我一直在关注http://www.codeproject.com/KB/IP/sharppcap.aspx上的指南来实现一个简单的数据包嗅探器来为我自动化身份验证,我已经设法进入过滤部分,并且到目前为止,它必须对教程代码进行一些调整才能使它工作,但我现在感到难过.
我收到的错误是;
'PacketDotNet.TcpPacket.GetEncapsulated(PacketDotNet.Packet)'的最佳重载方法匹配有一些无效的参数
参数1:无法从'SharpPcap.RawCapture'转换为'PacketDotNet.Packet'
但是我还没有提到我自己的PacketDotNet(到目前为止一切都是SharpPcap).
到目前为止我已经包含了整个代码,问题出在device_OnPacketArrival()函数中.
using System;
using System.Collections.Generic;
using System.Linq;
using System.Text;
using PacketDotNet;
using SharpPcap;
namespace ConsoleApplication1
{
class Program
{
static void Main(string[] args)
{
string ver = SharpPcap.Version.VersionString;
Console.WriteLine("SharpPcap {0}, Example1.IfList.cs", ver);
// Retrieve the device list
CaptureDeviceList devices = CaptureDeviceList.Instance;
// If no devices were found print an error
if (devices.Count < 1)
{
Console.WriteLine("No devices were found on this machine");
return;
}
// Extract a device from the list
ICaptureDevice device = devices[0];
// Register our handler function to the
// 'packet arrival' event
device.OnPacketArrival +=
new SharpPcap.PacketArrivalEventHandler(device_OnPacketArrival);
// Open the device for capturing
int readTimeoutMilliseconds = 1000;
device.Open(DeviceMode.Promiscuous, readTimeoutMilliseconds);
// tcpdump filter to capture only TCP/IP packets
string filter = "ip and tcp";
device.Filter = filter;
Console.WriteLine();
Console.WriteLine("-- The following tcpdump filter will be applied: \"{0}\"",
filter);
Console.WriteLine("-- Listening on {0}, hit 'Enter' to stop...",
device.Description);
// Start capturing packets indefinitely
device.Capture();
// Close the pcap device
// (Note: this line will never be called since
// we're capturing indefinitely
device.Close();
}
private static void device_OnPacketArrival(object sender, CaptureEventArgs e)
{
var tcp = TcpPacket.GetEncapsulated(e.Packet);
}
}
}
Run Code Online (Sandbox Code Playgroud)
SharpPcap.RawPacket用于保存通过网络适配器捕获的原始数据,但PacketDotNet需要在GetEncapsulated()方法工作之前解析的数据包.您需要的步骤如下:
var packet = PacketDotNet.Packet.ParsePacket(rawPacket.LinkLayerType, rawPacket.Data);
Run Code Online (Sandbox Code Playgroud)
然后,您可以通过传递方法提取封装TcpPacket的GetEncapsulated()方法packet.
来自https://sourceforge.net/projects/sharppcap/的SharpPcap源代码示例12 显示了语法以及如何修改数据包.
请记住,PacketType.GetEncapsulated()返回对数据包部分的引用,因此修改它将改变原始数据包.