SmartSniff v1.40 - 封包擷取程式
SmartSniff provides 3 methods for capturing TCP/IP packets : 1. Raw Sockets (Only for Windows 2000/XP or greater): Allows you to capture TCP/IP packets on your network without installing a capture driver. This method has some limitations and problems.
2. WinPcap Capture Driver: Allows you to capture TCP/IP packets on all Windows operating systems. (Windows 98/ME/NT/2000/XP/2003/Vista) In order to use it, you have to download and install WinPcap Capture Driver from this Web site. (WinPcap is a free open-source capture driver.)
This method is generally the preferred way to capture TCP/IP packets with SmartSniff, and it works better than the Raw Sockets method.
3. Microsoft Network Monitor Driver (Only for Windows 2000/XP/2003): Microsoft provides a free capture driver under Windows 2000/XP/2003 that can be used by SmartSniff, but this driver is not installed by default, and you have to manually install it, by using one of the following options:
* Option 1: Install it from the CD-ROM of Windows 2000/XP according to the instructions in Microsoft Web site
* Option 2 (XP Only) : Download and install the Windows XP Service Pack 2 Support Tools. One of the tools in this package is netcap.exe. When you run this tool in the first time, the Network Monitor Driver will automatically be installed on your system. Notice: If WinPcap is installed on your system, and you want to use the Microsoft Network Monitor Driver method, it's recommended to run SmartSniff with /NoCapDriver, because the Microsoft Network Monitor Driver may not work properly when WinPcap is loaded too. Version 1.40:‧Added local/remote MAC addresses (relevant only for local network, and it doesn't work with raw sockets)
‧Added IPNetInfo integration - When you put IPNetInfo utility in the same folder of SmartSniff, You can view the information about the remote IP addresses.
‧Added IP Country columns to display the country name of IP addresses. (requires to download an external file from http://software77.net/cgi-bin/ip-country/geo-ip.pl )http://www.nirsoft.net/utils/smsniff.html哇哇評:
擷取網路封包來看是一件好玩的事情
但是我還是習慣用wireshark(前身ethereal)來幹壞事
沒有啦~其實看封包還頗無聊的
若沒有真的是專門在做網路的工作~我想沒必要去看封包的
但是的確可以去學習一下封包裡面有哪些怪東西^^