ºìÁªLinuxÃÅ»§
Linux°ïÖú

Linux²Ù×÷ϵͳtcpdump×¥°ü·ÖÎöÏê½â

·¢²¼Ê±¼ä:2014-06-29 10:54:29À´Ô´:ºìÁª×÷Õß:velcbo
PS£ºtcpdumpÊÇÒ»¸öÓÃÓÚ½ØÈ¡ÍøÂç·Ö×飬²¢Êä³ö·Ö×éÄÚÈݵŤ¾ß£¬¼òµ¥Ëµ¾ÍÊÇÊý¾Ý°ü×¥°ü¹¤¾ß¡£tcpdumpƾ½èÇ¿´óµÄ¹¦ÄܺÍÁé»îµÄ½ØÈ¡²ßÂÔ£¬Ê¹Æä³ÉΪLinuxϵͳÏÂÓÃÓÚÍøÂç·ÖÎöºÍÎÊÌâÅŲéµÄÊ×Ñ¡¹¤¾ß¡£

tcpdumpÌṩÁËÔ´´úÂ룬¹«¿ªÁ˽ӿڣ¬Òò´Ë¾ß±¸ºÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬¶ÔÓÚÍøÂçά»¤ºÍÈëÇÖÕß¶¼ÊǷdz£ÓÐÓõŤ¾ß¡£tcpdump´æÔÚÓÚ»ù±¾µÄLinuxϵͳÖУ¬ÓÉÓÚËüÐèÒª½«ÍøÂç½çÃæÉèÖÃΪ»ìÔÓģʽ£¬ÆÕͨÓû§²»ÄÜÕý³£Ö´ÐУ¬µ«¾ß±¸rootȨÏÞµÄÓû§¿ÉÒÔÖ±½ÓÖ´ÐÐËüÀ´»ñÈ¡ÍøÂçÉϵÄÐÅÏ¢¡£Òò´ËϵͳÖдæÔÚÍøÂç·ÖÎö¹¤¾ßÖ÷Òª²»ÊǶԱ¾»ú°²È«µÄÍþв£¬¶øÊǶÔÍøÂçÉÏµÄÆäËû¼ÆËã»úµÄ°²È«´æÔÚÍþв¡£

Ò»¡¢¸ÅÊö
¹ËÃû˼Ò壬tcpdump¿ÉÒÔ½«ÍøÂçÖд«Ë͵ÄÊý¾Ý°üµÄ¡°Í·¡±ÍêÈ«½Ø»ñÏÂÀ´Ìṩ·ÖÎö¡£ËüÖ§³ÖÕë¶ÔÍøÂç²ã¡¢Ð­Òé¡¢Ö÷»ú¡¢ÍøÂç»ò¶Ë¿ÚµÄ¹ýÂË£¬²¢Ìṩand¡¢or¡¢notµÈÂß¼­Óï¾äÀ´°ïÖúÄãÈ¥µôÎÞÓõÄÐÅÏ¢¡£

# tcpdump -vv
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
11:53:21.444591 IP (tos 0x10, ttl 64, id 19324, offset 0, flags [DF], proto 6, length: 92) asptest.localdomain.ssh > 192.168.228.244.1858: P 3962132600:3962132652(52) ack 2726525936 win 1266
asptest.localdomain.1077 > 192.168.228.153.domain: [bad udp cksum 166e!] 325+ PTR? 244.228.168.192.in-addr.arpa. (46)
11:53:21.446929 IP (tos 0x0, ttl 64, id 42911, offset 0, flags [DF], proto 17, length: 151) 192.168.228.153.domain > asptest.localdomain.1077: 325 NXDomain q: PTR? 244.228.168.192.in-addr.arpa. 0/1/0 ns: 168.192.in-addr.arpa. (123)
11:53:21.447408 IP (tos 0x10, ttl 64, id 19328, offset 0, flags [DF], proto 6, length: 172) asptest.localdomain.ssh > 192.168.228.244.1858: P 168:300(132) ack 1 win 1266
347 packets captured
1474 packets received by filter
745 packets dropped by kernel

²»´ø²ÎÊýµÄtcpdump»áÊÕ¼¯ÍøÂçÖÐËùÓеÄÐÅÏ¢°üÍ·£¬Êý¾ÝÁ¿¾Þ´ó£¬±ØÐë¹ýÂË¡£

¶þ¡¢Ñ¡Ïî½éÉÜ

-A ÒÔASCII¸ñʽ´òÓ¡³öËùÓзÖ×飬²¢½«Á´Â·²ãµÄÍ·×îС»¯¡£

-c ÔÚÊÕµ½Ö¸¶¨µÄÊýÁ¿µÄ·Ö×éºó£¬tcpdump¾Í»áÍ£Ö¹¡£

-C ÔÚ½«Ò»¸öԭʼ·Ö×éдÈëÎļþ֮ǰ£¬¼ì²éÎļþµ±Ç°µÄ´óСÊÇ·ñ³¬¹ýÁ˲ÎÊýfile_size ÖÐÖ¸¶¨µÄ´óС¡£Èç¹û³¬¹ýÁËÖ¸¶¨´óС£¬Ôò¹Ø±Õµ±Ç°Îļþ£¬È»ºóÔÚ´ò¿ªÒ»¸öеÄÎļþ¡£²ÎÊý file_size µÄµ¥Î»ÊÇÕ××Ö½Ú£¨ÊÇ1,000,000×Ö½Ú£¬¶ø²»ÊÇ1,048,576×Ö½Ú£©¡£

-d ½«Æ¥ÅäÐÅÏ¢°üµÄ´úÂëÒÔÈËÃÇÄܹ»Àí½âµÄ»ã±à¸ñʽ¸ø³ö¡£

-dd ½«Æ¥ÅäÐÅÏ¢°üµÄ´úÂëÒÔcÓïÑÔ³ÌÐò¶ÎµÄ¸ñʽ¸ø³ö¡£

-ddd ½«Æ¥ÅäÐÅÏ¢°üµÄ´úÂëÒÔÊ®½øÖƵÄÐÎʽ¸ø³ö¡£

-D ´òÓ¡³öϵͳÖÐËùÓпÉÒÔÓÃtcpdump½Ø°üµÄÍøÂç½Ó¿Ú¡£

-e ÔÚÊä³öÐдòÓ¡³öÊý¾ÝÁ´Â·²ãµÄÍ·²¿ÐÅÏ¢¡£

-E ÓÃspi@ipaddr algo:secret½âÃÜÄÇЩÒÔaddr×÷ΪµØÖ·£¬²¢ÇÒ°üº¬Á˰²È«²ÎÊýË÷ÒýÖµspiµÄIPsec ESP·Ö×é¡£

-f ½«ÍⲿµÄInternetµØÖ·ÒÔÊý×ÖµÄÐÎʽ´òÓ¡³öÀ´¡£

-F ´ÓÖ¸¶¨µÄÎļþÖжÁÈ¡±í´ïʽ£¬ºöÂÔÃüÁîÐÐÖиø³öµÄ±í´ïʽ¡£

-i Ö¸¶¨¼àÌýµÄÍøÂç½Ó¿Ú¡£

-l ʹ±ê×¼Êä³ö±äΪ»º³åÐÐÐÎʽ£¬¿ÉÒÔ°ÑÊý¾Ýµ¼³öµ½Îļþ¡£

-L ÁгöÍøÂç½Ó¿ÚµÄÒÑÖªÊý¾ÝÁ´Â·¡£

-m ´ÓÎļþmoduleÖе¼ÈëSMI MIBÄ£¿é¶¨Òå¡£¸Ã²ÎÊý¿ÉÒÔ±»Ê¹Óöà´Î£¬ÒÔµ¼Èë¶à¸öMIBÄ£¿é¡£

-M Èç¹ûtcp±¨ÎÄÖдæÔÚTCP-MD5Ñ¡ÏÔòÐèÒªÓÃsecret×÷Ϊ¹²ÏíµÄÑéÖ¤ÂëÓÃÓÚÑéÖ¤TCP-MD5ѡѡÏîÕªÒª£¨ÏêÇé¿É²Î¿¼RFC 2385£©¡£

-b ÔÚÊý¾Ý-Á´Â·²ãÉÏÑ¡ÔñЭÒ飬°üÀ¨ip¡¢arp¡¢rarp¡¢ipx¶¼ÊÇÕâÒ»²ãµÄ¡£

-n ²»°ÑÍøÂçµØÖ·×ª»»³ÉÃû×Ö¡£

-nn Ö±½ÓÒÔIPºÍ¶Ë¿ÚºÅÏÔʾ£¬¶ø·ÇÖ÷»úÓë·þÎñÆ÷Ãû³Æ¡£

-N ²»Êä³öÖ÷»úÃûÖеÄÓòÃû²¿·Ö¡£ÀýÈ磬¡®nic.ddn.mil¡®Ö»Êä³ö¡¯nic¡®¡£

-t ÔÚÊä³öµÄÿһÐв»´òӡʱ¼ä´Á¡££¨£­tt -ttt£©

-O ²»ÔËÐзÖ×é·Ö×鯥Å䣨packet-matching£©´úÂëÓÅ»¯³ÌÐò¡£

-P ²»½«ÍøÂç½Ó¿ÚÉèÖóɻìÔÓģʽ¡£

-q ¿ìËÙÊä³ö¡£Ö»Êä³ö½ÏÉÙµÄЭÒéÐÅÏ¢¡£

-r ´ÓÖ¸¶¨µÄÎļþÖжÁÈ¡°ü(ÕâЩ°üÒ»°ãͨ¹ý-wÑ¡Ïî²úÉú)¡£

-S ½«tcpµÄÐòÁкÅÒÔ¾ø¶ÔÖµÐÎʽÊä³ö£¬¶ø²»ÊÇÏà¶ÔÖµ¡£

-s ´Óÿ¸ö·Ö×éÖжÁÈ¡×ʼµÄsnaplen¸ö×Ö½Ú£¬¶ø²»ÊÇĬÈϵÄ68¸ö×Ö½Ú¡£-s 0±íʾ²»ÏÞÖÆ³¤¶È£¬Êä³öÕû¸ö°ü¡£

-T ½«¼àÌýµ½µÄ°üÖ±½Ó½âÊÍΪָ¶¨µÄÀàÐ͵ı¨ÎÄ£¬³£¼ûµÄÀàÐÍÓÐrpcÔ¶³Ì¹ý³Ìµ÷Ó㩺Ísnmp£¨¼òµ¥ÍøÂç¹ÜÀíЭÒ飻£©¡£

-t ²»ÔÚÿһÐÐÖÐÊä³öʱ¼ä´Á¡£

-tt ÔÚÿһÐÐÖÐÊä³ö·Ç¸ñʽ»¯µÄʱ¼ä´Á¡£

-ttt Êä³ö±¾ÐкÍÇ°ÃæÒ»ÐÐÖ®¼äµÄʱ¼ä²î¡£

-tttt ÔÚÿһÐÐÖÐÊä³öÓÉdate´¦ÀíµÄĬÈϸñʽµÄʱ¼ä´Á¡£

-u Êä³öδ½âÂëµÄNFS¾ä±ú¡£

-v Êä³öÒ»¸öÉÔ΢ÏêϸµÄÐÅÏ¢£¬ÀýÈçÔÚip°üÖпÉÒÔ°üÀ¨ttlºÍ·þÎñÀàÐ͵ÄÐÅÏ¢¡£

-vv Êä³ö¸üÏêϸµÄÐÅÏ¢¡£

-vv Êä³öÏêϸµÄ±¨ÎÄÐÅÏ¢¡£

-w Ö±½Ó½«·Ö×éдÈëÎļþÖУ¬¶ø²»ÊDz»·ÖÎö²¢´òÓ¡³öÀ´¡£ £¨Êä³öµÄ.pcapÎļþ¿ÉÒÔÔÚwindowsÖÐÓÃwireshark´ò¿ª£¬½øÐнøÒ»²½·ÖÎö£©

ÒªÈÃwiresharkÄÜ·ÖÎötcpdumpµÄ°ü£¬¹Ø¼üµÄµØ·½ÊÇ -s ²ÎÊý£¬ »¹ÓÐҪΪ -w±£´æÊä³öÎļþ¡£

-X ÒÔ¼°-XX£¬ÒÔ16½øÖÆÓëASCII·½Ê½Êä³ö£¬¼´¿É¶Á·½Ê½ÏÔʾÊý¾Ý°ü£¬ÊʺÏhttp¡¢memcached asciiµÈÃ÷ÎÄ´«ÊäµÄЭÒ飬¿ÉÒÔ¿´µ½ÄÚÈÝ£»

Èý¡¢tcpdumpµÄ±í´ïʽ½éÉÜ

±í´ïʽÊÇÒ»¸öÕýÔò±í´ïʽ£¬tcpdumpÀûÓÃËü×÷Ϊ¹ýÂ˱¨ÎĵÄÌõ¼þ£¬Èç¹ûÒ»¸ö±¨ÎÄÂú×ã±í ´ïʽµÄÌõ¼þ£¬ÔòÕâ¸ö±¨ÎĽ«»á±»²¶»ñ¡£Èç¹ûûÓиø³öÈκÎÌõ¼þ£¬ÔòÍøÂçÉÏËùÓеÄÐÅÏ¢°ü ½«»á±»½Ø»ñ¡£

ÔÚ±í´ïʽÖÐÒ»°ãÈçϼ¸ÖÖÀàÐ͵Ĺؼü×Ö£º

µÚÒ»ÖÖÊǹØÓÚÀàÐ͵Ĺؼü×Ö£¬Ö÷Òª°üÀ¨host£¬net£¬port£¬ÀýÈç host 210.27.48.2£¬ Ö¸Ã÷ 210.27.48.2ÊÇһ̨Ö÷»ú£¬net 202.0.0.0Ö¸Ã÷202.0.0.0ÊÇÒ»¸öÍøÂçµØÖ·£¬port 23 Ö¸Ã÷¶Ë¿ÚºÅÊÇ23¡£Èç¹ûûÓÐÖ¸¶¨ÀàÐÍ£¬È±Ê¡µÄÀàÐÍÊÇhost¡£

µÚ¶þÖÖÊÇÈ·¶¨´«Êä·½ÏòµÄ¹Ø¼ü×Ö£¬Ö÷Òª°üÀ¨src£¬dst£¬dst or src£¬dst and src£¬ ÕâЩ¹Ø¼ü×ÖÖ¸Ã÷ÁË´«ÊäµÄ·½Ïò¡£¾ÙÀý˵Ã÷£¬src 210.27.48.2 £¬Ö¸Ã÷ip°üÖÐÔ´µØÖ·ÊÇ 210.27.48.2 £¬ dst net 202.0.0.0 Ö¸Ã÷Ä¿µÄÍøÂçµØÖ·ÊÇ202.0.0.0¡£Èç¹ûûÓÐÖ¸Ã÷·½Ïò¹Ø¼ü×Ö£¬ÔòȱʡÊÇsrc or dst¹Ø¼ü×Ö¡£

µÚÈýÖÖÊÇЭÒéµÄ¹Ø¼ü×Ö£¬Ö÷Òª°üÀ¨fddi£¬ip£¬arp£¬rarp£¬tcp£¬udpµÈÀàÐÍ¡£FddiÖ¸Ã÷ÊÇÔÚFDDI (·Ö²¼Ê½¹âÏËÊý¾Ý½Ó¿ÚÍøÂç)ÉϵÄÌØ¶¨µÄÍøÂçЭÒ飬ʵ¼ÊÉÏËüÊÇ¡±ether¡±µÄ±ðÃû£¬fddiºÍether ¾ßÓÐÀàËÆµÄÔ´µØÖ·ºÍÄ¿µÄµØÖ·£¬ËùÒÔ¿ÉÒÔ½«fddiЭÒé°üµ±×÷etherµÄ°ü½øÐд¦ÀíºÍ·ÖÎö¡£ ÆäËûµÄ¼¸¸ö¹Ø¼ü×Ö¾ÍÊÇÖ¸Ã÷Á˼àÌýµÄ°üµÄЭÒéÄÚÈÝ¡£Èç¹ûûÓÐÖ¸¶¨ÈκÎЭÒ飬Ôòtcpdump ½«»á ¼àÌýËùÓÐЭÒéµÄÐÅÏ¢°ü¡£

³ýÁËÕâÈýÖÖÀàÐ͵Ĺؼü×ÖÖ®Í⣬ÆäËûÖØÒªµÄ¹Ø¼ü×ÖÈçÏ£ºgateway£¬ broadcast£¬less£¬ greater£¬ »¹ÓÐÈýÖÖÂß¼­ÔËË㣬ȡ·ÇÔËËãÊÇ ¡®not ¡® ¡®! ¡®£¬ ÓëÔËËãÊÇ¡¯and¡¯£¬¡¯&&¡¯;»òÔËËãÊÇ¡¯or¡¯ £¬¡¯||¡¯£» ÕâЩ¹Ø¼ü×Ö¿ÉÒÔ×éºÏÆðÀ´¹¹³ÉÇ¿´óµÄ×éºÏÌõ¼þÀ´Âú×ãÈËÃǵÄÐèÒª¡£

Àý£º

tcpdump -i lo -nn -A -s 0 tcp -w /home/open/1.txt port 3306 and src host 112.142.34.24 and dst host 192.168.1.33

tcpdump -X -n -s 0 tcp port 8033 -i lo
tcpdump -A -n -x -s 0 tcp port 7430 and host 192.168.3.143
tcpdump -x -n -s 0 tcp port 9024 or 9021 or 9023 or 9020

ËÄ¡¢Êä³ö½á¹û½éÉÜ

ÏÂÃæÎÒÃǽéÉܼ¸ÖÖµäÐ͵ÄtcpdumpÃüÁîµÄÊä³öÐÅÏ¢

(1) Êý¾ÝÁ´Â·²ãÍ·ÐÅÏ¢
ʹÓÃÃüÁ
#tcpdump --e host ICE
ICE ÊÇһ̨װÓÐlinuxµÄÖ÷»ú¡£ËüµÄMACµØÖ·ÊÇ0£º90£º27£º58£ºAF£º1A H219ÊÇһ̨װÓÐSolarisµÄSUN¹¤×÷Õ¾¡£ËüµÄMACµØÖ·ÊÇ8£º0£º20£º79£º5B£º46£» ÉÏÒ»ÌõÃüÁîµÄÊä³ö½á¹ûÈçÏÂËùʾ£º

21:50:12.847509 eth0 < 8:0:20:79:5b:46 0:90:27:58:af:1a ip 60: h219.33357 > ICE. telne t 0:0(0) ack 22535 win 8760 (DF)

21£º50£º12ÊÇÏÔʾµÄʱ¼ä£¬ 847509ÊÇIDºÅ£¬eth0 <±íʾ´ÓÍøÂç½Ó¿Úeth0½ÓÊո÷Ö×飬 eth0 >±íʾ´ÓÍøÂç½Ó¿ÚÉ豸·¢ËÍ·Ö×飬 8:0:20:79:5b:46ÊÇÖ÷»úH219µÄMACµØÖ·£¬ Ëü±íÃ÷ÊÇ´ÓÔ´µØÖ·H219·¢À´µÄ·Ö×é. 0:90:27:58:af:1aÊÇÖ÷»úICEµÄMACµØÖ·£¬ ±íʾ¸Ã·Ö×éµÄÄ¿µÄµØÖ·ÊÇICE¡£ ip ÊDZíÃ÷¸Ã·Ö×éÊÇIP·Ö×飬60 ÊÇ·Ö×éµÄ³¤¶È£¬ h219.33357 > ICE. telnet ±íÃ÷¸Ã·Ö×éÊÇ´ÓÖ÷»úH219µÄ33357¶Ë¿Ú·¢ÍùÖ÷»úICEµÄ TELNET(23)¶Ë¿Ú¡£ ack 22535 ±íÃ÷¶ÔÐòÁкÅÊÇ222535µÄ°ü½øÐÐÏìÓ¦¡£ win 8760±íÃ÷·¢ ËÍ´°¿ÚµÄ´óСÊÇ8760¡£

(2) ARP°üµÄtcpdumpÊä³öÐÅÏ¢

ʹÓÃÃüÁ
#tcpdump arp

µÃµ½µÄÊä³ö½á¹ûÊÇ£º

22:32:42.802509 eth0 > arp who-has route tell ICE (0:90:27:58:af:1a)
22:32:42.802902 eth0 < arp reply route is-at 0:90:27:12:10:66 (0:90:27:58:af:1a)

22:32:42ÊÇʱ¼ä´Á£¬ 802509ÊÇIDºÅ£¬ eth0 >±íÃ÷´ÓÖ÷»ú·¢³ö¸Ã·Ö×飬arp±íÃ÷ÊÇARPÇëÇó°ü£¬ who-has route tell ICE±íÃ÷ÊÇÖ÷»úICEÇëÇóÖ÷»úrouteµÄMACµØÖ·¡£ 0:90:27:58:af:1aÊÇÖ÷»ú ICEµÄMACµØÖ·¡£

(3) TCP°üµÄÊä³öÐÅÏ¢

ÓÃtcpdump²¶»ñµÄTCP°üµÄÒ»°ãÊä³öÐÅÏ¢ÊÇ£º

src > dst: flags data-seqno ack window urgent options

src > dst:±íÃ÷´ÓÔ´µØÖ·µ½Ä¿µÄµØÖ·£¬ flagsÊÇTCP±¨ÎÄÖеıêÖ¾ÐÅÏ¢£¬S ÊÇSYN±êÖ¾£¬ F (FIN)£¬ P (PUSH) £¬ R (RST) ¡°.¡± (ûÓбê¼Ç); data-seqnoÊDZ¨ÎÄÖеÄÊý¾Ý µÄ˳ÐòºÅ£¬ ackÊÇÏÂ´ÎÆÚÍûµÄ˳ÐòºÅ£¬ windowÊǽÓÊÕ»º´æµÄ´°¿Ú´óС£¬ urgent±íÃ÷ ±¨ÎÄÖÐÊÇ·ñÓнô¼±Ö¸Õë¡£ OptionsÊÇÑ¡Ïî¡£

(4) UDP°üµÄÊä³öÐÅÏ¢

ÓÃtcpdump²¶»ñµÄUDP°üµÄÒ»°ãÊä³öÐÅÏ¢ÊÇ£º

route.port1 > ICE.port2: udp lenth

UDPÊ®·Ö¼òµ¥£¬ÉÏÃæµÄÊä³öÐбíÃ÷´ÓÖ÷»úrouteµÄport1¶Ë¿Ú·¢³öµÄÒ»¸öUDP±¨ÎÄ µ½Ö÷»úICEµÄport2¶Ë¿Ú£¬ÀàÐÍÊÇUDP£¬ °üµÄ³¤¶ÈÊÇlenth¡£

Îå¡¢¾ÙÀý

(1) ÏëÒª½Ø»ñËùÓÐ210.27.48.1 µÄÖ÷»úÊÕµ½µÄºÍ·¢³öµÄËùÓеķÖ×飺
#tcpdump host 210.27.48.1

(2) ÏëÒª½Ø»ñÖ÷»ú210.27.48.1 ºÍÖ÷»ú210.27.48.2»ò210.27.48.3µÄͨÐÅ£¬Ê¹ÓÃÃüÁעÒ⣺À¨ºÅǰµÄ·´Ð±¸ÜÊDZØÐëµÄ£©£º
#tcpdump host 210.27.48.1 and (210.27.48.2 or 210.27.48.3 )

(3) Èç¹ûÏëÒª»ñÈ¡Ö÷»ú210.27.48.1³ýÁ˺ÍÖ÷»ú210.27.48.2Ö®ÍâËùÓÐÖ÷»úͨÐŵÄip°ü£¬Ê¹ÓÃÃüÁ
#tcpdump ip host 210.27.48.1 and ! 210.27.48.2

(4) Èç¹ûÏëÒª»ñÈ¡Ö÷»ú192.168.228.246½ÓÊÕ»ò·¢³öµÄssh°ü£¬²¢ÇÒ²»×ª»»Ö÷»úÃûʹÓÃÈçÏÂÃüÁ
#tcpdump -nn -n src host 192.168.228.246 and port 22 and tcp

(5) »ñÈ¡Ö÷»ú192.168.228.246½ÓÊÕ»ò·¢³öµÄssh°ü£¬²¢°ÑmacµØÖ·Ò²Ò»Í¬ÏÔʾ£º
# tcpdump -e src host 192.168.228.246 and port 22 and tcp -n -nn

(6) ¹ýÂ˵ÄÊÇÔ´Ö÷»úΪ192.168.0.1ÓëÄ¿µÄÍøÂçΪ192.168.0.0µÄ±¨Í·£º
tcpdump src host 192.168.0.1 and dst net 192.168.0.0/24

(7) ¹ýÂËÔ´Ö÷»úÎïÀíµØÖ·ÎªXXXµÄ±¨Í·£º
tcpdump ether src 00:50:04:BA:9B and dst¡­¡­
£¨ÎªÊ²Ã´ether srcºóÃæÃ»ÓÐhost»òÕßnet£¿ÎïÀíµØÖ·µ±È»²»¿ÉÄÜÓÐÍøÂ磩¡£

(8) ¹ýÂËÔ´Ö÷»ú192.168.0.1ºÍÄ¿µÄ¶Ë¿Ú²»ÊÇtelnetµÄ±¨Í·£¬²¢µ¼Èëµ½tes.t.txtÎļþÖУº
Tcpdump src host 192.168.0.1 and dst port not telnet -l > test.txt

ip icmp arp rarp ºÍ tcp¡¢udp¡¢icmpÕâЩѡÏîµÈ¶¼Òª·Åµ½µÚÒ»¸ö²ÎÊýµÄλÖã¬ÓÃÀ´¹ýÂËÊý¾Ý±¨µÄÀàÐÍ¡£

ÀýÌ⣺ÈçºÎʹÓÃtcpdump¼àÌýÀ´×Ôeth0ÊÊÅ俨ÇÒͨÐÅЭÒéΪport 22£¬Ä¿±êÀ´Ô´Îª192.168.1.100µÄÊý¾Ý°ü×ÊÁÏ£¿

´ð£ºtcpdump -i eth0 -nn port 22 and src host 192.168.1.100

ÀýÌ⣺ÈçºÎʹÓÃtcpdumpץȡ·ÃÎÊeth0ÊÊÅ俨ÇÒ·ÃÎʶ˿ÚΪtcp 9080£¿

´ð:tcpdump -i eth0 dst 172.168.70.35 and tcp port 9080

ÀýÌ⣺ÈçºÎʹÓÃtcpdumpץȡÓëÖ÷»ú192.168.43.23»ò×ÅÓëÖ÷»ú192.168.43.24ͨÐű¨ÎÄ£¬²¢ÇÒÏÔʾÔÚ¿ØÖÆÌ¨ÉÏ

tcpdump -X -s 1024 -i eth0 host (192.168.43.23 or 192.168.43.24) and host 172.16.70.35

×÷Õߣºljianhui
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ