21.设备端使用tcpdump 抓包工具抓包

一:
下载 libpcap-1.8.1.tar.gz 和 tcpdump-4.9.0.tar.gz工具:

二:编译libpcap:
1.解压并修改:
root# tar -zxvf libpcap-1.8.1.tar.gz
root# cd libpcap-1.8.1/
root# vi configure +5435

#注释8行代码:
5435 #add by lt 20170319
5436 #if test -z "$with_pcap" && test "$cross_compiling" = yes; then
5437 #       as_fn_error $? "pcap type not determined when cross-compiling; use --with-pcap=..." "$LINENO" 5
5438 #fi
5439 
5440 # Check whether --with-pcap was given.
5441 #if test "${with_pcap+set}" = set; then :
5442 # withval=$with_pcap;
5443 #fi

2.配置并编译:

root@user126:/opt/libpcap-1.8.1/# ./configure --prefix=/opt/libpcap/pub --host=arm-himix400-linux --target=arm-himix400-linux CC=arm-himix400-linux-gcc 
make
make install 

三:编译tcpdump:

root# tar -zxvf tcpdump-4.9.0.tar.gz 

root@user126:/opt/tcpdump-4.9.0# ./configure --prefix=/opt/tcpdump/dump --host=arm-himix400-linux CC=arm-himix400-linux-gcc
make
make install 

四:使用参考:
注意需要等网口配置好之后再去抓数据,尤其是4G网口,因为当网口重启后,抓包会终止。

1.抓eth0网口的数据:

./tcpdump  -i eth0 -s 0 -w /var/aaa.pcap

2.抓eth0网口的23端口数据:

./tcpdump tcp port 23 -i eth0 -s 0 -w /var/bbb.pcap

3.抓4G网口的数据:

./tcpdump  -i usb0 -s 0 -w /var/ccc.pcap

猜你喜欢

转载自blog.csdn.net/yanghangwww/article/details/111772434