官术网_书友最值得收藏!

Collecting network traffic using Wireshark

While tcpdump is a cool tool to capture network traffic, Wireshark is widely used when it comes to network forensic investigations. In this section, we will focus on installing and using Wireshark to capture network traffic.

Wireshark is available for most of the OS, including Windows, Mac OS, and most flavors of Linux.

It is available for free download at https://www.wireshark.org/download.html.

Using Wireshark

Install Wireshark using the Ubuntu Software Center, as shown in the following screenshot:

Using Wireshark

Run Wireshark with network privileges either directly or using the terminal to start capturing packets, as shown in the following screenshot:

Using Wireshark

Configure according to network topology and other specific details using the Capture Options, as shown in the following screenshot:

Using Wireshark

To get started, all we need to do is select an interface to start capturing packets from. Let's select eth0, as follows:

Using Wireshark

When we select an interface to start capturing packets (eth0), the output is as shown in the following screenshot:

Using Wireshark

To save the raw data in a file, click on the save to file button and choose the required directory, as shown in the following screenshot:

Using Wireshark

That's it! Nice and easy. In the future chapters, we will analyze the captured data.

主站蜘蛛池模板: 安顺市| 城步| 朝阳区| 平山县| 长兴县| 汉中市| 五峰| 丹巴县| 桂平市| 阳高县| 盖州市| 那曲县| 石林| 手机| 嘉义县| 嘉鱼县| 广元市| 星子县| 龙南县| 綦江县| 易门县| 苗栗市| 福泉市| 五莲县| 阜平县| 吴堡县| 光山县| 肃北| 来凤县| 曲松县| 五台县| 增城市| 鄂尔多斯市| 栾城县| 彰化市| 七台河市| 黑水县| 长寿区| 中西区| 汽车| 双柏县|