How To Install pcapdiff on Fedora 34

pcapdiff is Compares packet captures, detects forged, dropped or mangled packets

Introduction

In this tutorial we learn how to install pcapdiff on Fedora 34.

What is pcapdiff

Pcapdiff is a tool developed by the EFF to compare two packet captures and identify potentially forged, dropped, or mangled packets. Two technically- inclined friends can set up packet captures (e.g. tcpdump or Wireshark) on their own computers and produce network traffic between their two computers over the Internet. Later, they can run pcapdiff on the two packet capture files to identify suspicious packets for further investigation. See Detecting packet injection and EFF’s Test Your ISP Project for more background.

We can use yum or dnf to install pcapdiff on Fedora 34. In this tutorial we discuss both methods but you only need to choose one of method to install pcapdiff.

Install pcapdiff on Fedora 34 Using dnf

Update yum database with dnf using the following command.

sudo dnf makecache --refresh

The output should look something like this:

Fedora 34 - x86_64                               20 kB/s | 6.6 kB     00:00
Fedora 34 openh264 (From Cisco) - x86_64        1.4 kB/s | 989  B     00:00
Fedora Modular 34 - x86_64                       68 kB/s | 6.5 kB     00:00
Fedora 34 - x86_64 - Updates                    3.5 kB/s | 6.2 kB     00:01
Fedora Modular 34 - x86_64 - Updates             17 kB/s | 5.9 kB     00:00
Metadata cache created.

After updating yum database, We can install pcapdiff using dnf by running the following command:

sudo dnf -y install pcapdiff

Install pcapdiff on Fedora 34 Using yum

Update yum database with yum using the following command.

sudo yum makecache --refresh

The output should look something like this:

Fedora 34 - x86_64                               20 kB/s | 6.6 kB     00:00
Fedora 34 openh264 (From Cisco) - x86_64        1.4 kB/s | 989  B     00:00
Fedora Modular 34 - x86_64                       68 kB/s | 6.5 kB     00:00
Fedora 34 - x86_64 - Updates                    3.5 kB/s | 6.2 kB     00:01
Fedora Modular 34 - x86_64 - Updates             17 kB/s | 5.9 kB     00:00
Metadata cache created.

After updating yum database, We can install pcapdiff using yum by running the following command:

sudo yum -y install pcapdiff

How To Uninstall pcapdiff on Fedora 34

To uninstall only the pcapdiff package we can use the following command:

sudo dnf remove pcapdiff

pcapdiff Package Contents on Fedora 34

/usr/bin/pcapdiff
/usr/bin/printpackets
/usr/share/doc/pcapdiff
/usr/share/doc/pcapdiff/COPYING.2
/usr/share/doc/pcapdiff/COPYING.3
/usr/share/doc/pcapdiff/README
/usr/share/pcapdiff
/usr/share/pcapdiff/pcapdiff.py
/usr/share/pcapdiff/pcapdiff_helper.py
/usr/share/pcapdiff/printpackets.py

References

Summary

In this tutorial we learn how to install pcapdiff on Fedora 34 using yum and dnf.