官术网_书友最值得收藏!

tcpdump

tcpdump is the most widely used packet capture utility. It is available on Linux/Unix-based operating systems, which means it's installed by default in Kali Linux. It has the abilities to save captures to a .pcap file and read .pcap files.

tcpdump has a number of switches that you can use. Some of its common switches are as follows:

  • tcpdump -d: Displays a list of interfaces
  • tcpdump -i [interface]: Specifies an interface to perform the packet capture on
  • tcpdump -c: Specifies the number of packets to capture
  • tcpdump -w /path: Defines a file that tcpdump should write to
  • tcpdump -r /path: Reads a capture file
  • tcpdump -XX: Captures packets in ASCII or HEX

The following is a practical example of using tcpdump to capture FTP traffic. Using tcpdump, you are able to see the username and password in clear text, as shown in Figure 28:

Figure 28: Login details in plain text

You can replicate the preceding test by using a publicly accessible ftp server, which is used for speedtest. The URL is speedtest.tele2.net.

主站蜘蛛池模板: 星子县| 湖口县| 右玉县| 昔阳县| 北票市| 娄烦县| 宜兰市| 南通市| 彩票| 毕节市| 清苑县| 黔东| 镇坪县| 石楼县| 大埔区| 吉安县| 乐亭县| 即墨市| 扶风县| 且末县| 屏南县| 和田市| 木兰县| 昌吉市| 仁寿县| 灯塔市| 四会市| 福清市| 塘沽区| 成都市| 元阳县| 安吉县| 三台县| 桃园县| 临漳县| 莱阳市| 三门峡市| 汉寿县| 宁晋县| 丽江市| 达孜县|