以下是Linux Sniffer的一般配置使用方法:
sudo apt update,sudo apt install tcpdump。sudo yum install tcpdump。sudo apt-get update,sudo apt-get install build-essential libncurses5-dev zlib1g-dev gawk flex quilt git-lfs libssl-dev xz-utils -y。sudo yum groupinstall "Development Tools" -y,sudo yum install ncurses-devel zlib-devel awk flex quilt git-lfs openssl-devel xz -y。git clone https://github.com/netsniff/netsniff.git,cd netsniff。make,sudo make install。/etc/netsniff/netsniff.conf,可修改以下参数: CAPTURE_ENABLED:1启用捕获,0禁用。MODE:promisc为混杂模式,nonpromisc为非混杂模式。INTERFACE:指定网络接口,如eth0、wlan0等。FILTER:设置过滤器表达式,如"tcp and src host 192.168.1.100"。sudo /usr/local/bin/sniff启动。sudo tcpdump -i eth0可在eth0接口上捕获数据包;sudo tcpdump -i eth0 port 80可过滤HTTP流量。