LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
查看: 958|回复: 7

linux下有没有类似sniffer的工具?

[复制链接]
发表于 2004-8-31 00:12:46 | 显示全部楼层 |阅读模式
linux下有没有类似sniffer的工具?
最好是图形界面的,不然我怕自己不会用
发表于 2004-8-31 00:44:53 | 显示全部楼层

记得好象不是图形的

This is version 0.0.1 of Smbsniff, a LanManager file sniffer for unix.
Smbsniff is maintained by Frederic Lavecot : Frederic.Lavecot@hsc.fr

**** Please read this file to the end as it gives important information
**** and it's not very long
**** or a leat read section "WHAT YOU NEED TO KNOW BEFORE USING SMBSNIF"


WHAT IS SMBSNIF ?
-----------------

Smbsniff is a LanManager packet sniffer that will write to your disk all the
files shared and the documents printed in a LanManager environnement (all
the Microsoft and Samba machines using LanManager protocol to share data).


WHY WOULD YOU WANT TO USE SMBSNIF ?
-----------------------------------

To show people (your boss ?) how insecure this protocol is, for debugging
purposes, for fun, ...


WHAT YOU NEED TO KNOW BEFORE USING SMBSNIF
------------------------------------------

Smbsnif should work on *BSD and Linux and might even work on Solaris.

You will need the libpcap in all cases :
ftp://ftp.ee.lbl.gov/libpcap.tar.Z
or
http://www.tcpdump.org

Smbsniff can work directly on the network but the sniffing part is still wobbly
and you might (most probably will) loose data.

If you want to get the best out of smbsniff use a real sniffer like :
- the stable tcpdump : ftp://ftp.ee.lbl.gov/tcpdump.tar.Z
- the new tcpdump : http://www.tcpdump.org/
- ethereal : http://www.ethereal.com/

Use  :
# tcpdump -s 1514 -w <file> port 139
$ smbsniff -f <file>


NOTE : Smbsniff is still under developement
       and it is FAR from working perfectly.

KNOWN BUGS
----------

Files are not the right size / structure of the file is not correct.
(This is still an alpha version)

File size is bigger/smaller than the original file size.
(Same as above : still an early version and I don't have much time to spend
on it)

If you get a message like :
Read X : offset corrected file <file> will be wrong
Write X : offset corrected file <file> will be wrong
then this means the program is dropping packets or the sniffer you used to
capture the packets has dropped some packets. (It can also mean and this
is often the case that the program is not working correctly)

Note : under linux (when using tcpdump or other sniffers), their is no way
to know packets have been dropped.

Note 2 : If your sniffer IS dropping packets you can easily patch le libpcap
to adjust the size of the capture buffer. To do that :
In file pcap-bpf.c change the line
v = 32768;
to something like
v = 524288;
And don't forget to rebuild your pcap library.
That forked great for me.

CONTRIBUTIONS
-------------

If you want to contribute, send bug alerts or give feedback please mail me :
Frederic.Lavecot@hsc.fr.


WEB SITE
--------

Smbsniff's primary download site is :

              http://www.hsc.fr/ressources/outils/index.html.en


Thanks to the following peoples for their suggestions and help

Stephane Aubert <Stephane.Aubert@hsc.fr>
Denis Ducamp    <Denis.Ducamp@hsc.fr>
Jerome Bouigas
Sebastien Michaud

Also Herv&#65533;Schauer (for letting me work on this),
     ee.lbl.gov (for libpcap and tcpdump),
     and the free software community in general.
 楼主| 发表于 2004-8-31 01:16:00 | 显示全部楼层
没有图形的吗?
文本的好难用啊!
刚才找了一个aps,用起来很不爽
发表于 2004-8-31 09:41:04 | 显示全部楼层
LINUX下的SNIFFER工具还是ethereal最好用,有图形界面,分析包的功能是最强的,几乎支持所有的协议
发表于 2004-12-9 10:26:48 | 显示全部楼层
能给些Ethereal 网络分析, 定义协议过滤的实例么?

具体的说明书也可以,希望有中文的。
发表于 2004-12-10 05:32:20 | 显示全部楼层
tcpdump
发表于 2004-12-10 14:40:41 | 显示全部楼层
呵呵,tcpdump的功能很强大啊,俺一直用她
发表于 2004-12-25 22:16:22 | 显示全部楼层
试试NTOP吧,不错的。
您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表