tcpdump port http or port ftp or port smtp or port imap or port pop3 -l -A | egrep -i \ 'pass=|pwd=|log=|login=|user=|username=|pw=|passw=|passwd=|password=|pass:|user:|username: \ |password:|login:|pass |user ' --color=auto --line-buffered -B20 |
1 | ngrep '[&\s?](?:login|user(?:name|)|p(ass(?:word|wd|)|w|wd))[\s:=]\s?([^&\s]*)' -q -i |