一:
下载 libpcap-1.8.1.tar.gz 和 tcpdump-4.9.0.tar.gz工具:
二:编译libpcap:
1.解压并修改:
root# tar -zxvf libpcap-1.8.1.tar.gz
root# cd libpcap-1.8.1/
root# vi configure +5435
#注释8行代码:
5435 #add by lt 20170319
5436 #if test -z "$with_pcap" && test "$cross_compiling" = yes; then
5437 # as_fn_error $? "pcap type not determined when cross-compiling; use --with-pcap=..." "$LINENO" 5
5438 #fi
5439
5440 # Check whether --with-pcap was given.
5441 #if test "${with_pcap+set}" = set; then :
5442 # withval=$with_pcap;
5443 #fi
2.配置并编译:
root@user126:/opt/libpcap-1.8.1/# ./configure --prefix=/opt/libpcap/pub --host=arm-himix400-linux --target=arm-himix400-linux CC=arm-himix400-linux-gcc
make
make install
三:编译tcpdump:
root# tar -zxvf tcpdump-4.9.0.tar.gz
root@user126:/opt/tcpdump-4.9.0# ./configure --prefix=/opt/tcpdump/dump --host=arm-himix400-linux CC=arm-himix400-linux-gcc
make
make install
四:使用参考:
注意需要等网口配置好之后再去抓数据,尤其是4G网口,因为当网口重启后,抓包会终止。
1.抓eth0网口的数据:
./tcpdump -i eth0 -s 0 -w /var/aaa.pcap
2.抓eth0网口的23端口数据:
./tcpdump tcp port 23 -i eth0 -s 0 -w /var/bbb.pcap
3.抓4G网口的数据:
./tcpdump -i usb0 -s 0 -w /var/ccc.pcap