Read PPP Record Files Safely with pppdump
You will turn a PPP record file into text you can inspect, then choose between character, hexadecimal and packet-oriented output. The installed command is pppdump from the Ubuntu ppp package, version 2.4.9-1+1.1ubuntu4. Allow about ten minutes if the record file is already available. This guide reads the capture and writes decoded output; it does not start or stop a PPP connection.
The route
Jump straight to the step you need, or tick off Done means at the end.
Prerequisite: a readable file created by pppd with its record option. You also need enough free space for the text output. Reading a file in your home directory is normally unprivileged. Use elevated privileges only if the file permissions require it, and prefer copying the evidence to a controlled working directory first.
1. Check the installed command and source file
Confirm which binary will run and inspect the record without changing it:
$ command -v pppdump
/usr/sbin/pppdump
$ test -r /path/to/ppp-record && echo 'record is readable'
record is readable
$ pppdump -h /path/to/ppp-record
The last command prints hexadecimal bytes and decoded directions to standard output. It does not create a report file unless you redirect it. The command accepts one or more filenames; with no filename it reads standard input.
Checkpoint: if the readability test prints nothing, stop and fix the path or access policy before adding sudo. If a privileged copy is appropriate, preserve the original and limit access to the copy:
$ sudo install -o "$USER" -g "$(id -gn)" -m 0600 /path/to/ppp-record ./ppp-record.copy
$ test -r ./ppp-record.copy && echo 'working copy is readable'
working copy is readable
2. Produce a first report without destroying an old one
Shell redirection with > truncates its destination before pppdump runs. Choose a new name, or write a temporary report and rename it only after the command succeeds:
$ pppdump -h ./ppp-record.copy > ./ppp-record.hex.new
$ test "$?" -eq 0
$ test -s ./ppp-record.hex.new && echo 'hex report is non-empty'
hex report is non-empty
$ mv ./ppp-record.hex.new ./ppp-record.hex
The mv changes the name in the same filesystem and is normally unprivileged. If the decode fails, leave the previous report alone and inspect the error. Remove the incomplete .new file only after checking its path; deletion cannot be undone through pppdump.
For a quick terminal view, omit the redirection:
$ pppdump -h ./ppp-record.copy | less
Do not paste a full capture into a shared terminal or ticket if it may contain credentials, authentication exchanges, addresses or application data.
3. Select the output that answers the question
Without -h or -p, the default output prints bytes as characters where possible and uses escape sequences for non-printing or non-ASCII bytes. Use it when the record contains readable protocol text:
$ pppdump ./ppp-record.copy > ./ppp-record.text
Use -h when byte values matter. This is often the clearest first pass for control characters and binary payloads:
$ pppdump -h ./ppp-record.copy > ./ppp-record.hex
Use -p to collect bytes into PPP packets. It interprets asynchronous HDLC framing and escape characters, checks each packet's FCS, and prints packet bytes both as hexadecimal and as characters, replacing non-printing characters with a dot:
$ pppdump -p ./ppp-record.copy > ./ppp-record.packets
Packet mode is the useful choice when you need packet boundaries or want framing and FCS checks. It is not merely a prettier version of hexadecimal mode, so do not compare its line layout directly with a default character report.
4. Handle compression and direction labels
If packet data was compressed with BSD-Compress or Deflate, add -d to -p. The short form is -pd:
$ pppdump -pd ./ppp-record.copy > ./ppp-record.decompressed
The decompression switch only has meaning with packet collection. If the output is unexpectedly unreadable, first repeat the command without -d and compare the packet report. Do not assume every opaque payload is compressed PPP data.
Use -r when the direction indicators in the record need reversing. This changes labels only: bytes or packets marked received are printed as sent, and those marked sent are printed as received.
$ pppdump -pr ./ppp-record.copy > ./ppp-record.reversed
Use this only when you have established that the recording endpoint's perspective is opposite to the labels you need. Reversing labels does not reverse packet bytes or repair a malformed capture.
5. Make timestamps and MRU checks explicit
The -a option prints absolute times instead of the ordinary time presentation. Add it when you are comparing the report with logs from another machine:
$ pppdump -pa ./ppp-record.copy > ./ppp-record.absolute
With packet mode, -m sets the maximum receive unit used for over-length checks in both directions. Supply a numeric value appropriate to the link:
$ pppdump -p -m 1500 ./ppp-record.copy > ./ppp-record.mru1500
Do not treat 1500 as a universal default. It is an example value, not a measurement of your connection. Check the negotiated or configured link settings before using an MRU-specific report in an incident record.
6. Read from standard input and verify a batch
When another tool has already selected the record, pipe it to pppdump without a filename:
$ find ./captures -maxdepth 1 -type f -name '*.ppp' -print0 \
| xargs -0 pppdump -p
That example sends multiple filenames to one invocation. For a single stream, the simpler form is:
$ cat ./ppp-record.copy | pppdump -p > ./ppp-record.stdin
For a script, check the exit status immediately and keep the source file:
if pppdump -p ./ppp-record.copy > ./ppp-record.packets.new; then
mv ./ppp-record.packets.new ./ppp-record.packets
else
status=$?
printf 'pppdump failed with status %s\n' "$status" >&2
exit "$status"
fi
If the command reports an input error, check that the file is readable and that it is actually a PPP record produced by the matching capture workflow. An arbitrary pcap, text log or modem trace is not interchangeable with a pppd record file. Keep the raw record until the report has been checked, because the report is a derived view rather than a replacement for the evidence.
Done means
- The installed
pppdumpversion and input path were checked. - A report was written to a new path, so an existing report was not truncated.
-h,-p,-pd,-r,-aand-mwere used only for the interpretation each option provides.- Any direction or MRU assumption is recorded alongside the derived report.
- The original PPP record remains available, with sensitive output access controlled.