|
slackware 10.1
swaret --install tcpdump
安装到tcpdump version 3.9.4 libpcap version 0.9.4
网卡
eth0 Link encap:Ethernet HWaddr 00:15:60:0C:93:82
inet addr:172.20.1.190 Bcast:172.20.1.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:228210 errors:0 dropped:0 overruns:0 frame:0
TX packets:100824 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:30956935 (29.5 Mb) TX bytes:26026005 (24.8 Mb)
Interrupt:5
eth1 Link encap:Ethernet HWaddr 00:15:60:0C:93:81
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:5
#tcpdump dst host 172.20.1.44
没有抓取到包
在windows上面用Ethereal可以抓到
tcpdump不是说用root登陆就可以打开网卡的混杂模式然后抓取到网络包的么?
我用ssh然后用root登陆的,为什么还是抓取不到任何的关于上面命令的包?
为什么,多谢!!!
在线等 |
|