网络命令之_tshark

tshark常用抓包方式 : 还是不错的, 值得学习, 学会分析 !

tshark

-n : disable all name resolutions, 禁止 name 解析

-r : 输入文件

-D : 查看可用的网络接口

-i : 待抓取的网络接口 和 tcpdump 的 -i 一样

-z : 各类统计显示, 这个功能最强大, 是自动化分析的关键 !

-Y : 和 -R类似

-R :

...

三板斧在 tshark 中的对应

- Summary <--> capinfos

- Service Response Time <--> 视不同的协议而定

- Expert info <--> 用 -z 统计 重传情况, 乱序情况

D:\5CTF\ruan jian\UsbKeyboardDataHacker-main>python UsbKeyboardDataHacker.py --input D:\金砖\网络安全防护治理\样题\流量分析\8c90b141-714a-4a34-8e30-5b1ecbcf328b\foremost_output\zip\key.pcap Traceback (most recent call last): File "D:\5CTF\ruan jian\UsbKeyboardDataHacker-main\UsbKeyboardDataHacker.py", line 121, in <module> main() File "D:\5CTF\ruan jian\UsbKeyboardDataHacker-main\UsbKeyboardDataHacker.py", line 113, in main for timestamp, press in parse_pcap_file(args.input): File "D:\5CTF\ruan jian\UsbKeyboardDataHacker-main\UsbKeyboardDataHacker.py", line 18, in parse_pcap_file for packet in cap: File "C:\Users\朱\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.9_qbz5n2kfra8p0\LocalCache\local-packages\Python39\site-packages\pyshark\capture\capture.py", line 212, in _packets_from_tshark_sync tshark_process = existing_process or self.eventloop.run_until_complete( File "C:\Program Files\WindowsApps\PythonSoftwareFoundation.Python.3.9_3.9.3568.0_x64__qbz5n2kfra8p0\lib\asyncio\base_events.py", line 647, in run_until_complete return future.result() File "C:\Users\朱\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.9_qbz5n2kfra8p0\LocalCache\local-packages\Python39\site-packages\pyshark\capture\capture.py", line 340, in _get_tshark_process parameters = [self._get_tshark_path(), "-l", "-n", "-T", output_type] + \ File "C:\Users\朱\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.9_qbz5n2kfra8p0\LocalCache\local-packages\Python39\site-packages\pyshark\capture\capture.py", line 315, in _get_tshark_path return get_process_path(self.tshark_path) File "C:\Users\朱\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.9_qbz5n2kfra8p0\LocalCache\local-packages\Python39\site-packages\pyshark\tshark\tshark.py", line 70, in get_process_path raise TSharkNotFoundException( pyshark.tshark.tshark.TSharkNotFoundException: TShark not found. Try adding its location to the configuration file. Searched these paths: ['C:\\Program Files\\Wireshark\\tshark.exe', 'C:\\Program Files (x86)\\Wireshark\\tshark.exe', 'C:\\Program Files\\Wireshark\\tshark.exe']
07-07
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值