官术网_书友最值得收藏!

Collecting network traffic using Wireshark

While tcpdump is a cool tool to capture network traffic, Wireshark is widely used when it comes to network forensic investigations. In this section, we will focus on installing and using Wireshark to capture network traffic.

Wireshark is available for most of the OS, including Windows, Mac OS, and most flavors of Linux.

It is available for free download at https://www.wireshark.org/download.html.

Using Wireshark

Install Wireshark using the Ubuntu Software Center, as shown in the following screenshot:

Using Wireshark

Run Wireshark with network privileges either directly or using the terminal to start capturing packets, as shown in the following screenshot:

Using Wireshark

Configure according to network topology and other specific details using the Capture Options, as shown in the following screenshot:

Using Wireshark

To get started, all we need to do is select an interface to start capturing packets from. Let's select eth0, as follows:

Using Wireshark

When we select an interface to start capturing packets (eth0), the output is as shown in the following screenshot:

Using Wireshark

To save the raw data in a file, click on the save to file button and choose the required directory, as shown in the following screenshot:

Using Wireshark

That's it! Nice and easy. In the future chapters, we will analyze the captured data.

主站蜘蛛池模板: 香格里拉县| 宁津县| 进贤县| 洪洞县| 荣成市| 遂川县| 绿春县| 溧阳市| 元氏县| 武乡县| 贵州省| 河曲县| 巴林左旗| 微博| 柞水县| 临邑县| 昌平区| 山阳县| 龙南县| 策勒县| 大竹县| 镇江市| 专栏| 江门市| 突泉县| 嵩明县| 星座| 诏安县| 浠水县| 雷州市| 兰州市| 平凉市| 勃利县| 武陟县| 墨竹工卡县| 成武县| 四会市| 紫金县| 波密县| 瓮安县| 吉木乃县|