0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

OpenWrt パケットキャプチャー

Last updated at Posted at 2023-06-16

はじめに

初心者対応構成

  • スクリプトでの自動設定
  • UCIとLuCi及びWinSCPにて比較しながら作業がおススメ

PowerShellSSHアクセス

ssh root@192.168.1.1
ssh root@192.168.1.1のショートカット作成(デスクトップ)
powershell
$DESKTOP = ([Environment]::GetFolderPath("Desktop") + "\192.168.1.1.lnk")
$WshShell = New-Object -comObject WScript.Shell
$Shortcut = $WshShell.CreateShortcut("$DESKTOP")
$Shortcut.TargetPath = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
$Shortcut.Arguments = '-windowstyle hidden -ExecutionPolicy RemoteSigned "Start-Process ssh root@192.168.1.1"'
$Shortcut.IconLocation = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe,0"
$Shortcut.WorkingDirectory = "."
$Shortcut.Save()

  • 強制的に貼り付け
  • yes

SSHログイン出来ない場合:exclamation:

known_hostsクリア

  • C:\Users\yourusername\.ssh\known_hosts ※Windows隠しファイル
powershell
Clear-Content .ssh\known_hosts -Force


OpenSSHのインストール
※Windows 10 Fall Creators Update(1709)以降標準搭載

  • 機能の確認
powershell
Get-WindowsCapability -Online | Where-Object Name -like 'OpenSSH*'

  • 機能のインストール
powershell
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0


パケットキャプチャー

TCPDUMP

  • デバイスの設定
opkg update
opkg install tcpdump
uci add dropbear dropbear
uci set dropbear.@dropbear[-1].RootPasswordAuth="on"
uci set dropbear.@dropbear[-1].PasswordAuth="on"
uci set dropbear.@dropbear[-1].GatewayPorts='on'
uci set dropbear.@dropbear[-1].Port="23" #任意のポート
uci commit dropbear
/etc/init.d/dropbear restart

Wireshark

  • Windowsの設定

    • Stable Release: 4.0.6
      ※インストール時sshdump必須

    • 以下のショートカットを作成
      "C:\Program Files\Wireshark\Wireshark.exe" -k -i -

  • ワイヤーシャークの設定

    • SSH remote capture
      • Serverタブ
        • Remote SSH server address : 192.168.1.1
        • Remote SSH server port : 23 # デバイスで設定したポート
      • Authnticationタブ
        • Remote SSH server usename : root
        • Remote SSH server password : デバイスのパスワード
      • Captureタブ
        • Remote capture command : -i br-lan -U -s0 -w -

luci-app-tcpdump

git clone https://github.com/KFERMercer/luci-app-tcpdump.git ./package/luci-app-tcpdump
make menuconfig

CloudShark

未検証

opkg update
opkg install luci-i18n-cshark-ja

エアクラック

opkg update
opkg install aircrack-ng

おまけ

アングラですね

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?