远程抓包的实现步骤:
1,安装或启动rpcapd服务
Windows上只要安装WinPcap软件就行了,它已经包含了rpcapd服务,只要启动就行了
Linux上需要自己编译
Ubuntu下
apt-get install bison flex
wget http://www.winpcap.org/install/bin/WpcapSrc_4_1_2.zip
unzip WpcapSrc_4_1_2.zip
cd winpcap/wpcap/libpcap
chmod +x configure runlex.sh
CFLAGS=-static ./configure
make
cd rpcapd
make
Fedora下
yum install glibc-static
wget http://www.winpcap.org/install/bin/WpcapSrc_4_1_2.zip
unzip WpcapSrc_4_1_2.zip
cd winpcap/wpcap/libpcap
chmod +x configure runlex.sh
CFLAGS=-static ./configure
make
cd rpcapd
make
然后
./rpcapd -n
就运行rpcap服务了
![](http://dl.iteye.com/upload/attachment/332252/75c55038-00ab-38d9-bb15-5685ca21aaac.png)
./rpcapd -n -d
将以dameon模式在后台运行
问题1:
./configure执行到最后出错
checking for perl... /usr/bin/perl
checking for bison... no
checking for byacc... no
checking for yacc... no
configure: error: I couldn't find yacc (or bison or ...); make sure it's installed and in your path
./configure执行到最后出错
checking for perl... /usr/bin/perl
checking for bison... no
checking for byacc... no
checking for yacc... no
configure: error: I couldn't find yacc (or bison or ...); make sure it's installed and in your path
解决办法:
sudo apt-get install flex bison
sudo apt-get install flex bison
yacc(Yet Another Compiler Compiler),是Unix/Linux上一个用来生成编译器的编译器(编译器代码生成器)。
如想深入了解google下。
问题2:
configure: error: Header file pcap.h not found; if you installed libpcap from source, did you also do "make install-incl", and if you installed a binary package of libpcap, is there also a developer's package of libpcap,
and did you also install that package?
configure: error: Header file pcap.h not found; if you installed libpcap from source, did you also do "make install-incl", and if you installed a binary package of libpcap, is there also a developer's package of libpcap,
and did you also install that package?
问题原因是ubuntu下缺少pcap.h等文件。
解决方法:
编译安装libpcap.
在www.tcpdump.org页面中可下载源码:libpcap-1.0.0.tar.gz
cd到文件目录:
$tar -xvf libpcap-1.0.0.tar.gz
$cd libpcap-1.0.0.tar.gz
$./configure
$make
$sudo make install
在InterFace中选择Remote,在弹出的框中输入IP地址点击确定
![](http://dl.iteye.com/upload/attachment/332244/51d2acca-4cdf-3d00-a72c-c604a2d6e2ae.png)
在右边选择想要监听的网卡
![](http://dl.iteye.com/upload/attachment/332246/d69df53f-bcbc-39af-ade3-a96a29e78629.png)
最后点Start就开始抓包了
![点击查看原始大小图片](http://dl.iteye.com/upload/attachment/332248/80f2dd9d-7651-3fc6-8268-8737858928a9.png)