winpcap的一个小的抓包测试程序

 

#include "pcap.h"
#include <winsock2.h>
#pragma comment(lib,"Ws2_32.lib")
#pragma comment(lib,"wpcap.lib")

void main(){
 pcap_if_t *alldevs;
 pcap_if_t *p;
 pcap_t *devHandle;//适配器句柄
 struct pcap_pkthdr *packetHeader;//与数据包捕获有关的一个Header
 const unsigned char *packetData;//数据包内容的指针
 char errbuf[PCAP_ERRBUF_SIZE];
 if(pcap_findalldevs(&alldevs,errbuf)==-1){//检索所有适配器
  fprintf(stderr,"error:%s\n",errbuf);
  exit(1);
 }
 if(alldevs==NULL){
  printf("no devs\n");
  return;
 }
 int i=0;
 for(p=alldevs;p;p=p->next){
  printf("%d:%s\n",++i,p->name);
  printf("%s\n",p->description);
 }
 int choose;
 printf("Input the index of the chosen adapter:\n");
 scanf("%d",&choose);
 if(choose<1||choose>i){
  pcap_freealldevs(alldevs);//释放适配器列表
  return;
 }
 p=alldevs;
 for(i=0;i<choose;i++)
  p=p->next;
 char err[PCAP_ERRBUF_SIZE];
 devHandle=pcap_open_live(p->name,65535,1,1000,err);//获取捕获网络数据包的数据包捕获描述符  现用pcap_open
 if(devHandle==NULL){
  fprintf(stderr,"\nUnable to open the adapter\n",p->name);
  pcap_freealldevs(alldevs);
  return;
 }
 printf("\nCapture session started on adapter %s\n",p->name);
 pcap_freealldevs(alldevs);
 int ret;
 while((ret=pcap_next_ex(devHandle,&packetHeader,&packetData))>=0){//开始抓包,pcap_dispatch(...)阻塞,pcap_loop(...)非阻塞
  if(ret==0)
   continue;
  printf("length of packet:%d\n",packetHeader->len);
  //printf("addr:%s\n",inet_ntoa(((sockaddr_in *)(p->addresses->addr))->sin_addr));
  //printf("net mask:%s\n",inet_ntoa(((sockaddr_in *)(p->addresses->netmask))->sin_addr));
  //printf("broad addr:%s\n",inet_ntoa(((sockaddr_in *)(p->addresses->broadaddr))->sin_addr));
  //printf("dest addr:%s\n",inet_ntoa(((sockaddr_in *)(p->addresses->dstaddr))->sin_addr));
 }
 if(ret==-1){
  printf("Error reading the packet:%s\n",pcap_geterr(devHandle));
  return;
 }
 return;
}

  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
以下是一个基于WinPcap的网络抓包Python程序的示例代码: ``` import socket import struct import sys import threading from ctypes import * from winpcapy import * # define constants PCAP_ERRBUF_SIZE = 256 # define structure for IP header class IP(Structure): _fields_ = [ ("ihl", c_ubyte, 4), ("version", c_ubyte, 4), ("tos", c_ubyte), ("len", c_ushort), ("id", c_ushort), ("offset", c_ushort), ("ttl", c_ubyte), ("protocol_num", c_ubyte), ("sum", c_ushort), ("src", c_ulong), ("dst", c_ulong) ] def __new__(self, data=None): return self.from_buffer_copy(data) def __init__(self, data=None): # map protocol constants to their names self.protocol_map = {1: "ICMP", 6: "TCP", 17: "UDP"} # human readable IP addresses self.src_address = socket.inet_ntoa(struct.pack("<L", self.src)) self.dst_address = socket.inet_ntoa(struct.pack("<L", self.dst)) # human readable protocol try: self.protocol = self.protocol_map[self.protocol_num] except: self.protocol = str(self.protocol_num) # define callback function for packet capture def packet_handler(header, data): # parse IP header ip_header = IP(data) # print out packet information print("Protocol: %s, Source: %s, Destination: %s" % (ip_header.protocol, ip_header.src_address, ip_header.dst_address)) def main(): # open network adapter for capturing errbuf = create_string_buffer(PCAP_ERRBUF_SIZE) adapter = pcap_open_live("eth0", 65536, 1, 1000, errbuf) if not adapter: print("Unable to open adapter: %s" % errbuf.value.decode("utf-8")) sys.exit(1) # start packet capture loop try: pcap_loop(adapter, -1, packet_handler, None) except KeyboardInterrupt: pass # close the adapter pcap_close(adapter) if __name__ == "__main__": main() ``` 这个程序使用WinPcap库来捕获网络数据,并使用Python中的ctypes库来定义IP头的结构体。程序打开一个名为“eth0”的网络适配器,然后进入无限循环以捕获数据。当用户按下Ctrl + C时,程序将退出循环并关闭适配器。程序还一个处理程序回调函数,它将在每个捕获的数据上运行,并打印有关该的一些信息。

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值