无法使用jpcap打开设备

时间:2012-12-20 14:47:15

标签: java winpcap jpcap

我无法使用jpcap库打开找到的网络设备。我安装了winpcap并在system32和syswow64中安装了jpcap.dll。尝试打开设备时,以下教程代码崩溃。崩溃日志:

PacketCapture: loading native library jpcap.. ok
net.sourceforge.jpcap.capture.CaptureDeviceOpenException: Error opening adapter: The system cannot find the device specified. (20)
    at net.sourceforge.jpcap.capture.PacketCapture.open(Native Method)
    at net.sourceforge.jpcap.capture.PacketCapture.open(PacketCapture.java:57)
    at networksnifferdesktop.NetworkSnifferDesktop.<init>(NetworkSnifferDesktop.java:26)
    at networksnifferdesktop.NetworkSnifferDesktop.main(NetworkSnifferDesktop.java:40)
Java Result: 1

在调试中,我可以看到m_device设置为:

"\Device\NPF_{EC5226CF-3F55-4148-B40E-1FC3F8BB3398}   Realtek PCIe GBE Family Controller"

在以下代码中:

package networksnifferdesktop;

import net.sourceforge.jpcap.capture.*;
import net.sourceforge.jpcap.net.*;

public class NetworkSnifferDesktop
{
    private static final int INFINITE = -1;
    private static final int PACKET_COUNT = 10;

    // BPF filter for capturing any packet
    private static final String FILTER = "";

    private PacketCapture m_pcap;
    private String m_device;

    public NetworkSnifferDesktop() throws Exception
    {
        // Step 1:  Instantiate Capturing Engine
        m_pcap = new PacketCapture();

        // Step 2:  Check for devices
        m_device = m_pcap.findDevice();

        // Step 3:  Open Device for Capturing (requires root)
        m_pcap.open(m_device, true);

        // Step 4:  Add a BPF Filter (see tcpdump documentation)
        m_pcap.setFilter(FILTER, true);

        // Step 5:  Register a Listener for Raw Packets
        m_pcap.addRawPacketListener(new RawPacketHandler());

        // Step 6:  Capture Data (max. PACKET_COUNT packets)
        m_pcap.capture(PACKET_COUNT);
    }

    public static void main(String[] args)
    {
        try
        {
            NetworkSnifferDesktop example = new NetworkSnifferDesktop();
        }
        catch (Exception e)
        {
            e.printStackTrace();
            System.exit(1);
        }
    }
}

class RawPacketHandler implements RawPacketListener
{
    private static int m_counter = 0;

    public void rawPacketArrived(RawPacket data)
    {
        m_counter++;
        System.out.println("Received packet (" + m_counter + ")");
    }
}

1 个答案:

答案 0 :(得分:3)

"\Device\NPF_{EC5226CF-3F55-4148-B40E-1FC3F8BB3398} Realtek PCIe GBE Family Controller",如果你的字面意思是一个字符串,其第一个字符是“\ Device”中的“D”,其最后一个字符是“Controller”中的“r”,是有效的WinPcap设备名称字符串。

"\Device\NPF_{EC5226CF-3F55-4148-B40E-1FC3F8BB3398}"将是有效的设备名称字符串。

从查看Jpcap源代码看,findDevice方法似乎 NOT 返回有效的设备名称字符串。它被记录为返回“描述网络设备的字符串”;它返回的是一个字符串,其中包含设备名称字符串,换行符,两个空格以及设备的供应商描述字符串。 This has been reported as a Jpcap bug

我建议您扫描字符串以查找第一个空格字符(“空白空间”包括空格和换行符),并使用,作为设备名称传递给打开的例程,一切都可以但不是包括那个空白字符。 (如果找不到空格字符,请使用整个字符串。)