PS£ºtcpdumpÊÇÒ»¸öÓÃÓÚ½ØÈ¡ÍøÂç·Ö×飬²¢Êä³ö·Ö×éÄÚÈݵŤ¾ß£¬¼òµ¥Ëµ¾ÍÊÇÊý¾Ý°ü×¥°ü¹¤¾ß¡£tcpdumpƾ½èÇ¿´óµÄ¹¦ÄܺÍÁé»îµÄ½ØÈ¡²ßÂÔ£¬Ê¹Æä³ÉΪLinuxϵͳÏÂÓÃÓÚÍøÂç·ÖÎöºÍÎÊÌâÅŲéµÄÊ×Ñ¡¹¤¾ß¡£
tcpdumpÌṩÁËÔ´´úÂ룬¹«¿ªÁ˽ӿڣ¬Òò´Ë¾ß±¸ºÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬¶ÔÓÚÍøÂçά»¤ºÍÈëÇÖÕß¶¼ÊǷdz£ÓÐÓõŤ¾ß¡£tcpdump´æÔÚÓÚ»ù±¾µÄLinuxϵͳÖУ¬ÓÉÓÚËüÐèÒª½«ÍøÂç½çÃæÉèÖÃΪ»ìÔÓģʽ£¬ÆÕͨÓû§²»ÄÜÕý³£Ö´ÐУ¬µ«¾ß±¸rootȨÏÞµÄÓû§¿ÉÒÔÖ±½ÓÖ´ÐÐËüÀ´»ñÈ¡ÍøÂçÉϵÄÐÅÏ¢¡£Òò´ËϵͳÖдæÔÚÍøÂç·ÖÎö¹¤¾ßÖ÷Òª²»ÊǶԱ¾»ú°²È«µÄÍþв£¬¶øÊǶÔÍøÂçÉÏµÄÆäËû¼ÆËã»úµÄ°²È«´æÔÚÍþв¡£
Ò»¡¢¸ÅÊö
¹ËÃû˼Ò壬tcpdump¿ÉÒÔ½«ÍøÂçÖд«Ë͵ÄÊý¾Ý°üµÄ¡°Í·¡±ÍêÈ«½Ø»ñÏÂÀ´Ìṩ·ÖÎö¡£ËüÖ§³ÖÕë¶ÔÍøÂç²ã¡¢ÐÒé¡¢Ö÷»ú¡¢ÍøÂç»ò¶Ë¿ÚµÄ¹ýÂË£¬²¢Ìṩand¡¢or¡¢notµÈÂß¼Óï¾äÀ´°ïÖúÄãÈ¥µôÎÞÓõÄÐÅÏ¢¡£
# tcpdump -vv
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
11:53:21.444591 IP (tos 0x10, ttl 64, id 19324, offset 0, flags [DF], proto 6, length: 92) asptest.localdomain.ssh > 192.168.228.244.1858: P 3962132600:3962132652(52) ack 2726525936 win 1266
asptest.localdomain.1077 > 192.168.228.153.domain: [bad udp cksum 166e!] 325+ PTR? 244.228.168.192.in-addr.arpa. (46)
11:53:21.446929 IP (tos 0x0, ttl 64, id 42911, offset 0, flags [DF], proto 17, length: 151) 192.168.228.153.domain > asptest.localdomain.1077: 325 NXDomain q: PTR? 244.228.168.192.in-addr.arpa. 0/1/0 ns: 168.192.in-addr.arpa. (123)
11:53:21.447408 IP (tos 0x10, ttl 64, id 19328, offset 0, flags [DF], proto 6, length: 172) asptest.localdomain.ssh > 192.168.228.244.1858: P 168:300(132) ack 1 win 1266
347 packets captured
1474 packets received by filter
745 packets dropped by kernel
²»´ø²ÎÊýµÄtcpdump»áÊÕ¼¯ÍøÂçÖÐËùÓеÄÐÅÏ¢°üÍ·£¬Êý¾ÝÁ¿¾Þ´ó£¬±ØÐë¹ýÂË¡£
¶þ¡¢Ñ¡Ïî½éÉÜ
-A ÒÔASCII¸ñʽ´òÓ¡³öËùÓзÖ×飬²¢½«Á´Â·²ãµÄÍ·×îС»¯¡£
-c ÔÚÊÕµ½Ö¸¶¨µÄÊýÁ¿µÄ·Ö×éºó£¬tcpdump¾Í»áÍ£Ö¹¡£
-C ÔÚ½«Ò»¸öÔʼ·Ö×éдÈëÎļþ֮ǰ£¬¼ì²éÎļþµ±Ç°µÄ´óСÊÇ·ñ³¬¹ýÁ˲ÎÊýfile_size ÖÐÖ¸¶¨µÄ´óС¡£Èç¹û³¬¹ýÁËÖ¸¶¨´óС£¬Ôò¹Ø±Õµ±Ç°Îļþ£¬È»ºóÔÚ´ò¿ªÒ»¸öеÄÎļþ¡£²ÎÊý file_size µÄµ¥Î»ÊÇÕ××Ö½Ú£¨ÊÇ1,000,000×Ö½Ú£¬¶ø²»ÊÇ1,048,576×Ö½Ú£©¡£
-d ½«Æ¥ÅäÐÅÏ¢°üµÄ´úÂëÒÔÈËÃÇÄܹ»Àí½âµÄ»ã±à¸ñʽ¸ø³ö¡£
-dd ½«Æ¥ÅäÐÅÏ¢°üµÄ´úÂëÒÔcÓïÑÔ³ÌÐò¶ÎµÄ¸ñʽ¸ø³ö¡£
-ddd ½«Æ¥ÅäÐÅÏ¢°üµÄ´úÂëÒÔÊ®½øÖƵÄÐÎʽ¸ø³ö¡£
-D ´òÓ¡³öϵͳÖÐËùÓпÉÒÔÓÃtcpdump½Ø°üµÄÍøÂç½Ó¿Ú¡£
-e ÔÚÊä³öÐдòÓ¡³öÊý¾ÝÁ´Â·²ãµÄÍ·²¿ÐÅÏ¢¡£
-E ÓÃspi@ipaddr algo:secret½âÃÜÄÇЩÒÔaddr×÷ΪµØÖ·£¬²¢ÇÒ°üº¬Á˰²È«²ÎÊýË÷ÒýÖµspiµÄIPsec ESP·Ö×é¡£
-f ½«ÍⲿµÄInternetµØÖ·ÒÔÊý×ÖµÄÐÎʽ´òÓ¡³öÀ´¡£
-F ´ÓÖ¸¶¨µÄÎļþÖжÁÈ¡±í´ïʽ£¬ºöÂÔÃüÁîÐÐÖиø³öµÄ±í´ïʽ¡£
-i Ö¸¶¨¼àÌýµÄÍøÂç½Ó¿Ú¡£
-l ʹ±ê×¼Êä³ö±äΪ»º³åÐÐÐÎʽ£¬¿ÉÒÔ°ÑÊý¾Ýµ¼³öµ½Îļþ¡£
-L ÁгöÍøÂç½Ó¿ÚµÄÒÑÖªÊý¾ÝÁ´Â·¡£
-m ´ÓÎļþmoduleÖе¼ÈëSMI MIBÄ£¿é¶¨Òå¡£¸Ã²ÎÊý¿ÉÒÔ±»Ê¹Óöà´Î£¬ÒÔµ¼Èë¶à¸öMIBÄ£¿é¡£
-M Èç¹ûtcp±¨ÎÄÖдæÔÚTCP-MD5Ñ¡ÏÔòÐèÒªÓÃsecret×÷Ϊ¹²ÏíµÄÑéÖ¤ÂëÓÃÓÚÑéÖ¤TCP-MD5ѡѡÏîÕªÒª£¨ÏêÇé¿É²Î¿¼RFC 2385£©¡£
-b ÔÚÊý¾Ý-Á´Â·²ãÉÏÑ¡ÔñÐÒ飬°üÀ¨ip¡¢arp¡¢rarp¡¢ipx¶¼ÊÇÕâÒ»²ãµÄ¡£
-n ²»°ÑÍøÂçµØÖ·×ª»»³ÉÃû×Ö¡£
-nn Ö±½ÓÒÔIPºÍ¶Ë¿ÚºÅÏÔʾ£¬¶ø·ÇÖ÷»úÓë·þÎñÆ÷Ãû³Æ¡£
-N ²»Êä³öÖ÷»úÃûÖеÄÓòÃû²¿·Ö¡£ÀýÈ磬¡®nic.ddn.mil¡®Ö»Êä³ö¡¯nic¡®¡£
-t ÔÚÊä³öµÄÿһÐв»´òӡʱ¼ä´Á¡££¨£tt -ttt£©
-O ²»ÔËÐзÖ×é·Ö×鯥Å䣨packet-matching£©´úÂëÓÅ»¯³ÌÐò¡£
-P ²»½«ÍøÂç½Ó¿ÚÉèÖóɻìÔÓģʽ¡£
-q ¿ìËÙÊä³ö¡£Ö»Êä³ö½ÏÉÙµÄÐÒéÐÅÏ¢¡£
-r ´ÓÖ¸¶¨µÄÎļþÖжÁÈ¡°ü(ÕâЩ°üÒ»°ãͨ¹ý-wÑ¡Ïî²úÉú)¡£
-S ½«tcpµÄÐòÁкÅÒÔ¾ø¶ÔÖµÐÎʽÊä³ö£¬¶ø²»ÊÇÏà¶ÔÖµ¡£
-s ´Óÿ¸ö·Ö×éÖжÁÈ¡×ʼµÄsnaplen¸ö×Ö½Ú£¬¶ø²»ÊÇĬÈϵÄ68¸ö×Ö½Ú¡£-s 0±íʾ²»ÏÞÖÆ³¤¶È£¬Êä³öÕû¸ö°ü¡£
-T ½«¼àÌýµ½µÄ°üÖ±½Ó½âÊÍΪָ¶¨µÄÀàÐ͵ı¨ÎÄ£¬³£¼ûµÄÀàÐÍÓÐrpcÔ¶³Ì¹ý³Ìµ÷Ó㩺Ísnmp£¨¼òµ¥ÍøÂç¹ÜÀíÐÒ飻£©¡£
-t ²»ÔÚÿһÐÐÖÐÊä³öʱ¼ä´Á¡£
-tt ÔÚÿһÐÐÖÐÊä³ö·Ç¸ñʽ»¯µÄʱ¼ä´Á¡£
-ttt Êä³ö±¾ÐкÍÇ°ÃæÒ»ÐÐÖ®¼äµÄʱ¼ä²î¡£
-tttt ÔÚÿһÐÐÖÐÊä³öÓÉdate´¦ÀíµÄĬÈϸñʽµÄʱ¼ä´Á¡£
-u Êä³öδ½âÂëµÄNFS¾ä±ú¡£
-v Êä³öÒ»¸öÉÔ΢ÏêϸµÄÐÅÏ¢£¬ÀýÈçÔÚip°üÖпÉÒÔ°üÀ¨ttlºÍ·þÎñÀàÐ͵ÄÐÅÏ¢¡£
-vv Êä³ö¸üÏêϸµÄÐÅÏ¢¡£
-vv Êä³öÏêϸµÄ±¨ÎÄÐÅÏ¢¡£
-w Ö±½Ó½«·Ö×éдÈëÎļþÖУ¬¶ø²»ÊDz»·ÖÎö²¢´òÓ¡³öÀ´¡£ £¨Êä³öµÄ.pcapÎļþ¿ÉÒÔÔÚwindowsÖÐÓÃwireshark´ò¿ª£¬½øÐнøÒ»²½·ÖÎö£©
ÒªÈÃwiresharkÄÜ·ÖÎötcpdumpµÄ°ü£¬¹Ø¼üµÄµØ·½ÊÇ -s ²ÎÊý£¬ »¹ÓÐҪΪ -w±£´æÊä³öÎļþ¡£
-X ÒÔ¼°-XX£¬ÒÔ16½øÖÆÓëASCII·½Ê½Êä³ö£¬¼´¿É¶Á·½Ê½ÏÔʾÊý¾Ý°ü£¬ÊʺÏhttp¡¢memcached asciiµÈÃ÷ÎÄ´«ÊäµÄÐÒ飬¿ÉÒÔ¿´µ½ÄÚÈÝ£»
Èý¡¢tcpdumpµÄ±í´ïʽ½éÉÜ
±í´ïʽÊÇÒ»¸öÕýÔò±í´ïʽ£¬tcpdumpÀûÓÃËü×÷Ϊ¹ýÂ˱¨ÎĵÄÌõ¼þ£¬Èç¹ûÒ»¸ö±¨ÎÄÂú×ã±í ´ïʽµÄÌõ¼þ£¬ÔòÕâ¸ö±¨ÎĽ«»á±»²¶»ñ¡£Èç¹ûûÓиø³öÈκÎÌõ¼þ£¬ÔòÍøÂçÉÏËùÓеÄÐÅÏ¢°ü ½«»á±»½Ø»ñ¡£
ÔÚ±í´ïʽÖÐÒ»°ãÈçϼ¸ÖÖÀàÐ͵Ĺؼü×Ö£º
µÚÒ»ÖÖÊǹØÓÚÀàÐ͵Ĺؼü×Ö£¬Ö÷Òª°üÀ¨host£¬net£¬port£¬ÀýÈç host 210.27.48.2£¬ Ö¸Ã÷ 210.27.48.2ÊÇһ̨Ö÷»ú£¬net 202.0.0.0Ö¸Ã÷202.0.0.0ÊÇÒ»¸öÍøÂçµØÖ·£¬port 23 Ö¸Ã÷¶Ë¿ÚºÅÊÇ23¡£Èç¹ûûÓÐÖ¸¶¨ÀàÐÍ£¬È±Ê¡µÄÀàÐÍÊÇhost¡£
µÚ¶þÖÖÊÇÈ·¶¨´«Êä·½ÏòµÄ¹Ø¼ü×Ö£¬Ö÷Òª°üÀ¨src£¬dst£¬dst or src£¬dst and src£¬ ÕâЩ¹Ø¼ü×ÖÖ¸Ã÷ÁË´«ÊäµÄ·½Ïò¡£¾ÙÀý˵Ã÷£¬src 210.27.48.2 £¬Ö¸Ã÷ip°üÖÐÔ´µØÖ·ÊÇ 210.27.48.2 £¬ dst net 202.0.0.0 Ö¸Ã÷Ä¿µÄÍøÂçµØÖ·ÊÇ202.0.0.0¡£Èç¹ûûÓÐÖ¸Ã÷·½Ïò¹Ø¼ü×Ö£¬ÔòȱʡÊÇsrc or dst¹Ø¼ü×Ö¡£
µÚÈýÖÖÊÇÐÒéµÄ¹Ø¼ü×Ö£¬Ö÷Òª°üÀ¨fddi£¬ip£¬arp£¬rarp£¬tcp£¬udpµÈÀàÐÍ¡£FddiÖ¸Ã÷ÊÇÔÚFDDI (·Ö²¼Ê½¹âÏËÊý¾Ý½Ó¿ÚÍøÂç)ÉϵÄÌØ¶¨µÄÍøÂçÐÒ飬ʵ¼ÊÉÏËüÊÇ¡±ether¡±µÄ±ðÃû£¬fddiºÍether ¾ßÓÐÀàËÆµÄÔ´µØÖ·ºÍÄ¿µÄµØÖ·£¬ËùÒÔ¿ÉÒÔ½«fddiÐÒé°üµ±×÷etherµÄ°ü½øÐд¦ÀíºÍ·ÖÎö¡£ ÆäËûµÄ¼¸¸ö¹Ø¼ü×Ö¾ÍÊÇÖ¸Ã÷Á˼àÌýµÄ°üµÄÐÒéÄÚÈÝ¡£Èç¹ûûÓÐÖ¸¶¨ÈκÎÐÒ飬Ôòtcpdump ½«»á ¼àÌýËùÓÐÐÒéµÄÐÅÏ¢°ü¡£
³ýÁËÕâÈýÖÖÀàÐ͵Ĺؼü×ÖÖ®Í⣬ÆäËûÖØÒªµÄ¹Ø¼ü×ÖÈçÏ£ºgateway£¬ broadcast£¬less£¬ greater£¬ »¹ÓÐÈýÖÖÂß¼ÔËË㣬ȡ·ÇÔËËãÊÇ ¡®not ¡® ¡®! ¡®£¬ ÓëÔËËãÊÇ¡¯and¡¯£¬¡¯&&¡¯;»òÔËËãÊÇ¡¯or¡¯ £¬¡¯||¡¯£» ÕâЩ¹Ø¼ü×Ö¿ÉÒÔ×éºÏÆðÀ´¹¹³ÉÇ¿´óµÄ×éºÏÌõ¼þÀ´Âú×ãÈËÃǵÄÐèÒª¡£
Àý£º
tcpdump -i lo -nn -A -s 0 tcp -w /home/open/1.txt port 3306 and src host 112.142.34.24 and dst host 192.168.1.33
tcpdump -X -n -s 0 tcp port 8033 -i lo
tcpdump -A -n -x -s 0 tcp port 7430 and host 192.168.3.143
tcpdump -x -n -s 0 tcp port 9024 or 9021 or 9023 or 9020
ËÄ¡¢Êä³ö½á¹û½éÉÜ
ÏÂÃæÎÒÃǽéÉܼ¸ÖÖµäÐ͵ÄtcpdumpÃüÁîµÄÊä³öÐÅÏ¢
(1) Êý¾ÝÁ´Â·²ãÍ·ÐÅÏ¢
ʹÓÃÃüÁ
#tcpdump --e host ICE
ICE ÊÇһ̨װÓÐlinuxµÄÖ÷»ú¡£ËüµÄMACµØÖ·ÊÇ0£º90£º27£º58£ºAF£º1A H219ÊÇһ̨װÓÐSolarisµÄSUN¹¤×÷Õ¾¡£ËüµÄMACµØÖ·ÊÇ8£º0£º20£º79£º5B£º46£» ÉÏÒ»ÌõÃüÁîµÄÊä³ö½á¹ûÈçÏÂËùʾ£º
21:50:12.847509 eth0 < 8:0:20:79:5b:46 0:90:27:58:af:1a ip 60: h219.33357 > ICE. telne t 0:0(0) ack 22535 win 8760 (DF)
21£º50£º12ÊÇÏÔʾµÄʱ¼ä£¬ 847509ÊÇIDºÅ£¬eth0 <±íʾ´ÓÍøÂç½Ó¿Úeth0½ÓÊո÷Ö×飬 eth0 >±íʾ´ÓÍøÂç½Ó¿ÚÉ豸·¢ËÍ·Ö×飬 8:0:20:79:5b:46ÊÇÖ÷»úH219µÄMACµØÖ·£¬ Ëü±íÃ÷ÊÇ´ÓÔ´µØÖ·H219·¢À´µÄ·Ö×é. 0:90:27:58:af:1aÊÇÖ÷»úICEµÄMACµØÖ·£¬ ±íʾ¸Ã·Ö×éµÄÄ¿µÄµØÖ·ÊÇICE¡£ ip ÊDZíÃ÷¸Ã·Ö×éÊÇIP·Ö×飬60 ÊÇ·Ö×éµÄ³¤¶È£¬ h219.33357 > ICE. telnet ±íÃ÷¸Ã·Ö×éÊÇ´ÓÖ÷»úH219µÄ33357¶Ë¿Ú·¢ÍùÖ÷»úICEµÄ TELNET(23)¶Ë¿Ú¡£ ack 22535 ±íÃ÷¶ÔÐòÁкÅÊÇ222535µÄ°ü½øÐÐÏìÓ¦¡£ win 8760±íÃ÷·¢ ËÍ´°¿ÚµÄ´óСÊÇ8760¡£
(2) ARP°üµÄtcpdumpÊä³öÐÅÏ¢
ʹÓÃÃüÁ
#tcpdump arp
µÃµ½µÄÊä³ö½á¹ûÊÇ£º
22:32:42.802509 eth0 > arp who-has route tell ICE (0:90:27:58:af:1a)
22:32:42.802902 eth0 < arp reply route is-at 0:90:27:12:10:66 (0:90:27:58:af:1a)
22:32:42ÊÇʱ¼ä´Á£¬ 802509ÊÇIDºÅ£¬ eth0 >±íÃ÷´ÓÖ÷»ú·¢³ö¸Ã·Ö×飬arp±íÃ÷ÊÇARPÇëÇó°ü£¬ who-has route tell ICE±íÃ÷ÊÇÖ÷»úICEÇëÇóÖ÷»úrouteµÄMACµØÖ·¡£ 0:90:27:58:af:1aÊÇÖ÷»ú ICEµÄMACµØÖ·¡£
(3) TCP°üµÄÊä³öÐÅÏ¢
ÓÃtcpdump²¶»ñµÄTCP°üµÄÒ»°ãÊä³öÐÅÏ¢ÊÇ£º
src > dst: flags data-seqno ack window urgent options
src > dst:±íÃ÷´ÓÔ´µØÖ·µ½Ä¿µÄµØÖ·£¬ flagsÊÇTCP±¨ÎÄÖеıêÖ¾ÐÅÏ¢£¬S ÊÇSYN±êÖ¾£¬ F (FIN)£¬ P (PUSH) £¬ R (RST) ¡°.¡± (ûÓбê¼Ç); data-seqnoÊDZ¨ÎÄÖеÄÊý¾Ý µÄ˳ÐòºÅ£¬ ackÊÇÏÂ´ÎÆÚÍûµÄ˳ÐòºÅ£¬ windowÊǽÓÊÕ»º´æµÄ´°¿Ú´óС£¬ urgent±íÃ÷ ±¨ÎÄÖÐÊÇ·ñÓнô¼±Ö¸Õë¡£ OptionsÊÇÑ¡Ïî¡£
(4) UDP°üµÄÊä³öÐÅÏ¢
ÓÃtcpdump²¶»ñµÄUDP°üµÄÒ»°ãÊä³öÐÅÏ¢ÊÇ£º
route.port1 > ICE.port2: udp lenth
UDPÊ®·Ö¼òµ¥£¬ÉÏÃæµÄÊä³öÐбíÃ÷´ÓÖ÷»úrouteµÄport1¶Ë¿Ú·¢³öµÄÒ»¸öUDP±¨ÎÄ µ½Ö÷»úICEµÄport2¶Ë¿Ú£¬ÀàÐÍÊÇUDP£¬ °üµÄ³¤¶ÈÊÇlenth¡£
Îå¡¢¾ÙÀý
(1) ÏëÒª½Ø»ñËùÓÐ210.27.48.1 µÄÖ÷»úÊÕµ½µÄºÍ·¢³öµÄËùÓеķÖ×飺
#tcpdump host 210.27.48.1
(2) ÏëÒª½Ø»ñÖ÷»ú210.27.48.1 ºÍÖ÷»ú210.27.48.2»ò210.27.48.3µÄͨÐÅ£¬Ê¹ÓÃÃüÁעÒ⣺À¨ºÅǰµÄ·´Ð±¸ÜÊDZØÐëµÄ£©£º
#tcpdump host 210.27.48.1 and (210.27.48.2 or 210.27.48.3 )
(3) Èç¹ûÏëÒª»ñÈ¡Ö÷»ú210.27.48.1³ýÁ˺ÍÖ÷»ú210.27.48.2Ö®ÍâËùÓÐÖ÷»úͨÐŵÄip°ü£¬Ê¹ÓÃÃüÁ
#tcpdump ip host 210.27.48.1 and ! 210.27.48.2
(4) Èç¹ûÏëÒª»ñÈ¡Ö÷»ú192.168.228.246½ÓÊÕ»ò·¢³öµÄssh°ü£¬²¢ÇÒ²»×ª»»Ö÷»úÃûʹÓÃÈçÏÂÃüÁ
#tcpdump -nn -n src host 192.168.228.246 and port 22 and tcp
(5) »ñÈ¡Ö÷»ú192.168.228.246½ÓÊÕ»ò·¢³öµÄssh°ü£¬²¢°ÑmacµØÖ·Ò²Ò»Í¬ÏÔʾ£º
# tcpdump -e src host 192.168.228.246 and port 22 and tcp -n -nn
(6) ¹ýÂ˵ÄÊÇÔ´Ö÷»úΪ192.168.0.1ÓëÄ¿µÄÍøÂçΪ192.168.0.0µÄ±¨Í·£º
tcpdump src host 192.168.0.1 and dst net 192.168.0.0/24
(7) ¹ýÂËÔ´Ö÷»úÎïÀíµØÖ·ÎªXXXµÄ±¨Í·£º
tcpdump ether src 00:50:04:BA:9B and dst¡¡
£¨ÎªÊ²Ã´ether srcºóÃæÃ»ÓÐhost»òÕßnet£¿ÎïÀíµØÖ·µ±È»²»¿ÉÄÜÓÐÍøÂ磩¡£
(8) ¹ýÂËÔ´Ö÷»ú192.168.0.1ºÍÄ¿µÄ¶Ë¿Ú²»ÊÇtelnetµÄ±¨Í·£¬²¢µ¼Èëµ½tes.t.txtÎļþÖУº
Tcpdump src host 192.168.0.1 and dst port not telnet -l > test.txt
ip icmp arp rarp ºÍ tcp¡¢udp¡¢icmpÕâЩѡÏîµÈ¶¼Òª·Åµ½µÚÒ»¸ö²ÎÊýµÄλÖã¬ÓÃÀ´¹ýÂËÊý¾Ý±¨µÄÀàÐÍ¡£
ÀýÌ⣺ÈçºÎʹÓÃtcpdump¼àÌýÀ´×Ôeth0ÊÊÅ俨ÇÒͨÐÅÐÒéΪport 22£¬Ä¿±êÀ´Ô´Îª192.168.1.100µÄÊý¾Ý°ü×ÊÁÏ£¿
´ð£ºtcpdump -i eth0 -nn port 22 and src host 192.168.1.100
ÀýÌ⣺ÈçºÎʹÓÃtcpdumpץȡ·ÃÎÊeth0ÊÊÅ俨ÇÒ·ÃÎʶ˿ÚΪtcp 9080£¿
´ð:tcpdump -i eth0 dst 172.168.70.35 and tcp port 9080
ÀýÌ⣺ÈçºÎʹÓÃtcpdumpץȡÓëÖ÷»ú192.168.43.23»ò×ÅÓëÖ÷»ú192.168.43.24ͨÐű¨ÎÄ£¬²¢ÇÒÏÔʾÔÚ¿ØÖÆÌ¨ÉÏ
tcpdump -X -s 1024 -i eth0 host (192.168.43.23 or 192.168.43.24) and host 172.16.70.35
×÷Õߣºljianhui