[转] Android利用tcpdump抓包
2016-03-22 17:38
661 查看
原文链接:/article/4008758.html
Android利用tcpdump抓包
博客分类:Android
AndroidAccessGoHTML
Instructions
http://source.android.com/porting/tcpdump.html
Source Code and Documents
http://www.tcpdump.org/
Compiled Binary Download
http://www.strazzere.com/android/tcpdump
数据包分析工具Wireshark
http://www.wireshark.org/download.html
Installing tcpdump
Pushing the binary to an existing device
Download tcpdump from http://www.tcpdump.org/, then execute:
Cmd代码
![](https://oscdn.geek-share.com/Uploads/Images/Content/201705/07fc3ae7c030c629d734ac350cd30687.png)
adb root
adb remount
adb push /wherever/you/put/tcpdump /system/xbin/tcpdump
adb shell chmod 6755 /data/local/tmp/tcpdump
Running tcpdump
You need to have root access on your device.
Batch mode capture
The typical procedure is to capture packets to a file and then examine the file on the desktop, as illustrated below:
Cmd代码
![](https://oscdn.geek-share.com/Uploads/Images/Content/201705/07fc3ae7c030c629d734ac350cd30687.png)
adb shell tcpdump -i any -p -s 0 -w /sdcard/capture.pcap
# "-i any": listen on any network interface
# "-p": disable promiscuous mode (doesn't work anyway)
# "-s 0": capture the entire packet
# "-w": write packets to a file (rather than printing to stdout)
... do whatever you want to capture, then ^C to stop it ...
adb pull /sdcard/capture.pcap .
sudo apt-get install wireshark # or ethereal, if you're still on dapper
wireshark capture.pcap # or ethereal
... look at your packets and be wise ...
You can run tcpdump in the background from an interactive shell or from Terminal. By default, tcpdump captures all traffic without filtering. If you prefer, add an expression like port 80 to the tcpdump command line.
Real time packet monitoring
Execute the following if you would like to watch packets go by rather than capturing them to a file (-n skips DNS lookups. -s 0 captures the entire packet rather than just the header):
Cmd代码
![](https://oscdn.geek-share.com/Uploads/Images/Content/201705/07fc3ae7c030c629d734ac350cd30687.png)
adb shell tcpdump -n -s 0
Typical tcpdump options apply. For example, if you want to see HTTP traffic:
Cmd代码
![](https://oscdn.geek-share.com/Uploads/Images/Content/201705/07fc3ae7c030c629d734ac350cd30687.png)
adb shell tcpdump -X -n -s 0 port 80
相关文章推荐
- 3.22学习理解httpContext与where 1=1
- AlphaGo论文的译文,用深度神经网络和树搜索征服围棋:Mastering the game of Go with deep neural networks and tree search
- HttpRequestMethodNotSupportedException
- WinInet, WinHttp, Winsock, ws2_32的区别和联系
- 高效利用Angular中内置服务$http、$location等
- 【原】HTTP in iOS你看我就够
- 网络第03天:XML数据解析
- 数字签名与数字证书
- linux系统下tcpdump和nc工具的使用
- 常见HTTP错误代码大全
- Thttpd_上传文件
- iOS企业版发布 HTTPS证书以及服务器设置
- 基于HTTP协议的Web服务器
- 手机usb共享网络给ubuntu命令行配置
- MFC发送HTTP请求
- http 简单调用第三方接口
- Python twisted事件驱动网络框架 源码剖析
- 计算机网络 数据链路层
- HTTP协议中POST、GET、HEAD的区别是什么
- “App TransportSecurity has blocked a cleartext HTTP (http://) resource load since it isinsecure.