官术网_书友最值得收藏!

Capturing traffic

Learning how to use packet-capturing tools is vital for any security professional. We will cover two packet capturing tools in this section: Wireshark (GUI-based) and tcpdump (CLI-based).

Before we begin using these tools, let's take a step back to understand why there will be a need to capture traffic when performing a penetration test. Network traffic travels in packets, and each packet holds a number of fields that contain the information it needs to travel across the network and perform a certain function. Performing a packet capture (or packet sniffing) will allow you to view the structure of the packets, plus any data that is available. Some protocol traffic is unencrypted, such as FTP. This will allow you to see the username and password in clear text.

Packet sniffing is a type of wire tap that is applied to computer networks. You can liken this to phone tapping, where a conversation is spied on.
主站蜘蛛池模板: 东兰县| 湄潭县| 区。| 碌曲县| 松潘县| 响水县| 普定县| 绥江县| 通州区| 濮阳市| 定陶县| 江安县| 玛纳斯县| 凤阳县| 凤山县| 景泰县| 宁夏| 澄迈县| 阳城县| 阿城市| 安化县| 自贡市| 鸡东县| 临城县| 房山区| 尖扎县| 宜君县| 个旧市| 喀什市| 鹤庆县| 越西县| 彭州市| 临安市| 河曲县| 卫辉市| 巴彦淖尔市| 财经| 喀喇沁旗| 合江县| 深水埗区| 甘孜县|