{"id":1303,"date":"2022-01-07T10:21:26","date_gmt":"2022-01-07T09:21:26","guid":{"rendered":"https:\/\/virtualguru.cz\/?p=1303"},"modified":"2022-01-07T12:14:20","modified_gmt":"2022-01-07T11:14:20","slug":"jak-na-packet-capture","status":"publish","type":"post","link":"https:\/\/virtualguru.cz\/en\/2022\/01\/07\/jak-na-packet-capture\/","title":{"rendered":"Jak na packet capture"},"content":{"rendered":"<p>Pro spoustu z V\u00e1s to bude jist\u011b rutina, ale zde je n\u00e1vod jak zaznamenat s\u00ed\u0165ov\u00e9 pakety pro anal\u00fdzu nap\u0159. pomoc\u00ed Wireshark.<\/p>\n<p>Nejprve mus\u00edme zjistit jak\u00fd identifik\u00e1tor m\u00e1 virtu\u00e1ln\u00ed stroj, na kter\u00e9m chceme zaznamenat p\u0159en\u00e1\u0161en\u00e1 data. Virtu\u00e1ln\u00ed stroj m\u00e1 identifik\u00e1tor zvan\u00fd <em>World Id.<\/em> P\u0159ihl\u00e1s\u00edme se tedy na ESXi hypervizor do shellu, nebo p\u0159es SSH a vylistujeme si v\u0161echny VM na n\u011bm spu\u0161t\u011bn\u00e9.<\/p>\n<p>To m\u016f\u017eeme prov\u00e9st pomoc\u00ed v\u00edce p\u0159\u00edkaz\u016f, nap\u0159. <em>esxcli vm process list\u00a0<\/em> nebo p\u0159ehledn\u011bji\u00a0<em><strong>esxcli network vm list<\/strong><\/em><\/p>\n<p><a href=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1304 size-medium\" src=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01-300x153.jpg\" alt=\"\" width=\"300\" height=\"153\" srcset=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01-300x153.jpg 300w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01-1024x522.jpg 1024w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01-768x392.jpg 768w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01-1536x783.jpg 1536w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/esxcli-01.jpg 1775w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Nyn\u00ed, kdy\u017e ji\u017e m\u00e1me identifik\u00e1tor m\u016f\u017eeme zjistit p\u0159\u00edmo \u010d\u00edslo portu, kter\u00fd pou\u017e\u00edv\u00e1, tzv.\u00a0<em>Port ID\u00a0<\/em>p\u0159\u00edkazem <em><strong>esxcli network vm port list -w World_ID<\/strong><\/em><a href=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/port_id.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-1305 aligncenter\" src=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/port_id-300x100.jpg\" alt=\"\" width=\"300\" height=\"100\" srcset=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/port_id-300x100.jpg 300w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/port_id.jpg 717w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Te\u010f u\u017e m\u00e1me v\u0161e pot\u0159ebn\u00e9 abychom spustili zachyt\u00e1v\u00e1n\u00ed paket\u016f na po\u017eadovan\u00e9m portu nebo portech a to p\u0159\u00edkazem <em><strong>pktcap-uw &#8211;switchport Port_ID -o \/tmp\/vysledny_soubor.pcap<\/strong><\/em><\/p>\n<p>P\u0159\u00edkaz pktcap-uw m\u00e1 n\u011bkolik p\u0159ep\u00edna\u010d\u016f\/parametr\u016f. V\u00e1m by m\u011bly sta\u010dit dva. Prvn\u00ed, <strong>&#8211;switchport<\/strong>, kde zad\u00e1te po\u017eadovan\u00fd port a druh\u00fd <strong>-o<\/strong>, kter\u00fdm p\u0159esm\u011brujete v\u00fdstup do v\u00fdsledn\u00e9ho souboru, kter\u00fd pak m\u016f\u017eete analyzovat ve WireShark.<a href=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/pkcap.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-1306 aligncenter\" src=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/pkcap-300x195.jpg\" alt=\"\" width=\"300\" height=\"195\" srcset=\"https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/pkcap-300x195.jpg 300w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/pkcap-768x498.jpg 768w, https:\/\/virtualguru.cz\/wp-content\/uploads\/2022\/01\/pkcap.jpg 913w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Zachyt\u00e1v\u00e1n\u00ed b\u011b\u017e\u00ed a\u017e do t\u00e9 doby, ne\u017e jej ru\u010dn\u011b ukon\u010d\u00edte, sta\u010d\u00ed pomoc\u00ed CTRL+C. Pak ji\u017e jen vykop\u00edrujete v\u00fdsledn\u00fd soubor, nap\u0159. p\u0159es WinSCP.<\/p>\n<p>Douf\u00e1m, \u017ee V\u00e1m tento \u010dl\u00e1nek pomohl, abyste jednotliv\u00e9 p\u0159\u00edkazy nemuseli lovit v pam\u011bti, nebo na g\u016fglu.<\/p>","protected":false},"excerpt":{"rendered":"<p>Pro spoustu z V\u00e1s to bude jist\u011b rutina, ale zde je n\u00e1vod jak zaznamenat s\u00ed\u0165ov\u00e9 pakety pro anal\u00fdzu nap\u0159. pomoc\u00ed Wireshark. Nejprve mus\u00edme zjistit jak\u00fd&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/virtualguru.cz\/en\/2022\/01\/07\/jak-na-packet-capture\/\">Continue Reading<span class=\"screen-reader-text\">Jak na packet capture<\/span> <i class=\"fas fa-angle-right\"><\/i><\/a><\/div>","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"iawp_total_views":14,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-1303","post","type-post","status-publish","format-standard","hentry","category-vsphere","entry"],"_links":{"self":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/1303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/comments?post=1303"}],"version-history":[{"count":6,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/1303\/revisions"}],"predecessor-version":[{"id":1312,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/1303\/revisions\/1312"}],"wp:attachment":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/media?parent=1303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/categories?post=1303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/tags?post=1303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}