sur
la ligne d'un fichier l'affiche sur toutes les pages, et la barre du haut
passe à un autre. L'analyse porte sur les flux, pas sur le contenu des
paquets.

![Analyse hors ligne : fichiers de capture avec leurs paquets, flux et période](images/sandbox.png)

Expand All @@ -386,10 +389,18 @@ la langue.

**Capture locale** construit des flux à partir d'une interface locale,
idéalement un port relié au port miroir d'un switch : `traffic66 interfaces`
les liste, `-capture eth1` (ou un nom ou numéro Windows) capture. Linux
demande root ou `setcap cap_net_raw,cap_net_admin+ep`, macOS root, Windows
[Npcap](https://npcap.com). Les flux capturés proviennent de l'équipement
`127.0.0.1`.
les liste, `-capture eth1` capture. Sous Windows :

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

Linux demande root ou `setcap cap_net_raw,cap_net_admin+ep`, macOS root,
Windows [Npcap](https://npcap.com). Les flux capturés proviennent de
l'équipement `127.0.0.1`. La capture locale n'a ni interfaces ni compteurs
d'équipement, le **Contrôle des interfaces** n'a donc rien à comparer pour
elle.

<a id="10-options-and-data"></a>

Expand Down
20 changes: 15 additions & 5 deletions docs/README.hi.md
Original file line number Diff line number Diff line change
Expand Up @@ -352,8 +352,10 @@ NetFlow/IPFIX के साथ उतनी देर तक जितनी द
**ऑफ़लाइन pcap विश्लेषण** पैकेट कैप्चर (pcap, pcapng) को उन्हीं पेजों पर
दिखाता है, लाइव डेटा से अलग: `traffic66 a.pcap b.pcapng` 127.0.0.1 पर शुरू
होकर browser खोलता है (अधिकतम 3 फ़ाइलें, 3 GB; Ctrl+C आयात किया डेटा मिटा देता
है), या उस पेज पर 50 MB तक की अधिकतम 3 फ़ाइलें अपलोड करें। यह flows पर काम
करता है, पैकेट की सामग्री पर नहीं।
है), या उस पेज पर 50 MB तक की अधिकतम 3 फ़ाइलें अपलोड करें। एक समय में एक
फ़ाइल का विश्लेषण होता है, हर फ़ाइल अपने अलग database में: किसी फ़ाइल की
पंक्ति पर **विश्लेषण करें** उसे हर पेज पर दिखाता है, और ऊपर की पट्टी दूसरी
फ़ाइल पर बदल देती है। यह flows पर काम करता है, पैकेट की सामग्री पर नहीं।

![ऑफ़लाइन विश्लेषण: कैप्चर फ़ाइलें, उनके पैकेट, फ़्लो और समय](images/sandbox.png)

Expand All @@ -368,9 +370,17 @@ browser में खोलें, q बाहर निकलें; `-lang`

**Local capture** किसी local interface से flows बनाता है, सबसे अच्छा किसी
switch के mirror port से जुड़ा port: `traffic66 interfaces` उनकी सूची देता है,
`-capture eth1` (या Windows का नाम या नंबर) capture करता है। Linux को root या
`setcap cap_net_raw,cap_net_admin+ep` चाहिए, macOS को root, Windows को
[Npcap](https://npcap.com)। Capture किए गए flows डिवाइस `127.0.0.1` से आते हैं।
`-capture eth1` capture करता है। Windows पर:

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

Linux को root या `setcap cap_net_raw,cap_net_admin+ep` चाहिए, macOS को root,
Windows को [Npcap](https://npcap.com)। Capture किए गए flows डिवाइस `127.0.0.1`
से आते हैं। Local capture में डिवाइस के interfaces या counters नहीं होते,
इसलिए **इंटरफ़ेस मिलान** के पास इसके लिए तुलना करने को कुछ नहीं है।

<a id="10-options-and-data"></a>

Expand Down
21 changes: 16 additions & 5 deletions docs/README.id.md
Original file line number Diff line number Diff line change
Expand Up @@ -357,7 +357,10 @@ kecil bisa tersembunyi di balik sampling.
halaman yang sama, terpisah dari data langsung: `traffic66 a.pcap b.pcapng`
berjalan di 127.0.0.1 dan membuka browser (maksimal 3 file, 3 GB; Ctrl+C
menghapus data yang diimpor), atau unggah maksimal 3 file berukuran 50 MB di
halaman itu. Analisis bekerja pada flow, bukan isi paket.
halaman itu. Satu file dianalisis pada satu waktu, masing-masing dalam
database tersendiri: **Analisis** pada baris sebuah file menampilkannya di
semua halaman, dan bilah di bagian atas beralih ke file lain. Analisis
bekerja pada flow, bukan isi paket.

![Analisis offline: file tangkapan beserta paket, flow, dan waktunya](images/sandbox.png)

Expand All @@ -372,10 +375,18 @@ rentang waktu, w buka di browser, q keluar; `-lang` memilih bahasa.

**Capture lokal** membuat flow dari interface lokal, paling baik port yang
terhubung ke port mirror sebuah switch: `traffic66 interfaces` menampilkan
daftarnya, `-capture eth1` (atau nama atau nomor di Windows) melakukan
capture. Linux butuh root atau `setcap cap_net_raw,cap_net_admin+ep`, macOS
butuh root, Windows butuh [Npcap](https://npcap.com). Flow hasil capture
berasal dari perangkat `127.0.0.1`.
daftarnya, `-capture eth1` melakukan capture. Di Windows:

```
traffic66.exe interfaces # list the network cards: name, number, address
traffic66.exe -capture Wi-Fi # capture on the wireless card (or by number: -capture 2)
```

Linux butuh root atau `setcap cap_net_raw,cap_net_admin+ep`, macOS butuh
root, Windows butuh [Npcap](https://npcap.com). Flow hasil capture berasal
dari perangkat `127.0.0.1`. Capture lokal tidak punya interface atau counter
perangkat, jadi **Pencocokan antarmuka** tidak punya apa pun untuk
dibandingkan.

<a id="10-options-and-data"></a>

Expand Down
Loading
Loading