CentOS 嗅探器配置步骤
一 准备与权限
ip link 查看。二 快速上手 tcpdump
sudo yum install -y tcpdumpsudo tcpdump -i eth0 -nn -vsudo tcpdump -i eth0 port 80 -nnsudo tcpdump -i eth0 -w capture.pcaptcpdump -r capture.pcap -nn -i eth0host 192.0.2.10 and port 3306)。三 图形化分析 Wireshark
sudo yum install -y epel-release && sudo yum install -y wiresharktshark(Wireshark 命令行版)进行自动化抓包与分析。tcpdump 生成的 .pcap 文件下载到本地,用 Wireshark 打开进行深度协议解析与图形化分析。四 进阶工具 Go-Sniffer 与 MySQL Sniffer
sudo yum install -y libpcap libpcap-develwget https://golang.org/dl/go1.10.3.linux-amd64.tar.gz && tar -C /usr/local -xzf go1.10.3.linux-amd64.tar.gzecho 'export PATH=$PATH:/usr/local/go/bin' >> ~/.bashrc && source ~/.bashrcgo get -v -u github.com/40t/go-sniffer && sudo cp -rf $(go env GOPATH)/bin/go-sniffer /usr/local/bingo-sniffer eth0 redis -p 6379 out.loggo-sniffer eth0 mysql -p 3306sudo yum install -y cmake libpcap-devel glib2-devel libnet-devel gcc gcc-c++git clone https://github.com/jeremycole/mysql-sniffer.gitcd mysql-sniffer && mkdir proj && cd proj && cmake .. && make && cd bin/./mysql-sniffer -c mysql-sniffer.conf(配置文件可选)五 性能与合规建议