Wireshark 打不开 pcap
📂 Wireshark 报错无法打开 r0capture 输出的 pcap。
症状
The file "...pcap" is not a capture file in a format Wireshark understands.原因与排查
1. pcap 全局头损坏
r0capture 用 open(pcap, "wb", 0) 无缓冲写,Ctrl+C 时 stoplog 会 flush+close。若进程被 kill -9(非 SIGTERM),可能未 close,但已写的数据应仍可读。
2. 文件为空
bash
ls -l out.pcap
# 若 0 字节,说明一条包都没抓到空 pcap 没有 24 字节全局头,Wireshark 无法识别。先确认抓到了流量。
3. 字节序 magic
pcap magic 应是 d4 c3 b2 a1(小端)。用 hex 工具看前 4 字节:
bash
xxd out.pcap | head -1
# 00000000: d4c3 b2a1 0200 0400 ...若不是 d4c3b2a1 或 a1b2c3d4,文件已损坏。
4. 用 tcpdump 验证
bash
tcpdump -r out.pcap -n
# 能读出包说明 pcap 格式正确5. Wireshark 版本太老
老版 Wireshark 不认 linktype 228 (LINKTYPE_IPV4)。升级 Wireshark。