官术网_书友最值得收藏!

Collecting network traffic using Wireshark

While tcpdump is a cool tool to capture network traffic, Wireshark is widely used when it comes to network forensic investigations. In this section, we will focus on installing and using Wireshark to capture network traffic.

Wireshark is available for most of the OS, including Windows, Mac OS, and most flavors of Linux.

It is available for free download at https://www.wireshark.org/download.html.

Using Wireshark

Install Wireshark using the Ubuntu Software Center, as shown in the following screenshot:

Using Wireshark

Run Wireshark with network privileges either directly or using the terminal to start capturing packets, as shown in the following screenshot:

Using Wireshark

Configure according to network topology and other specific details using the Capture Options, as shown in the following screenshot:

Using Wireshark

To get started, all we need to do is select an interface to start capturing packets from. Let's select eth0, as follows:

Using Wireshark

When we select an interface to start capturing packets (eth0), the output is as shown in the following screenshot:

Using Wireshark

To save the raw data in a file, click on the save to file button and choose the required directory, as shown in the following screenshot:

Using Wireshark

That's it! Nice and easy. In the future chapters, we will analyze the captured data.

主站蜘蛛池模板: 竹溪县| 卓资县| 千阳县| 金沙县| 赤水市| 北海市| 鲁山县| 榆社县| 琼海市| 沭阳县| 和田市| 扬中市| 定日县| 平果县| 东乡族自治县| 托克逊县| 梨树县| 平远县| 迁安市| 安义县| 台江县| 桂平市| 遂溪县| 汽车| 谢通门县| 上杭县| 龙海市| 吉安市| 三明市| 黑河市| 禹州市| 信丰县| 苏州市| 辽宁省| 芦溪县| 门头沟区| 沿河| 左权县| 托里县| 防城港市| 新乐市|