我无法使用jpcap库打开找到的网络设备。我安装了winpcap并在system32和syswow64中安装了jpcap.dll。尝试打开设备时,以下教程代码崩溃。崩溃日志:
PacketCapture: loading native library jpcap.. ok
net.sourceforge.jpcap.capture.CaptureDeviceOpenException: Error opening adapter: The system cannot find the device specified. (20)
at net.sourceforge.jpcap.capture.PacketCapture.open(Native Method)
at net.sourceforge.jpcap.capture.PacketCapture.open(PacketCapture.java:57)
at networksnifferdesktop.NetworkSnifferDesktop.<init>(NetworkSnifferDesktop.java:26)
at networksnifferdesktop.NetworkSnifferDesktop.main(NetworkSnifferDesktop.java:40)
Java Result: 1
在调试中,我可以看到m_device
设置为:
"\Device\NPF_{EC5226CF-3F55-4148-B40E-1FC3F8BB3398} Realtek PCIe GBE Family Controller"
在以下代码中:
package networksnifferdesktop;
import net.sourceforge.jpcap.capture.*;
import net.sourceforge.jpcap.net.*;
public class NetworkSnifferDesktop
{
private static final int INFINITE = -1;
private static final int PACKET_COUNT = 10;
// BPF filter for capturing any packet
private static final String FILTER = "";
private PacketCapture m_pcap;
private String m_device;
public NetworkSnifferDesktop() throws Exception
{
// Step 1: Instantiate Capturing Engine
m_pcap = new PacketCapture();
// Step 2: Check for devices
m_device = m_pcap.findDevice();
// Step 3: Open Device for Capturing (requires root)
m_pcap.open(m_device, true);
// Step 4: Add a BPF Filter (see tcpdump documentation)
m_pcap.setFilter(FILTER, true);
// Step 5: Register a Listener for Raw Packets
m_pcap.addRawPacketListener(new RawPacketHandler());
// Step 6: Capture Data (max. PACKET_COUNT packets)
m_pcap.capture(PACKET_COUNT);
}
public static void main(String[] args)
{
try
{
NetworkSnifferDesktop example = new NetworkSnifferDesktop();
}
catch (Exception e)
{
e.printStackTrace();
System.exit(1);
}
}
}
class RawPacketHandler implements RawPacketListener
{
private static int m_counter = 0;
public void rawPacketArrived(RawPacket data)
{
m_counter++;
System.out.println("Received packet (" + m_counter + ")");
}
}
答案 0 :(得分:3)
"\Device\NPF_{EC5226CF-3F55-4148-B40E-1FC3F8BB3398} Realtek PCIe GBE Family Controller"
,如果你的字面意思是一个字符串,其第一个字符是“\ Device”中的“D”,其最后一个字符是“Controller”中的“r”,是不有效的WinPcap设备名称字符串。
"\Device\NPF_{EC5226CF-3F55-4148-B40E-1FC3F8BB3398}"
将是有效的设备名称字符串。
从查看Jpcap源代码看,findDevice
方法似乎 NOT 返回有效的设备名称字符串。它被记录为返回“描述网络设备的字符串”;它返回的是一个字符串,其中包含设备名称字符串,换行符,两个空格以及设备的供应商描述字符串。 This has been reported as a Jpcap bug
我建议您扫描字符串以查找第一个空格字符(“空白空间”包括空格和换行符),并使用,作为设备名称传递给打开的例程,一切都可以但不是包括那个空白字符。 (如果找不到空格字符,请使用整个字符串。)