1、修改报文IP到同一指定值
tcpprep -p --pcap=input.pcap --cachefile=output.cache
tcprewrite -i input.pcap -o output.pcap --cachefile=ouput.cache -e 1.1.1.1:2.2.2.2
批量处理shell脚本:
#!/bin/sh
myFile=/root/IP_connect.txt
file_path=/root/pcap_file
cat $myFile | while read line
do
echo $line
m=`echo $line |awk '{print $1}'`
n=`echo $line |awk '{print $2}'`
f=`echo $line |awk '{print $3}'`
cd $file_path
tcpprep -p --pcap=succ_change.pcap --cachefile=test_cache.cache
sleep 1
tcprewrite -i succ_change.pcap -o $f --cachefile=test_cache.cache -e $m:$n
sleep 1
mv $f $file_path/pcap/
sleep 1
cd $file_path
rm -rf test_cache.cache
sleep 3
echo "finished!"
done