Linux Sniffer进行网络审计的步骤如下:
tcpdump
、ngrep
)和图形化工具(如Wireshark、EtherApe)。tcpdump
:Debian/Ubuntu用sudo apt-get install tcpdump
,CentOS/RHEL用sudo yum install tcpdump
。tcpdump
。sudo tcpdump -i eth0
。sudo tcpdump -i eth0 -w capture.pcap
(保存为文件以便分析)。sudo tcpdump -i eth0 port 80
(仅捕获HTTP流量)。tcpdump
过滤特定流量(如tcpdump -r capture.pcap 'icmp'
)。.pcap
文件,查看协议、源/目的IP、端口等细节。参考来源: