Is there an API for Wireshark, to develop programs

2020-02-08 15:18发布

Googling didn't give me great results. Is there any sort of API for Wireshark that abstracts away from the main source code so we can develop programs that interact with it and deal with the data it provides?

edit: I appreciate the suggestions for different ways to receive packets, but I want to implement packet injection into Wireshark. Sniffing will be an important part of my project, however I'm not sure that the suggested solution allows for packet injection.

7条回答
Bombasti
2楼-- · 2020-02-08 15:41

c++ well could not find one.. but here is the wireshark documentation of Python support..! http://wiki.wireshark.org/Python

查看更多
在下西门庆
3楼-- · 2020-02-08 15:43

Since there's at least one that makes commercial products that integrate somewhat with wireshark , it has to be possible. It seems the immediate integration point is with the data it produces according to wikipedia, Wireshark uses libpcap. A quick google search reveals that there are several options

Scapy actually looks kind of interesting, though it doesn't really do anything to interact with wireshark, but you can capture packets with it.

查看更多
Fickle 薄情
4楼-- · 2020-02-08 15:50

wireshark uses libpcap, this library abstracts away platform differences in packet sniffing and provides a format for data files. that's how I'd inject packets into wireshark.

查看更多
对你真心纯属浪费
5楼-- · 2020-02-08 16:00

Try the lua scripting that they've got in the newer versions of wireshark.. you can write custom dissectors (for your own protocols and so on).

http://wiki.wireshark.org/Lua

查看更多
▲ chillily
6楼-- · 2020-02-08 16:06

I wasn't able to find any information indicating that to be possible in the developer's guide. So that seems indicate "no".

查看更多
爷的心禁止访问
7楼-- · 2020-02-08 16:07

I use pypcap to read packets and dpkt to parse.

For example, to use dpkt to read packets from a saved pcap:

import socket
import dpkt
import sys
pcapReader = dpkt.pcap.Reader(file(sys.argv[1], "rb"))
for ts, data in pcapReader:
    ether = dpkt.ethernet.Ethernet(data)
    if ether.type != dpkt.ethernet.ETH_TYPE_IP: raise
    ip = ether.data
    src = socket.inet_ntoa(ip.src)
    dst = socket.inet_ntoa(ip.dst)
    print "%s -> %s" % (src, dst)

To grab frames off the wire with pypcap:

    import pcap
    pc = pcap.pcapObject()
    dev = sys.argv[1]
    pc.open_live(dev, 1600, 0, 100)
    pc.setfilter("udp port 53", 0, 0)
    while 1:
        pc.dispatch(1, p.pcap_dispatch)

Of course, the two can be used together: (ripped from pypcap's homepage)

>>> import dpkt, pcap
>>> pc = pcap.pcap()
>>> pc.setfilter('icmp')
>>> for ts, pkt in pc:
...     print `dpkt.ethernet.Ethernet(pkt)`

Good luck!

查看更多
登录 后发表回答