tcpdump使用範例

範例1. 只抓IPv4的smtp包,ip[0:1]表示ip頭中的第一個字節(從0開始),長度爲1;然後右移4位的值等於0x4;-S表示顯示seq和ack序號的絕對值,而不是相對值。

tcpdump -i eth0 -S '(ip[0:1]>>4 = 0x4) and (tcp port 25)'

顯示內容如下:

16:51:27.353122 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [S], seq 1321281134, win 14600, options 
[mss 1460,sackOK,TS val 942718477 ecr 0,nop,wscale 7], length 016:51:27.353901 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [S.], seq 1935336471, ack 1321281135, wi
n 14480, options [mss 1460,sackOK,TS val 1142756484 ecr 942718477,nop,wscale 6], length 016:51:27.354329 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [.], ack 1935336472, win 115, options [n
op,nop,TS val 942718479 ecr 1142756484], length 016:51:28.580959 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [P.], seq 1935336472:1935336521, ack 132
1281135, win 227, options [nop,nop,TS val 1142757712 ecr 942718479], length 4916:51:28.581314 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [.], ack 1935336521, win 115, options [n
op,nop,TS val 942719706 ecr 1142757712], length 0



16:51:36.277983 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [P.], seq 1321281135:1321281141, ack 193
5336521, win 115, options [nop,nop,TS val 942727402 ecr 1142757712], length 616:51:36.278031 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [.], ack 1321281141, win 227, options [n
op,nop,TS val 1142765409 ecr 942727402], length 016:51:36.278383 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [P.], seq 1935336521:1935336536, ack 132
1281141, win 227, options [nop,nop,TS val 1142765409 ecr 942727402], length 1516:51:36.278451 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [F.], seq 1935336536, ack 1321281141, wi
n 227, options [nop,nop,TS val 1142765409 ecr 942727402], length 016:51:36.278893 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [.], ack 1935336536, win 115, options [n
op,nop,TS val 942727403 ecr 1142765409], length 016:51:36.278894 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [F.], seq 1321281141, ack 1935336537, wi
n 115, options [nop,nop,TS val 942727403 ecr 1142765409], length 016:51:36.278934 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [.], ack 1321281142, win 227, options [n
op,nop,TS val 1142765410 ecr 942727403], length 0

發佈了102 篇原創文章 · 獲贊 8 · 訪問量 13萬+
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章