1.先Ctrl+Alt+T打开命令窗口
输入命令ifconfig查看网络端口
(1)tcpdump -i <interface>
例子:tcpdump -i eth0
(2)tcpdump -i <interface> -w <path>
例子:tcpdump -i eth0 -w /tmp/test.pcap
(3)tcpdump -i <interface> -w <path> host <IP>
例子:tcpdump -i eth0 -w /tmp/test.pcap host 192.168.0.1
(4)tcpdump -i <interface> -w <path> port <port number>
例子:tcpdump -i eth0 -w /tmp/test.pcap port 80
(5)tcpdump -i <interface> -w <path> net <subnet>
例子:tcpdump -i eth0 -w /tmp/test.pcap net 192.168.0.1/24
(6)tcpdump -i <interface> -s 0 -w <path> host <IP>
例子:tcpdump -i eth0 -s 0 -w /tmp/test.pcap host 192.168.1.1
(7)tcpdump -i <interface> -w <path> "host<IP>&&port<port number>"
例子:tcpdump -i eth0 -w /tmp/test.pcap "host 192.168.0.1 && port 80"
(8)tcpdump -i <interface> -w <path> "host <IP> || host <IP>"
tcpdump -i eth0 -w /tmp/test.pcap "host 192.168.0.1||host 192.168.0.2"
(9)将保存的抓包文件test.pcap传输到window系统下的Wireshark网络抓包和分析软件打开,就能看到抓取的数据包了