Dumpcap在Debian上的应用指南
一 安装与权限配置
sudo apt update && sudo apt install wireshark wireshark-common wireshark-clisudo usermod -aG wireshark $USER,随后需注销并重新登录生效。sudo setcap 'cap_net_raw,cap_net_admin+eip' /usr/bin/dumpcap(路径以实际安装为准,可用 which dumpcap 确认)。ip a 或 ifconfig 确认要监听的网卡名称(如 eth0、wlan0、或 any)。二 常用抓包命令
sudo dumpcap -i eth0 -w capture.pcapsudo dumpcap -i any -w capture.pcapsudo dumpcap -i eth0 -c 100 -w capture.pcapsudo dumpcap -i eth0 -G 60 -W bysec -w capture_%Y-%m-%d_%H-%M-%S.pcapsudo dumpcap -i eth0 -f "tcp port 80" -w http.pcapsudo dumpcap -i eth0 -f "tcp port 80 and host example.com" -w example_http.pcapsudo dumpcap -i eth0 -l。三 文件分析与后续处理
wireshark capture.pcaptshark -r capture.pcap -Y "http" -T fields -e frame.number -e ip.src -e ip.dst -e http.host -e http.request.method -e http.request.uritshark -i eth0 -Y "http" -T fields -e frame.number -e ip.src -e ip.dst -e http.host -e http.request.method -e http.request.uri四 进阶用法与运维实践
dumpcap -i any -w /var/log/dumpcap/capture.pcap,便于长期或守护式抓包(注意日志轮转与磁盘空间)。五 合规与性能提示