无法从SharpPcap.RawCapture转换为PacketDotNet.Packet

Clo*_*ith 6 .net c# sharppcap

我一直在关注http://www.codeproject.com/KB/IP/sharppcap.aspx上的指南来实现一个简单的数据包嗅探器来为我自动化身份验证,我已经设法进入过滤部分,并且到目前为止,它必须对教程代码进行一些调整才能使它工作,但我现在感到难过.

我收到的错误是;

'PacketDotNet.TcpPacket.GetEncapsulated(PacketDotNet.Packet)'的最佳重载方法匹配有一些无效的参数

参数1:无法从'SharpPcap.RawCapture'转换为'PacketDotNet.Packet'

但是我还没有提到我自己的PacketDotNet(到目前为止一切都是SharpPcap).

到目前为止我已经包含了整个代码,问题出在device_OnPacketArrival()函数中.

 using System;
 using System.Collections.Generic;
 using System.Linq;
 using System.Text;
 using PacketDotNet;
 using SharpPcap;

 namespace ConsoleApplication1
 {
     class Program
     {
         static void Main(string[] args)
         {
             string ver = SharpPcap.Version.VersionString;
             Console.WriteLine("SharpPcap {0}, Example1.IfList.cs", ver);

             // Retrieve the device list
             CaptureDeviceList devices = CaptureDeviceList.Instance;

             // If no devices were found print an error
             if (devices.Count < 1)
             {
                 Console.WriteLine("No devices were found on this machine");
                 return;
             }

             // Extract a device from the list
             ICaptureDevice device = devices[0];

             // Register our handler function to the
             // 'packet arrival' event
             device.OnPacketArrival +=
                 new SharpPcap.PacketArrivalEventHandler(device_OnPacketArrival);

             // Open the device for capturing
             int readTimeoutMilliseconds = 1000;
             device.Open(DeviceMode.Promiscuous, readTimeoutMilliseconds);

             // tcpdump filter to capture only TCP/IP packets
             string filter = "ip and tcp";
             device.Filter = filter;

             Console.WriteLine();
             Console.WriteLine("-- The following tcpdump filter will be applied: \"{0}\"",
                 filter);
             Console.WriteLine("-- Listening on {0}, hit 'Enter' to stop...",
                 device.Description);

             // Start capturing packets indefinitely
             device.Capture();

             // Close the pcap device
             // (Note: this line will never be called since
             // we're capturing indefinitely
             device.Close();
         }
         private static void device_OnPacketArrival(object sender, CaptureEventArgs e)
         {
             var tcp = TcpPacket.GetEncapsulated(e.Packet);
         }
     }
 }
Run Code Online (Sandbox Code Playgroud)

Chr*_*gan 6

SharpPcap.RawPacket用于保存通过网络适配器捕获的原始数据,但PacketDotNet需要在GetEncapsulated()方法工作之前解析的数据包.您需要的步骤如下:

var packet = PacketDotNet.Packet.ParsePacket(rawPacket.LinkLayerType, rawPacket.Data);
Run Code Online (Sandbox Code Playgroud)

然后,您可以通过传递方法提取封装TcpPacket的GetEncapsulated()方法packet.

来自https://sourceforge.net/projects/sharppcap/的SharpPcap源代码示例12 显示了语法以及如何修改数据包.

请记住,PacketType.GetEncapsulated()返回对数据包部分的引用,因此修改它将改变原始数据包.