官术网_书友最值得收藏!

tcpdump

tcpdump is the most widely used packet capture utility. It is available on Linux/Unix-based operating systems, which means it's installed by default in Kali Linux. It has the abilities to save captures to a .pcap file and read .pcap files.

tcpdump has a number of switches that you can use. Some of its common switches are as follows:

  • tcpdump -d: Displays a list of interfaces
  • tcpdump -i [interface]: Specifies an interface to perform the packet capture on
  • tcpdump -c: Specifies the number of packets to capture
  • tcpdump -w /path: Defines a file that tcpdump should write to
  • tcpdump -r /path: Reads a capture file
  • tcpdump -XX: Captures packets in ASCII or HEX

The following is a practical example of using tcpdump to capture FTP traffic. Using tcpdump, you are able to see the username and password in clear text, as shown in Figure 28:

Figure 28: Login details in plain text

You can replicate the preceding test by using a publicly accessible ftp server, which is used for speedtest. The URL is speedtest.tele2.net.

主站蜘蛛池模板: 平江县| 湘潭市| 梅州市| 武义县| 丰镇市| 措勤县| 白朗县| 扬中市| 合作市| 宣恩县| 根河市| 长葛市| 台中县| 滕州市| 南木林县| 崇义县| 类乌齐县| 响水县| 衡阳县| 黎平县| 景谷| 昌黎县| 清丰县| 新干县| 靖西县| 安乡县| 临沂市| 育儿| 大石桥市| 汾西县| 扬州市| 轮台县| 邢台市| 伽师县| 皮山县| 松桃| 库车县| 仁化县| 天门市| 安庆市| 苏尼特左旗|