#!/opt/local/bin/python import sys # for sys.argv, sys.path.append # dnslib from https://pypi.python.org/pypi/dnslib, install with "pip install dnslib" # When using a local copy of dnslib: # sys.path.append('~sergey/cs60/dns/dnslib-0.9.7') or wherever the downloaded copy lives from scapy.all import * from dnslib import * #l = rdpcap("recursive-dns-lookup-noDNSSEC.pcap") #l = rdpcap("recursive-dns-edns-no.pcap") #l = rdpcap("dns-reverse.pcap") #l = rdpcap("dns-reverse-afresh.pcap") l = rdpcap(sys.argv[1]) for pp in l : print "\n-------------------[ %s -> %s ]-------------------" % (pp[IP].src , pp[IP].dst) d = DNSRecord.parse(str(pp)[0x2a:]) # offset 0x2a is there the DNS payload starts print(d) # thanks to dnslib, prints d in the "dig" format