tcpdump-3.9.8-1.21.x86_64.rpm
libpcap0-0.9.8-50.10.1.x86_64.rpm
tcpdump -i any -s 0 -w /home/xyz.cap
wireshark解包;
------------------------------------------------------------------------
安装:
https://blog.csdn.net/ai2000ai/article/details/54378787
使用:
tcpdump -i eth0 host 1.203.80.138 -w ~/aa.data
使用em1网卡,网卡可以通过命令ifconfig查看
host:目的或源地址是1.203.80.138的网络数据
-w ~/aa.data:将抓包转换成wireshark工具识别的格式