官术网_书友最值得收藏!

tcpdump

tcpdump is the most widely used packet capture utility. It is available on Linux/Unix-based operating systems, which means it's installed by default in Kali Linux. It has the abilities to save captures to a .pcap file and read .pcap files.

tcpdump has a number of switches that you can use. Some of its common switches are as follows:

  • tcpdump -d: Displays a list of interfaces
  • tcpdump -i [interface]: Specifies an interface to perform the packet capture on
  • tcpdump -c: Specifies the number of packets to capture
  • tcpdump -w /path: Defines a file that tcpdump should write to
  • tcpdump -r /path: Reads a capture file
  • tcpdump -XX: Captures packets in ASCII or HEX

The following is a practical example of using tcpdump to capture FTP traffic. Using tcpdump, you are able to see the username and password in clear text, as shown in Figure 28:

Figure 28: Login details in plain text

You can replicate the preceding test by using a publicly accessible ftp server, which is used for speedtest. The URL is speedtest.tele2.net.

主站蜘蛛池模板: 苍溪县| 潼南县| 盈江县| 礼泉县| 凤山市| 普陀区| 江安县| 二连浩特市| 周至县| 徐水县| 临泉县| 华安县| 太仓市| 房产| 保定市| 大邑县| 汶川县| 页游| 吉林省| 门头沟区| 右玉县| 达尔| 那坡县| 建平县| 临夏市| 东莞市| 承德县| 淮北市| 米泉市| 葫芦岛市| 凤凰县| 阳城县| 贵南县| 武宁县| 奇台县| 社会| 襄樊市| 牟定县| 积石山| 铅山县| 衡阳县|