官术网_书友最值得收藏!

tcpdump

tcpdump is the most widely used packet capture utility. It is available on Linux/Unix-based operating systems, which means it's installed by default in Kali Linux. It has the abilities to save captures to a .pcap file and read .pcap files.

tcpdump has a number of switches that you can use. Some of its common switches are as follows:

  • tcpdump -d: Displays a list of interfaces
  • tcpdump -i [interface]: Specifies an interface to perform the packet capture on
  • tcpdump -c: Specifies the number of packets to capture
  • tcpdump -w /path: Defines a file that tcpdump should write to
  • tcpdump -r /path: Reads a capture file
  • tcpdump -XX: Captures packets in ASCII or HEX

The following is a practical example of using tcpdump to capture FTP traffic. Using tcpdump, you are able to see the username and password in clear text, as shown in Figure 28:

Figure 28: Login details in plain text

You can replicate the preceding test by using a publicly accessible ftp server, which is used for speedtest. The URL is speedtest.tele2.net.

主站蜘蛛池模板: 新龙县| 黄山市| 凤凰县| 遵义县| 鲁山县| 盘山县| 陈巴尔虎旗| 兴海县| 巫溪县| 镇安县| 五台县| 竹山县| 广宗县| 虎林市| 错那县| 屯昌县| 华坪县| 蒙山县| 虎林市| 宁远县| 文化| 二连浩特市| 阿克陶县| 仙居县| 南昌市| 宁南县| 健康| 河间市| 彭泽县| 阿城市| 南宁市| 文登市| 璧山县| 丽水市| 黄骅市| 左贡县| 苏州市| 且末县| 浦东新区| 高碑店市| 宁化县|