使用 Wireshark/tcpdump 抓包
学习在命令行中使用 `tcpdump` 捕获和分析网络数据包,并使用 Wireshark 进行图形化分析
使用 Wireshark/tcpdump 抓包 是 CoddyKit 上的免费 Linux Networking & TCP/IP for Developers 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Linux Networking & TCP/IP for Developers 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Linux Networking & TCP/IP for Developers 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
What is Packet Capture?
Packet capture is like taking a snapshot of all the network data flowing in and out of your device. It's a powerful technique for understanding network behavior and troubleshooting issues.
You can see the raw "packets" of information, including their source, destination, and the data they carry. This helps diagnose slow connections, find security problems, or debug network applications.
Introducing `tcpdump`
tcpdump is a command-line utility for capturing and analyzing network traffic. It's pre-installed on most Linux systems, making it a go-to tool for quick network inspections.
It works by "sniffing" packets directly from your network interface. You can view them in real-time or save them for later analysis.
Basic Capture with `tcpdump`
Let's start with the most basic usage: capturing all traffic on a specific network interface. You often need sudo privileges to run tcpdump.
The -i flag specifies the interface (e.g., eth0 or wlan0). If you omit -i, tcpdump tries to pick one automatically.
sudo tcpdump -i eth0Filtering by Host
Capturing all traffic can be overwhelming. You'll often want to filter for specific connections. The host keyword lets you capture traffic to or from a particular IP address or hostname.
sudo tcpdump -i eth0 host 192.168.1.1Filtering by Port
Another common filter is by port. This is useful for seeing traffic related to specific services, like web (port 80/443), SSH (port 22), or DNS (port 53).
sudo tcpdump -i eth0 port 80Combining Filters
You can combine filters using logical operators like and, or, and not. This allows for very precise targeting of the traffic you want to see.
For example, to see HTTP traffic to a specific host, you'd combine host and port.
sudo tcpdump -i eth0 host 192.168.1.1 and port 80Saving to a File (`.pcap`)
For deeper analysis, it's best to save the captured packets to a file. The -w flag writes the raw packet data to a file with a .pcap extension. This file can then be opened by other tools.
The -c flag limits the number of packets to capture.
sudo tcpdump -i eth0 -c 100 -w my_capture.pcapWireshark: The GUI Analyzer
While tcpdump is excellent for command-line capture, Wireshark is the industry-standard graphical tool for deep packet inspection. It provides a user-friendly interface to visualize and analyze captured network data.
Wireshark can capture live traffic or open .pcap files created by tcpdump or other tools.
Importing `tcpdump` Files
A common workflow is to capture packets using tcpdump on a remote server (where a GUI might not be available) and then transfer the .pcap file to your local machine for analysis with Wireshark.
In Wireshark, you simply go to File > Open and select your .pcap file. Wireshark will then display all the captured packets in a structured way.
`tcpdump` Filter Challenge
You need to capture traffic on the eth0 interface that is going to or coming from the IP address 10.0.0.5, but ONLY on port 22 (SSH). Which tcpdump command would achieve this?
Lesson Recap
In this lesson, we explored the powerful world of packet capture. We learned how to use tcpdump to capture and filter network traffic directly from the command line.
- Basic capture with
-i - Filtering by
hostandport - Combining filters with
and,or,not - Saving captures to a
.pcapfile with-w
We also introduced Wireshark as a graphical tool for in-depth analysis of these captured files. Mastering these tools is crucial for any network troubleshooter!
用 AI 导师学习 Linux Networking & TCP/IP for Developers — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「使用 Wireshark/tcpdump 抓包」课时是免费的吗?
是的 — 「使用 Wireshark/tcpdump 抓包」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Linux Networking & TCP/IP for Developers 课程的其余内容,请升级到 CoddyKit PRO。 Linux Networking & TCP/IP for Developers 课程共包含 4 节课。
「使用 Wireshark/tcpdump 抓包」这节课中我会学到什么?
学习在命令行中使用 `tcpdump` 捕获和分析网络数据包,并使用 Wireshark 进行图形化分析 你通过在浏览器中直接运行的动手代码来练习 Linux Networking & TCP/IP for Developers,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Linux Networking & TCP/IP for Developers 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Linux Networking & TCP/IP for Developers 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「使用 Wireshark/tcpdump 抓包」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Linux Networking & TCP/IP for Developers 课中编写并运行代码吗?
能。每节 Linux Networking & TCP/IP for Developers 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 使用 Wireshark/tcpdump 抓包
- 网络性能工具
- Linux 防火墙(Netfilter/iptables)
- 使用 dig 和 nslookup 诊断 DNS