官术网_书友最值得收藏!

tcpdump

tcpdump is the most widely used packet capture utility. It is available on Linux/Unix-based operating systems, which means it's installed by default in Kali Linux. It has the abilities to save captures to a .pcap file and read .pcap files.

tcpdump has a number of switches that you can use. Some of its common switches are as follows:

  • tcpdump -d: Displays a list of interfaces
  • tcpdump -i [interface]: Specifies an interface to perform the packet capture on
  • tcpdump -c: Specifies the number of packets to capture
  • tcpdump -w /path: Defines a file that tcpdump should write to
  • tcpdump -r /path: Reads a capture file
  • tcpdump -XX: Captures packets in ASCII or HEX

The following is a practical example of using tcpdump to capture FTP traffic. Using tcpdump, you are able to see the username and password in clear text, as shown in Figure 28:

Figure 28: Login details in plain text

You can replicate the preceding test by using a publicly accessible ftp server, which is used for speedtest. The URL is speedtest.tele2.net.

主站蜘蛛池模板: 秦安县| 刚察县| 安化县| 博湖县| 昌平区| 阿克陶县| 离岛区| 武安市| 宁武县| 文水县| 皮山县| 精河县| 泗阳县| 平凉市| 绥宁县| 宜丰县| 昌平区| 霞浦县| 南澳县| 佳木斯市| 溧阳市| 宁陵县| 叶城县| 定兴县| 大洼县| 色达县| 宁晋县| 沛县| 永修县| 越西县| 崇仁县| 大埔县| 六枝特区| 察隅县| 昭觉县| 宽城| 河曲县| 贺兰县| 麟游县| 仁化县| 肃宁县|