¡¾ÍƼö¡¿TCPDUMPÖÐÎÄÊÖ²á
ת×Ô£º [url]http://www.28600.com/article8/112-7340.htm[/url]ÎÄÕÂÖкܶà¿Õ¸ñ±»ºöÂÔÁË£¬¿ÉÄÜÓ°ÏìÔĶÁ£»½¨ÒéÔĶÁ×îеÄÓ¢ÎÄ԰棺
[url]http://www.tcpdump.org/tcpdump_man.html[/url]
££££££££££££££££££££££££££££££££££££
Ãû³Æ(NAME)
tcpdump-ת´¢ÍøÂçÉϵÄÊý¾ÝÁ÷
×ÜÀÀ(SYNOPSIS)
tcpdump[-adeflnNOpqStvx][-ccount][-Ffile]
[-iinterface][-rfile][-ssnaplen]
[-Ttype][-wfile][expression]
ÃèÊö(DESCRIPTION)
Tcpdump´òÓ¡³öÔÚij¸öÍøÂç½çÃæÉÏ,Æ¥Åä²¼¶û±í´ïʽexpressionµÄ±¨Í·.
¶ÔÓÚSunOSµÄnit»òbpf½çÃæ:ÒªÔËÐÐtcpdump,Äã±ØÐëÓÐ/dev/nit»ò/dev/bpf*µÄ¶Á·ÃÎÊȨÏÞ.
¶ÔÓÚSolarisµÄdlpi:Äã±ØÐëÓÐÍøÂç·ÂÕæÉ豸(networkpseudodevice),Èç/dev/leµÄ¶Á·ÃÎÊȨÏÞ.
¶ÔÓÚHP-UXµÄdlpi:Äã±ØÐëÊÇroot,»òÕß°ÑËü°²×°³ÉrootµÄÉèÖÃuid³ÌÐò.¶ÔÓÚIRIXµÄsnoop:Äã±ØÐëÊÇroot,»òÕß°ÑËü°²×°³ÉrootµÄÉèÖÃuid³ÌÐò.¶ÔÓÚLinux:Äã±ØÐëÊÇroot,»òÕß°ÑËü°²×°³ÉrootµÄÉèÖÃuid³ÌÐò.
¶ÔÓÚUltrixºÍDigitalUNIX:Ò»µ©³¬¼¶Óû§Ê¹ÓÃpfconfig(8)¿ª·ÅÁËpromiscuous²Ù×÷ģʽ(promiscuous-mode),ÈκÎÓû§¶¼¿ÉÒÔÔËÐÐtcpdump.
¶ÔÓÚBSD:Äã±ØÐëÓÐ/dev/bpf*µÄ¶Á·ÃÎÊȨÏÞ.
Ñ¡Ïî(OPTIONS)
-a
ÊÔ×ŰÑÍøÂçºÍ¹ã²¥µØÖ·×ª»»³ÉÃû³Æ.
-c
µ±ÊÕµ½count±¨ÎĺóÍ˳ö.
-d
°Ñ±àÒëºÃµÄ±¨ÎÄÆ¥ÅäÄ£°å(packet-matchingcode)·Òë³É¿É¶ÁÐÎʽ,´«Íù±ê×¼Êä³ö,È»ºóÍ˳ö.
-dd
°Ñ±¨ÎÄÆ¥ÅäÄ£°å(packet-matchingcode)ÒÔC³ÌÐòƬ¶ÏµÄÐÎʽÊä³ö.
-ddd
°Ñ±¨ÎÄÆ¥ÅäÄ£°å(packet-matchingcode)ÒÔÊ®½øÖÆÊýÐÎʽÊä³ö(Ç°Ãæ¼ÓÉÏ×ÜÊý).
-e
ÿÐж¼ÏÔʾÁ´Â·²ã±¨Í·.
-f
ÓÃÊý×ÖÐÎʽÏÔʾ'ÍⲿµÄ'»¥ÁªÍøµØÖ·,¶ø²»ÊÇ×Ö·ûÐÎʽ(Õâ¸öÑ¡ÏîÓÃÀ´ÈÆ¿ªÄÔ¿Ç»µ¹âµÄSUN»ÆÒ³·þÎñÆ÷µÄÎÊÌâ---Ò»°ã˵À´Ëü·ÒëÍâ²¿ÍøÂçÊý×ÖµØÖ·µÄʱºò»á³¤ÆÚ¹ÒÆð).
-F
°ÑfileµÄÄÚÈÝÓÃ×÷¹ýÂ˱í´ïʽ.ºöÂÔÃüÁîÐÐÉϵıí´ïʽ.
-i
¼àÌýinterface.Èç¹û²»Ö¸¶¨½Ó¿Ú,tcpdumpÔÚϵͳµÄ½Ó¿ÚÇåµ¥ÖÐ,ѰÕÒºÅÂë×îС,ÒѾÅäÖúõĽӿÚ(loopback³ýÍâ).Ñ¡ÖеÄʱºò»áÖжÏÁ¬½Ó.
-l
Ðлº³å±ê×¼Êä³ö.¿ÉÓÃÓÚ²¶×½Êý¾ÝµÄͬʱ²é¿´Êý¾Ý.ÀýÈç,
``tcpdump-l|teedat''or``tcpdump-l>dat&tail-fdat''.
-n
±ð°ÑµØÖ·×ª»»³ÉÃû×Ö(¾ÍÊÇ˵,Ö÷»úµØÖ·,¶Ë¿ÚºÅµÈ)
-N
²»ÏÔʾÖ÷»úÃû×ÖÖеÄÓòÃû²¿·Ö.ÀýÈç,Èç¹ûʹÓÃÕâ¸öÑ¡Ïî,tcpdumpÖ»ÏÔʾ``nic'',¶ø²»ÊÇ``nic.ddn.mil''.
-O
½ûÖ¹ÔËÐб¨ÎÄÆ¥ÅäÄ£°åµÄÓÅ»¯Æ÷.Ö»Óе±Ä㻳ÒÉÓÅ»¯Æ÷ÓÐbugʱ²ÅÓÐÓÃ.
-p
½ûÖ¹°Ñ½Ó¿ÚÖóÉpromiscuousģʽ.×¢Òâ,½Ó¿ÚÓпÉÄÜÒòÆäËûÔÒò¶ø´¦ÓÚpromiscuousģʽ;Òò´Ë,'-p'²»ÄÜ×÷Ϊ`etherhost{local-hw-addr}»òetherbroadcast'µÄ¼òд.
-q
¿ìËÙÊä³ö.ÏÔʾ½ÏÉÙµÄÐÒéÐÅÏ¢,Êä³öÐлá¶ÌÒ»µãµã.
-r
´ÓfileÖжÁÈëÊý¾Ý±¨(ÎļþÊÇÓÃ-wÑ¡Ïî´´½¨µÄ).Èç¹ûfileÊÇ``-'',¾Í¶Á±ê×¼ÊäÈë.
-s
´Óÿ¸ö±¨ÎÄÖнØÈ¡snaplen×Ö½ÚµÄÊý¾Ý,¶ø²»ÊÇȱʡµÄ68(Èç¹ûÊÇSunOSµÄNIT,×îСֵÊÇ96).68¸ö×Ö½ÚÊÊÓÃÓÚIP,ICMP,TCPºÍUDP,µ«ÊÇÓпÉÄܽصôÃû×Ö·þÎñÆ÷ºÍNFS±¨ÎĵÄÐÒéÐÅÏ¢(¼ûÏÂÃæ).Êä³öʱÈç¹ûÖ¸¶¨``[|proto]'',tcpdump¿ÉÒÔÖ¸³öÄÇЩ²¶×½Á¿¹ýСµÄÊý¾Ý±¨,ÕâÀïµÄprotoÊǽضϷ¢Éú´¦µÄÐÒé²ãÃû³Æ.×¢Òâ,²ÉÓøü´óµÄ²¶×½·¶Î§¼ÈÔö¼ÓÁË´¦Àí±¨ÎĵÄʱ¼ä,ÓÖÏàÓ¦µÄ¼õÉÙÁ˱¨ÎĵĻº³åÊýÁ¿,¿ÉÄܵ¼Ö±¨ÎĵĶªÊ§.ÄãÓ¦¸Ã°ÑsnaplenÉèµÄ¾¡Á¿Ð¡,Ö»ÒªÄܹ»ÈÝÄÉÄãÐèÒªµÄÐÒéÐÅÏ¢¾Í¿ÉÒÔÁË.
-T
°Ñͨ¹ý"expression"ÌôÑ¡³öÀ´µÄ±¨ÎĽâÊͳÉÖ¸¶¨µÄtype.ĿǰÒÑÖªµÄÀàÐÍÓÐ:rpc(Ô¶³Ì¹ý³Ìµ÷ÓÃRemoteProcedureCall),rtp(ʵʱӦÓÃÐÒéReal-TimeApplicationsprotocol),rtcp(ʵʱӦÓÿØÖÆÐÒéReal-TimeApplicationscontrolprotocol),vat(¿ÉÊÓÒôƵ¹¤¾ßVisualAudioTool),ºÍwb(·Ö²¼Ê½°×°ådistributedWhiteBoard).
-S
ÏÔʾ¾ø¶ÔµÄ,¶ø²»ÊÇÏà¶ÔµÄTCPÐòÁкÅ.
-t
½ûÖ¹ÏÔʾʱ´Á±êÖ¾.
-tt
ÏÔʾδ¸ñʽ»¯µÄʱ´Á±êÖ¾.
-v
(ÉÔ΢¶àÒ»µã)·±ËöµÄÊä³ö.ÀýÈç,ÏÔʾIPÊý¾Ý±¨ÖеÄÉú´æÖÜÆÚºÍ·þÎñÀàÐÍ.
-vv
¸ü·±ËöµÄÊä³ö.ÀýÈç,ÏÔʾNFSÓ¦´ð±¨Îĵĸ½¼ÓÓò.
-w
°ÑÔʼ±¨ÎÄ´æ½øfile,¶ø²»ÊÇ·ÖÎöºÍÏÔʾ.ËüÃÇ¿ÉÒÔÒÔºóÓÃ-rÑ¡ÏîÏÔʾ.Èç¹ûfileÊÇ``-'',¾ÍдÍù±ê×¼Êä³ö.
-x
ÒÔ16½øÖÆÊýÐÎʽÏÔʾÿһ¸ö±¨ÎÄ(È¥µôÁ´Â·²ã±¨Í·ºó).¿ÉÒÔÏÔʾ½ÏСµÄÍêÕû±¨ÎÄ,·ñÔòÖ»ÏÔʾsnaplen¸ö×Ö½Ú.
expression
ÓÃÀ´Ñ¡ÔñҪת´¢µÄÊý¾Ý±¨.Èç¹ûûÓÐÖ¸¶¨expression,¾Íת´¢ÍøÂçµÄÈ«²¿±¨ÎÄ.·ñÔò,ֻת´¢Ïà¶ÔexpressionΪ`true'µÄÊý¾Ý±¨.
expressionÒ»¸ö»ò¶à¸öÔÓï(primitive)×é³É.ÔÓïͨ³£ÓÉÒ»¸ö±êʶ(id,Ãû³Æ»òÊý×Ö),ºÍ±êÊ¶Ç°ÃæµÄÒ»¸ö»ò¶à¸öÐÞÊÎ×Ó(qualifier)×é³É.ÐÞÊÎ×ÓÓÐÈýÖÖ²»Í¬µÄÀàÐÍ:
type
ÀàÐÍÐÞÊÎ×ÓÖ¸³ö±êʶÃû³Æ»ò±êʶÊý×Ö´ú±íʲôÀàÐ͵Ķ«Î÷.¿ÉÒÔʹÓõÄÀàÐÍÓÐhost,netºÍport.ÀýÈç,`hostfoo',`net128.3',`port20'.Èç¹û²»Ö¸¶¨ÀàÐÍÐÞÊÎ×Ó,¾ÍʹÓÃȱʡµÄhost.
dir
·½ÏòÐÞÊÎ×ÓÖ¸³öÏà¶ÔÓÚ±êʶµÄ´«Êä·½Ïò(Êý¾ÝÊÇ´«È뻹ÊÇ´«³ö±êʶ).¿ÉÒÔʹÓõķ½ÏòÓÐsrc,dst,srcordstºÍsrcanddst.ÀýÈç, `srcfoo',`dstnet128.3',`srcordstportftp-data'.Èç¹û²»Ö¸¶¨·½ÏòÐÞÊÎ×Ó,¾ÍʹÓÃȱʡµÄsrcordst. ¶ÔÓÚ`null'Á´Â·²ã(¾ÍÊÇ˵ÏóslipÖ®ÀàµÄµãµ½µãÐÒé),ÓÃinboundºÍoutboundÐÞÊÎ×ÓÖ¸¶¨ËùÐèµÄ´«Êä·½Ïò.
proto
ÐÒéÐÞÊÎ×ÓÒªÇóÆ¥ÅäÖ¸¶¨µÄÐÒé.¿ÉÒÔʹÓõÄÐÒéÓÐ:ether,fddi,ip,arp,rarp,decnet,lat,sca,moprc,mopdl,tcpºÍudp.ÀýÈç,`ethersrcfoo',`arpnet128.3',`tcpport21'.Èç¹û²»Ö¸¶¨ÐÒéÐÞÊÎ×Ó,¾ÍʹÓÃËùÓзûºÏÀàÐ͵ÄÐÒé.ÀýÈç,`srcfoo'Ö¸`(ip»òarp»òrarp)srcfoo'(×¢ÒâºóÕß²»·ûºÏÓï·¨),`netbar'Ö¸`(ip»òarp»òrarp)netbar',`port53'Ö¸`(tcp»òudp)port53'.
[`fddi'ʵ¼ÊÉÏÊÇ`ether'µÄ±ðÃû;·ÖÎöÆ÷°ÑËüÃÇÊÓΪ``ÓÃÔÚÖ¸¶¨ÍøÂç½Ó¿ÚÉϵÄÊý¾ÝÁ´Â·²ã.''FDDI±¨Í·°üº¬ÀàËÆÓÚÒÔÌ«ÐÒéµÄÔ´Ä¿µØÖ·,¶øÇÒͨ³£°üº¬ÀàËÆÓÚÒÔÌ«ÐÒéµÄ±¨ÎÄÀàÐÍ,Òò´ËÄã¿ÉÒÔ¹ýÂËFDDIÓò,¾ÍÏó·ÖÎöÒÔÌ«ÐÒéÒ»Ñù.FDDI±¨Í·Ò²°üº¬ÆäËûÓò,µ«ÊÇÄã²»ÄÜÔÚ¹ýÂËÆ÷±í´ïʽÀïÏÔʽÃèÊö.]
×÷ΪÉÏÊöµÄ²¹³ä,ÓÐÒ»Ð©ÌØÊâµÄ`ÔÓï'¹Ø¼ü×Ö,ËüÃDz»Í¬ÓÚÉÏÃæµÄģʽ:gateway,broadcast,less,greaterºÍÊýѧ±í´ïʽ.ÕâЩÔÚºóÃæÓÐÐðÊö.
¸ü¸´ÔӵĹýÂËÆ÷±í´ïʽ¿ÉÒÔͨ¹ýand,orºÍnotÁ¬½ÓÔÓïÀ´×齨.ÀýÈç,`hostfooandnotportftpandnotportftp- data'.ΪÁËÉÙÇõã¼ü,¿ÉÒÔºöÂÔÏàͬµÄÐÞÊÎ×Ó.ÀýÈç,`tcpdstportftporftp-dataordomain'ʵ¼ÊÉϾÍÊÇ `tcpdstportftportcpdstportftp-dataortcpdstportdomain'.
ÔÊÐíµÄÔÓïÓÐ:
dsthosthost
Èç¹û±¨ÎÄÖÐIPµÄÄ¿µÄµØÖ·ÓòÊÇhost,ÔòÂß¼ÎªÕæ.host¼È¿ÉÒÔÊǵØÖ·,Ò²¿ÉÒÔÊÇÖ÷»úÃû.
srchosthost
Èç¹û±¨ÎÄÖÐIPµÄÔ´µØÖ·ÓòÊÇhost,ÔòÂß¼ÎªÕæ.
hosthost
Èç¹û±¨ÎÄÖÐIPµÄÔ´µØÖ·Óò»òÕßÄ¿µÄµØÖ·ÓòÊÇhost,ÔòÂß¼ÎªÕæ.ÉÏÃæËùÓеÄhost±í´ïʽ¶¼¿ÉÒÔ¼ÓÉÏip,arp,»òrarp¹Ø¼ü×Ö×öǰ׺,¾ÍÏó:
iphosthost
ËüµÈ¼ÛÓÚ:
etherproto\ipandhosthost
Èç¹ûhostÊÇÓµÓжà¸öIPµØÖ·µÄÖ÷»úÃû,ËüµÄÿ¸öµØÖ·¶¼»á±»²éÑé.
etherdstehost
Èç¹û±¨ÎĵÄÒÔ̫ĿµÄµØÖ·ÊÇehost,ÔòÂß¼ÎªÕæ.Ehost¼È¿ÉÒÔÊÇÃû×Ö(/etc/ethersÀïÓÐ),Ò²¿ÉÒÔÊÇÊý×Ö(ÓйØÊý×Ö¸ñʽÁí¼ûethers(3N)).
ethersrcehost
Èç¹û±¨ÎĵÄÒÔ̫ԴµØÖ·ÊÇehost,ÔòÂß¼ÎªÕæ.
etherhostehost
Èç¹û±¨ÎĵÄÒÔ̫ԴµØÖ·»òÒÔ̫ĿµÄµØÖ·ÊÇehost,ÔòÂß¼ÎªÕæ.
gatewayhost
Èç¹û±¨ÎİÑhostµ±×öÍø¹Ø,ÔòÂß¼ÎªÕæ.Ò²¾ÍÊÇ˵,±¨ÎĵÄÒÔ̫Դ»òÄ¿µÄµØÖ·ÊÇhost,µ«ÊÇIPµÄÔ´Ä¿µØÖ·¶¼²»ÊÇhost.host±ØÐëÊǸöÖ÷»úÃû,¶øÇÒ±ØÐë´æÔÚ/etc/hostsºÍ/etc/ethersÖÐ.(Ò»¸öµÈ¼ÛµÄ±í´ïʽÊÇ
etherhostehostandnothosthost
¶ÔÓÚhost/ehost,Ëü¼È¿ÉÒÔÊÇÃû×Ö,Ò²¿ÉÒÔÊÇÊý×Ö.)
dstnetnet
Èç¹û±¨ÎĵÄIPÄ¿µÄµØÖ·ÊôÓÚÍøÂçºÅnet,ÔòÂß¼ÎªÕæ.net¼È¿ÉÒÔÊÇÃû×Ö(´æÔÚ/etc/networksÖÐ),Ò²¿ÉÒÔÊÇÍøÂçºÅ.(Ïê¼ûnetworks(4)).
srcnetnet
Èç¹û±¨ÎĵÄIPÔ´µØÖ·ÊôÓÚÍøÂçºÅnet,ÔòÂß¼ÎªÕæ.
netnet
Èç¹û±¨ÎĵÄIPÔ´µØÖ·»òÄ¿µÄµØÖ·ÊôÓÚÍøÂçºÅnet,ÔòÂß¼ÎªÕæ.
netnetmaskmask
Èç¹ûIPµØÖ·Æ¥ÅäÖ¸¶¨ÍøÂçÑÚÂë(netmask)µÄnet,ÔòÂß¼ÎªÕæ.±¾ÔÓï¿ÉÒÔÓÃsrc»òdstÐÞÊÎ.
netnet/len
Èç¹ûIPµØÖ·Æ¥ÅäÖ¸¶¨ÍøÂçÑÚÂëµÄnet,ÔòÂß¼ÎªÕæ,ÑÚÂëµÄÓÐЧλ¿íΪlen.±¾ÔÓï¿ÉÒÔÓÃsrc»òdstÐÞÊÎ.
dstportport
Èç¹û±¨ÎÄÊÇip/tcp»òip/udp,²¢ÇÒÄ¿µÄ¶Ë¿ÚÊÇport,ÔòÂß¼ÎªÕæ.portÊÇÒ»¸öÊý×Ö,Ò²¿ÉÒÔÊÇ/etc/servicesÖÐ˵Ã÷¹ýµÄÃû×Ö(²Î¿´tcp(4P)ºÍudp(4P)).Èç¹ûʹÓÃÃû×Ö,Ôò¼ì²é¶Ë¿ÚºÅºÍÐÒé.Èç¹ûʹÓÃÊý×Ö,»òÕßÓжþÒåµÄÃû×Ö,ÔòÖ»¼ì²é¶Ë¿ÚºÅ(ÀýÈç,dstport513½«ÏÔʾtcp/loginµÄÊý¾ÝºÍudp/whoµÄÊý¾Ý,¶øportdomain½«ÏÔʾtcp/domainºÍudp/domainµÄÊý¾Ý).
srcportport
Èç¹û±¨ÎĵÄÔ´¶Ë¿ÚºÅÊÇport,ÔòÂß¼ÎªÕæ.
portport
Èç¹û±¨ÎĵÄÔ´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚÊÇport,ÔòÂß¼ÎªÕæ.ÉÏÊöµÄÈÎÒâÒ»¸ö¶Ë¿Ú±í´ïʽ¶¼¿ÉÒÔÓùؼü×Ötcp»òudp×öǰ׺,¾ÍÏó:
tcpsrcportport
ËüֻƥÅäÔ´¶Ë¿ÚÊÇportµÄTCP±¨ÎÄ.
lesslength
Èç¹û±¨Îĵij¤¶ÈСÓÚµÈÓÚlength,ÔòÂß¼ÎªÕæ.ËüµÈͬÓÚ:
len<=length.
greaterlength
Èç¹û±¨Îĵij¤¶È´óÓÚµÈÓÚlength,ÔòÂß¼ÎªÕæ.ËüµÈͬÓÚ:
len>=length.
ipprotoprotocol
Èç¹û±¨ÎÄÊÇIPÊý¾Ý±¨(²Î¼ûip(4P)),ÆäÄÚÈݵÄÐÒéÀàÐÍÊÇprotocol,ÔòÂß¼ÎªÕæ.Protocol¿ÉÒÔÊÇÊý×Ö,Ò²¿ÉÒÔÊÇÏÂÁÐÃû³ÆÖеÄÒ»¸ö:icmp,igrp,udp,nd,»òtcp.×¢ÒâÕâЩ±êʶ·ûtcp,udp,ºÍicmpҲͬÑùÊǹؼü×Ö,ËùÒÔ±ØÐëÓ÷´Ð±¸Ü(\)תÒå,ÔÚC-shellÖÐÓ¦¸ÃÊÇ\\.
etherbroadcast
Èç¹û±¨ÎÄÊÇÒÔÌ«¹ã²¥±¨ÎÄ,ÔòÂß¼ÎªÕæ.¹Ø¼ü×ÖetherÊÇ¿ÉÑ¡µÄ.
ipbroadcast
Èç¹û±¨ÎÄÊÇIP¹ã²¥±¨ÎÄ,ÔòÂß¼ÎªÕæ.Tcpdump¼ì²éÈ«0ºÍÈ«1¹ã²¥Ô¼¶¨,²¢ÇÒ¼ì²é±¾µØµÄ×ÓÍøÑÚÂë.
ethermulticast
Èç¹û±¨ÎÄÊÇÒÔÌ«¶àÄ¿´«Ëͱ¨ÎÄ(multicast),ÔòÂß¼ÎªÕæ.¹Ø¼ü×ÖetherÊÇ¿ÉÑ¡µÄ.Õâʵ¼ÊÉÏÊÇ`ether[0]&1!=0'µÄ¼òд.
ipmulticast
Èç¹û±¨ÎÄÊÇIP¶àÄ¿´«Ëͱ¨ÎÄ,ÔòÂß¼ÎªÕæ.
etherprotoprotocol
Èç¹û±¨ÎÄÐÒéÊôÓÚÒÔÌ«ÀàÐ͵Äprotocol,ÔòÂß¼ÎªÕæ.Protocol¿ÉÒÔÊÇÊý×Ö,Ò²¿ÉÒÔÊÇÃû×Ö,Èçip,arp,»òrarp.×¢ÒâÕâЩ±êʶ·ûÒ²Êǹؼü×Ö,ËùÒÔ±ØÐëÓ÷´Ð±¸Ü(\)תÒå.[Èç¹ûÊÇFDDI(ÀýÈç,`fddiprotocolarp'),ÐÒé±êʶÀ´×Ô802.2Âß¼Á´Â·¿ØÖÆ(LLC)±¨Í·,Ëüͨ³£Î»ÓÚFDDI±¨Í·µÄ¶¥²ã.µ±¸ù¾ÝÐÒé±êʶ¹ýÂ˱¨ÎÄʱ,Tcpdump¼ÙÉèËùÓеÄFDDI±¨Îĺ¬ÓÐLLC±¨Í·,¶øÇÒLLC±¨Í·ÓõÄÊÇSNAP¸ñʽ.]
decnetsrchost
Èç¹ûDECNETµÄÔ´µØÖ·ÊÇhost,ÔòÂß¼ÎªÕæ,¸ÃÖ÷»úµØÖ·µÄÐÎʽ¿ÉÄÜÊÇ``10.123'',»òÕßÊÇDECNETÖ÷»úÃû.[Ö»ÓÐÅäÖóÉÔËÐÐDECNETµÄUltrixϵͳ֧³ÖDECNETÖ÷»úÃû.]
decnetdsthost
Èç¹ûDECNETµÄÄ¿µÄµØÖ·ÊÇhost,ÔòÂß¼ÎªÕæ.
decnethosthost
Èç¹ûDECNETµÄÔ´µØÖ·»òÄ¿µÄµØÖ·ÊÇhost,ÔòÂß¼ÎªÕæ.
ip,arp,rarp,decnet
ÊÇ:
etherprotop
µÄ¼òдÐÎʽ,ÆäÖÐpΪÉÏÊöÐÒéµÄÒ»ÖÖ. lat,moprc,mopdl
ÊÇ:
etherprotop
µÄ¼òдÐÎʽ,ÆäÖÐpΪÉÏÊöÐÒéµÄÒ»ÖÖ.×¢ÒâtcpdumpĿǰ²»ÖªµÀÈçºÎ·ÖÎöÕâЩÐÒé.
tcp,udp,icmp
ÊÇ:
ipprotop
µÄ¼òдÐÎʽ,ÆäÖÐpΪÉÏÊöÐÒéµÄÒ»ÖÖ.
exprrelopexpr
Èç¹ûÕâ¸ö¹ØÏª*ÉÁ?ÔòÂß¼ÎªÕæ,ÆäÖÐrelopÊÇ>,<,>=,<=,=,!=Ö®Ò»,exprÊÇÊýѧ±í´ïʽ,Óɳ£ÕûÊý(±ê×¼CÓï·¨ÐÎʽ),ÆÕͨµÄ¶þ½øÖÆÔËËã·û[+,-,*,/,&,|],Ò»¸ö³¤¶ÈÔËËã·û,ºÍÖ¸¶¨µÄ±¨ÎÄÊý¾Ý·ÃÎÊËã·û×é³É.Òª·ÃÎʱ¨ÎÄÄÚµÄÊý¾Ý,ʹÓÃÏÂÃæµÄÓï·¨:
proto[expr:size]
ProtoÊÇether,fddi,ip,arp,rarp,tcp,udp,oricmpÖ®Ò»,ͬʱҲָ³öÁËϱê²Ù×÷µÄÐÒé²ã.expr¸ø³ö×Ö½Úµ¥Î»µÄÆ«ÒÆÁ¿,¸ÃÆ«ÒÆÁ¿Ïà¶ÔÓÚÖ¸¶¨µÄÐÒé²ã.SizeÊÇ¿ÉÑ¡Ïî,Ö¸³ö¸ÐÐËȤµÄ×Ö½ÚÊý;Ëü¿ÉÒÔÊÇ1,2,4,ȱʡΪ1×Ö½Ú.Óɹؼü×Ölen¸ø³öµÄ³¤¶ÈÔËËã·ûÖ¸Ã÷±¨Îĵij¤¶È.
ÀýÈç,`ether[0]&1!=0'²¶×½ËùÓеĶàÄ¿´«Ëͱ¨ÎÄ.±í´ïʽ`ip[0]&0xf!=5'²¶×½ËùÓдø¿ÉÑ¡ÓòµÄIP±¨ÎÄ.±í´ïʽ `ip[6:2]&0x1fff=0'Ö»²¶×½Î´·ÖƬºÍÆ¬Æ«ÒÆÎª0µÄÊý¾Ý±¨.ÕâÖÖ¼ì²éÒþº¬ÔÚtcpºÍudpϱê²Ù×÷ÖÐ.ÀýÈç,tcp[0]Ò»¶¨ÊÇ TCP±¨Í·µÄµÚÒ»¸ö×Ö½Ú,¶ø²»ÊÇÆäÖÐij¸öIPƬµÄµÚÒ»¸ö×Ö½Ú.
ÔÓï¿ÉÒÔÓÃÏÂÊö·½·¨½áºÏʹÓÃ:
Ô°À¨»¡À¨ÆðÀ´µÄÔÓïºÍ²Ù×÷·û(Ô°À¨»¡ÔÚShellÖÐÓÐרÓÃ,ËùÒÔ±ØÐëתÒå).
È¡·´²Ù×÷(`!'or`not').
Á¬½á²Ù×÷(`&&'or`and').
»ò²Ù×÷(`||'or`or').
È¡·´²Ù×÷ÓÐ×î¸ßÓÅÏȼ¶.»ò²Ù×÷ºÍÁ¬½á²Ù×÷ÓÐÏàͬµÄÓÅÏȼ¶,ÔËËãʱ´Ó×óµ½ÓÒ½áºÏ.×¢ÒâÁ¬½á²Ù×÷ÐèÒªÏÔʽµÄandËã·û,¶ø²»ÊDz¢ÁзÅÖÃ.
Èç¹û¸ø³ö±êʶ·û,µ«Ã»¸ø¹Ø¼ü×Ö,ÄÇô°µÖ¸×î½üʹÓõĹؼü×Ö.ÀýÈç,
nothostvsandace
×÷Ϊ
nothostvsandhostace
µÄ¼òдÐÎʽ,²»Ó¦¸ÃºÍ
not(hostvsorace)
»ìÏý.
±í´ïʽ²ÎÊý¿ÉÒÔ×÷Ϊµ¥¸ö²ÎÊý´«¸øtcpdump,Ò²¿ÉÒÔ×÷Ϊ¸´ºÏ²ÎÊý,ºóÕ߸ü·½±ãһЩ.Ò»°ã˵À´,Èç¹û±í´ïʽ°üº¬ShellÔª×Ö·û(metacharacter),´«µÝµ¥¸öÀ¨ÆðÀ´µÄ²ÎÊýÒªÈÝÒ×һЩ.¸´ºÏ²ÎÊýÔÚ±»½âÎöǰÓÿոñÁª½ÓÒ»Æð.
ʾÀý(EXAMPLES)
ÏÔʾËùÓнø³ösundownµÄ±¨ÎÄ:
tcpdumphostsundown
ÏÔʾheliosºÍÖ÷»úhot,aceÖ®¼äµÄ±¨ÎÄ´«ËÍ:
tcpdumphostheliosand\(hotorace\)
ÏÔʾaceºÍ³ýÁËheliosÒÔÍâµÄËùÓÐÖ÷»úµÄIP±¨ÎÄ:
tcpdumpiphostaceandnothelios
ÏÔʾ±¾µØµÄÖ÷»úºÍBerkeleyµÄÖ÷»úÖ®¼äµÄÍøÂçÊý¾Ý:
tcpdumpnetucb-ether
ÏÔʾËùÓÐͨ¹ýÍø¹ØsnupµÄftp±¨ÎÄ(×¢ÒâÕâ¸ö±í´ïʽ±»µ¥ÒýºÅÀ¨Æð,·ÀÖ¹shell½âÊÍÔ°À¨»¡):
tcpdump'gatewaysnupand(portftporftp-data)'
ÏÔʾ¼È²»ÊÇÀ´×Ô±¾µØÖ÷»ú,Ò²²»ÊÇ´«Íù±¾µØÖ÷»úµÄÍøÂçÊý¾Ý(Èç¹ûÄã°ÑÍø¹ØÍ¨Íùij¸öÆäËûÍøÂç,Õâ¸ö×ö·¨½«²»»á°ÑÊý¾Ý·¢ÍùÄãµÄ±¾µØÍøÂç).
tcpdumpipandnotnetlocalnet
ÏÔʾÿ¸öTCP»á»°µÄÆðʼºÍ½áÊø±¨ÎÄ(SYNºÍFIN±¨ÎÄ),¶øÇһỰ·½ÖÐÓÐÒ»¸öÔ¶³ÌÖ÷»ú.
tcpdump'tcp[13]&3!=0andnotsrcanddstnetlocalnet'
ÏÔʾ¾¹ýÍø¹ØsnupÖдóÓÚ576×Ö½ÚµÄIPÊý¾Ý±¨:
tcpdump'gatewaysnupandip[2:2]>576'
ÏÔʾIP¹ã²¥»ò¶àÄ¿´«Ë͵ÄÊý¾Ý±¨,ÕâЩ±¨ÎIJ»ÊÇͨ¹ýÒÔÌ«ÍøµÄ¹ã²¥»ò¶àÄ¿´«ËÍÐÎʽ´«Ë͵Ä:
tcpdump'ether[0]&1=0andip[16]>=224'
ÏÔʾËùÓв»ÊÇ»ØÏìÇëÇó/Ó¦´ðµÄICMP±¨ÎÄ(Ò²¾ÍÊÇ˵,²»ÊÇping±¨ÎÄ):
tcpdump'icmp[0]!=8andicmp[0]!=0"
Êä³ö¸ñʽ(OUTPUTFORMAT)
tcpdumpµÄÊä³ö¸ñʽȡ¾öÓÚÐÒé.ÏÂÃæµÄÃèÊö¸ø³ö´ó¶àÊý¸ñʽµÄ¼òҪ˵Ã÷ºÍ·¶Àý.
Á´Â·²ã±¨Í·(LinkLevelHeaders)
Èç¹û¸ø³ö'-e'Ñ¡Ïî¾ÍÏÔʾÁ´Â·²ã±¨Í·.ÔÚÒÔÌ«ÍøÉÏ,ÏÔʾ±¨ÎĵÄÔ´Ä¿µØÖ·,ÐÒéºÍ±¨Îij¤¶È.
ÔÚFDDIÍøÂçÉÏ,'-e'Ñ¡Ïîµ¼ÖÂtcpdumpÏÔʾ³ö`Ö¡¿ØÖÆ(framecontrol)'Óò,Ô´Ä¿µØÖ·ºÍ±¨Îij¤¶È.(`Ö¡¿ØÖÆ'Óò¸ºÔð½âÊÍÆäÓàµÄ±¨ÎÄ.ÆÕͨ±¨ÎÄ(±ÈÈçËµÔØÓÐIPÊý¾Ý±¨)ÊÇ`Òì²½'±¨ÎÄ,ÓÅÏȼ¶½éÓÚ0µ½7;ÀýÈç,`async4'.ÕâЩ±»ÈÏÎªÔØÓÐ802.2Âß¼Á´Â·¿ØÖÆ(LLC)±¨ÎÄ;Èç¹ûËüÃDz»ÊÇISOÊý¾Ý±¨»òÕßËùνµÄSNAP±¨ÎÄ,¾ÍÏÔʾ³öLLC±¨Í·.
(×¢Òâ:ÒÔÏÂÃèÊöÖмÙÉèÄãÊìϤRFC-1144ÖÐ˵Ã÷µÄSLIPѹËõËã·¨.)
ÔÚSLIPÁ´Â·ÉÏ,tcpdumpÏÔʾ³ö·½Ïòָʾ(``I''Ö¸inbound,``O''Ö¸outbound),±¨ÎÄÀàÐͺÍѹËõÐÅÏ¢.Ê×ÏÈÏÔʾµÄÊDZ¨ÎÄÀàÐÍ.ÓÐÈýÖÖÀàÐÍip,utcpºÍctcp.¶ÔÓÚip±¨ÎIJ»ÔÙÏÔʾ¸ü¶àµÄÁ´Â·ÐÅÏ¢.¶ÔÓÚTCP±¨ÎÄ,ÔÚÀàÐͺóÃæÏÔʾÁ¬½Ó±êʶ.Èç¹û±¨ÎÄÊÇѹËõ¹ýµÄ,¾ÍÏÔʾ³ö±àÂëµÄ±¨Í·.ÌØÊâÇéÐÎÒÔ*S+nºÍ*SA+nµÄÐÎʽÏÔʾ,ÕâÀïµÄnÊÇ˳ÐòºÅ(»ò˳ÐòºÅ¼°ÆäÈ·ÈÏ)·¢ÉúµÄ¸Ä±ä×ܺÍ.Èç¹û²»ÊÇÌØÊâÇéÐÎ,¾ÍÏÔʾ0»ò¶àÉÙ¸ö¸Ä±ä.¸Ä±äÓÉU(urgentpointer),W(window),A(ack),S(sequencenumber)ºÍI(packetID)Ö¸Ã÷,ºó¸úÒ»¸ö±ä»¯Á¿(+nor-n),»òÁíÒ»¸öÖµ(=n).×îºóÏÔʾ±¨ÎÄÖеÄÊý¾Ý×ܺÍ,ÒÔ¼°Ñ¹Ëõ±¨Í·µÄ³¤¶È.
ÀýÈç,ÏÂÃæÒ»ÐÐÏÔʾÁËÒ»¸ö´«³öµÄѹËõµÄTCP±¨ÎÄ,ÓÐÒ»¸öÒþº¬µÄÁ¬½Ó±êʶ;È·ÈÏ(ack)µÄ±ä»¯Á¿ÊÇ6,˳ÐòºÅÊÇ49,±¨ÎÄIDÊÇ6;ÓÐÈý¸ö×Ö½ÚµÄÊý¾ÝºÍÁù¸ö×Ö½ÚµÄѹËõ±¨Í·:
Octcp*A+6S+49I+63(6)
ARP/RARP±¨ÎÄ
Arp/rarp±¨ÎĵÄÊä³öÏÔʾÇëÇóÀàÐͼ°Æä²ÎÊý.Êä³ö¸ñʽÇãÏòÓÚÄܹ»×ÔÎÒ½âÊÍ.ÕâÀïÊÇÒ»¸ö¼òµ¥µÄÀý×Ó,À´×ÔÖ÷»úrtsgµ½Ö÷»úcsamµÄ'rlogin'¿ªÊ¼²¿·Ö:
arpwho-hascsamtellrtsg
arpreplycsamis-atCSAM
µÚÒ»ÐÐ˵Ã÷rtsg·¢³öÒ»¸öarp±¨ÎÄѯÎÊinternetÖ÷»úcsamµÄÒÔÌ«ÍøµØÖ·.CsamÓÃËüµÄÒÔÌ«µØÖ·×÷Ó¦´ð(Õâ¸öÀý×ÓÖÐ,ÒÔÌ«µØÖ·ÊÇ´óдµÄ,internetµØÖ·ÎªÐ¡Ð´).
Èç¹ûÓÃtcpdump-n¿´ÉÏÈ¥ÒªÇå³þһЩ:
arpwho-has128.3.254.6tell128.3.254.68
arpreply128.3.254.6is-at02:07:01:00:01:c4
Èç¹ûÓÃtcpdump-e,¿ÉÒÔ¿´µ½Êµ¼ÊÉϵÚÒ»¸ö±¨ÎÄÊǹ㲥,µÚ¶þ¸ö±¨ÎÄÊǵ㵽µãµÄ:
RTSGBroadcast080664:arpwho-hascsamtellrtsg
CSAMRTSG080664:arpreplycsamis-atCSAM
ÕâÀïµÚÒ»¸ö±¨ÎÄÖ¸³öÒÔÌ«ÍøÔ´µØÖ·ÊÇRTSG,Ä¿µÄµØÖ·ÊÇÒÔÌ«Íø¹ã²¥µØÖ·,ÀàÐÍÓòΪ16½øÖÆÊý0806(ÀàÐÍETHER_ARP),±¨ÎÄÈ«³¤64×Ö½Ú.
TCP±¨ÎÄ
(×¢Òâ:ÒÔϵÄÃèÊöÖмÙÉèÄãÊìϤRFC-793ÖÐ˵Ã÷µÄTCPÐÒé,Èç¹ûÄã²»Á˽âÕâ¸öÐÒé,ÎÞÂÛÊDZ¾ÎÄ»¹ÊÇtcpdump¶¼¶ÔÄãÓô¦²»´ó)
Ò»°ã˵À´tcpÐÒéµÄÊä³ö¸ñʽÊÇ:
src>dst:flagsdata-seqnoackwindowurgentoptions
SrcºÍdstÊÇÔ´Ä¿IPµØÖ·ºÍ¶Ë¿Ú.FlagsÊÇS(SYN),F(FIN),P(PUSH)»òR(RST)»òµ¥¶ÀµÄ`.'(ÎÞ±êÖ¾),»òÕßÊÇËüÃǵÄ×éºÏ.Data-seqno˵Ã÷Á˱¾±¨ÎÄÖеÄÊý¾ÝÔÚÁ÷ÐòºÅÖеÄλÖÃ(¼ûÏÂÀý).AckÊÇÔÚÕâÌõÁ¬½ÓÉÏÐÅÔ´»úÏ£ÍûÏÂÒ»¸ö½ÓÊÕµÄ×Ö½ÚµÄÁ÷ÐòºÅ (sequencenumber).WindowÊÇÔÚÕâÌõÁ¬½ÓÉÏÐÅÔ´»ú½ÓÊÕ»º³åÇøµÄ×Ö½Ú´óС.Urg±íÃ÷±¨ÎÄÄÚÊÇ`½ô¼±(urgent)'Êý¾Ý. OptionsÊÇtcp¿ÉÑ¡±¨Í·,ÓüâÀ¨ºÅÀ¨Æð(ÀýÈç,).
Src,dstºÍflags¿Ï¶¨´æÔÚ.ÆäËûÓòÒÀ¾Ý±¨ÎĵÄtcp±¨Í·ÄÚÈÝ,Ö»Êä³öÓбØÒªµÄ²¿·Ö.
ÏÂÃæÊÇ´ÓÖ÷»úrtsgrloginµ½Ö÷»úcsamµÄ¿ªÊ¼²¿·Ö.
rtsg.1023>csam.login:S768512:768512(0)win4096
csam.login>rtsg.1023:S947648:947648(0)ack768513win4096
rtsg.1023>csam.login:.ack1win4096
rtsg.1023>csam.login:P1:2(1)ack1win4096
csam.login>rtsg.1023:.ack2win4096
rtsg.1023>csam.login:P2:21(19)ack1win4096
csam.login>rtsg.1023:P1:2(1)ack21win4077
csam.login>rtsg.1023:P2:3(1)ack21win4077urg1
csam.login>rtsg.1023:P3:4(1)ack21win4077urg1
µÚÒ»ÐÐÊÇ˵´ÓrtsgµÄtcp¶Ë¿Ú1023ÏòcsamµÄlogin¶Ë¿Ú·¢Ëͱ¨ÎÄ.S±êÖ¾±íÃ÷ÉèÖÃÁËSYN±êÖ¾.±¨ÎĵÄÁ÷ÐòºÅÊÇ768512,ûÓÐÊý¾Ý. (Õâ¸öд³É`first:last(nbytes)',Òâ˼ÊÇ`´ÓÁ÷ÐòºÅfirstµ½last,²»°üÀ¨last,ÓÐnbytes×Ö½ÚµÄÓû§Êý¾Ý'.)´ËʱûÓÐÉÓ´øÈ·ÈÏ(piggy-backedack),ÓÐЧµÄ½ÓÊÕ´°¿ÚÊÇ4096×Ö½Ú,ÓÐÒ»¸ö×î´ó¶Î´óС(max-segment-size)µÄÑ¡Ïî,ÇëÇóÉèÖÃmssΪ1024×Ö½Ú.
CsamÓÃÀàËÆµÄÐÎʽӦ´ð,Ö»ÊÇÔö¼ÓÁËÒ»¸ö¶ÔrtsgSYNµÄÉÓ´øÈ·ÈÏ.È»ºóRtsgÈ·ÈÏcsamµÄSYN.`.'Òâζ×ÅûÓÐÉèÖñêÖ¾.Õâ¸ö±¨ÎIJ»°üº¬Êý¾Ý,Òò´ËÒ²¾ÍûÓÐÊý¾ÝµÄÁ÷ÐòºÅ.×¢ÒâÕâ¸öÈ·ÈÏÁ÷ÐòºÅÊÇÒ»¸öСÕûÊý(1).µ±tcpdumpµÚÒ»´Î·¢ÏÖÒ»¸ötcp»á»°Ê±,ËüÏÔʾ±¨ÎÄЯ´øµÄÁ÷ÐòºÅ.ÔÚËæºóÊÕµ½µÄ±¨ÎÄÀï,ËüÏÔʾµ±Ç°±¨ÎĺÍ×î³õÄǸö±¨ÎĵÄÁ÷ÐòºÅÖ®²î.ÕâÒâζ×Å´ÓµÚÒ»¸ö±¨ÎÄ¿ªÊ¼,ÒÔºóµÄÁ÷ÐòºÅ¿ÉÒÔÀí½â³ÉÊý¾ÝÁ÷ÖеÄÏà¶ÔÎ»ÒÆ asrelativebytepositionsintheconversation'sdatastream(withthefirstdatabyteeachdirectionbeing`1'). `-S'Ñ¡ÏîÄܹ»¸Ä±äÕâ¸öÌØÐÔ,Ö±½ÓÏÔʾÔʼµÄÁ÷ÐòºÅ.
ÔÚµÚÁùÐÐ,rtsg´«¸øcsam19¸ö×Ö½ÚµÄÊý¾Ý(×Ö½Ú2µ½20).±¨ÎÄÖÐÉèÖÃÁËPUSH±êÖ¾.µÚÆßÐÐcsam±íÃ÷ËüÊÕµ½ÁËrtsgµÄÊý¾Ý,×Ö½ÚÐòºÅÊÇ 21,µ«²»°üÀ¨µÚ21¸ö×Ö½Ú.ÏÔÈ»´ó¶àÊýÊý¾ÝÔÚsocketµÄ»º³åÇøÄÚ,ÒòΪcsamµÄ½ÓÊÕ´°¿ÚÊÕµ½µÄÊý¾ÝСÓÚ19¸ö×Ö½Ú.ͬʱcsamÏòrtsg·¢ËÍÁËÒ»¸ö×Ö½ÚµÄÊý¾Ý.µÚ°ËºÍµÚ¾ÅÐÐÏÔʾcsam·¢ËÍÁËÁ½¸ö×ֽڵĽô¼±Êý¾Ýµ½rtsg.
Èç¹û²¶×½ÇøÉèÖõĹýС,ÒÔÖÁÓÚtcpdump²»Äܲ¶×½µ½ÍêÕûµÄTCP±¨Í·,tcpdump»á¾¡¿ÉÄܵķÒëÒѲ¶»ñµÄ²¿·Ö,È»ºóÏÔʾ``[|tcp]'',±íÃ÷ÎÞ·¨·ÒëÆäÓಿ·Ö.Èç¹û±¨Í·°üº¬Ò»¸öαÔìµÄÑ¡Ïî (onewithalengththat'seithertoosmallorbeyondtheendoftheheader),tcpdumpÏÔʾ ``[badopt]''²¢ÇÒ²»ÔÙ·ÒëÆäËûÑ¡Ï·Ö(ÒòΪËü²»¿ÉÄÜÅжϳö´ÓÄĶù¿ªÊ¼).Èç¹û±¨Í·³¤¶È±íÃ÷´æÔÚÑ¡Ïî,µ«ÊÇIPÊý¾Ý±¨³¤¶È²»¹»,²»¿ÉÄÜÕæµÄ±£´æÑ¡Ïî,tcpdump¾ÍÏÔʾ``[badhdrlength]''.
UDP±¨ÎÄ
UDP¸ñʽ¾ÍÏóÕâ¸örwho±¨ÎÄÏÔʾµÄ:
actinide.who>broadcast.who:udp84
¾ÍÊÇ˵°ÑÒ»¸öudpÊý¾Ý±¨´ÓÖ÷»úactinideµÄwho¶Ë¿Ú·¢Ë͵½broadcast,Internet¹ã²¥µØÖ·µÄwho¶Ë¿Ú.±¨Îİüº¬84×Ö½ÚµÄÓû§Êý¾Ý.
ijЩUDP·þÎñÄܹ»Ê¶±ð³öÀ´(´ÓÔ´Ä¿¶Ë¿ÚºÅÉÏ),Òò¶øÏÔʾ³ö¸ü¸ß²ãµÄÐÒéÐÅÏ¢.ÌØ±ðÊÇÓòÃû·þÎñÇëÇó(RFC-1034/1035)ºÍNFSµÄRPCµ÷ÓÃ(RFC-1050).
UDPÓòÃû·þÎñÇëÇó(NameServerRequests)
(×¢Òâ:ÒÔϵÄÃèÊöÖмÙÉèÄãÊìϤRFC-1035˵Ã÷µÄÓòÃû·þÎñÐÒé.Èç¹ûÄã²»ÊìϤÕâ¸öÐÒé,ÏÂÃæµÄÄÚÈݾÍÏóÊÇÌìÊé.)
ÓòÃû·þÎñÇëÇóµÄ¸ñʽÊÇ
src>dst:idop?flagsqtypeqclassname(len)
h2opolo.1538>helios.domain:3+A?ucbvax.berkeley.edu.(37)
Ö÷»úh2opolo·ÃÎÊheliosÉϵÄÓòÃû·þÎñ,ѯÎʺÍucbvax.berkeley.edu.¹ØÁªµÄµØÖ·¼Ç¼(qtype=A).²éѯºÅÊÇ `3'.`+'±íÃ÷ÉèÖÃÁ˵ݹéÇëÇó±êÖ¾.²éѯ³¤¶ÈÊÇ37×Ö½Ú,²»°üÀ¨UDPºÍIPÍ·.²éѯ²Ù×÷ÊÇÆÕͨµÄQuery²Ù×÷,Òò´ËopÓò¿ÉÒÔºöÂÔ.Èç¹ûopÉèÖÃ³ÉÆäËûʲô¶«Î÷,ËüÓ¦¸ÃÏÔʾÔÚ`3'ºÍ`+'Ö®¼ä.ÀàËÆµÄ,qclassÊÇÆÕͨµÄC_INÀàÐÍ,Ò²±»ºöÂÔÁË.ÆäËûÀàÐ͵ÄqclassÓ¦¸ÃÔÚ`A'ºóÃæÏÔʾ.
Tcpdump»á¼ì²éһЩ²»¹æÔòÇé¿ö,ÏàÓ¦µÄ½á¹û×÷Ϊ²¹³äÓò·ÅÔÚ·½À¨ºÅÄÚ:Èç¹ûij¸ö²éѯ°üº¬»Ø´ð,Ãû×Ö·þÎñ»ò¹ÜÀí»ú¹¹²¿·Ö,¾Í°Ñancount, nscount,»òarcountÏÔʾ³É`[na]',`[nn]'»ò`[nau]',ÕâÀïµÄn´ú±íÏàÓ¦µÄÊýÁ¿.Èç¹ûÔÚµÚ¶þºÍµÚÈý×Ö½ÚÖÐ,ÈκÎÒ»¸ö»Ø´ðλ (AA,RA»òrcode)»òÈκÎÒ»¸ö`±ØÐëΪÁã'µÄλ±»ÖÃλ,¾ÍÏÔʾ`[b2&3=x]',ÕâÀïµÄxÊDZ¨Í·µÚ¶þºÍµÚÈý×Ö½ÚµÄ16½øÖÆÊý.
UDPÃû×Ö·þÎñ»Ø´ð
Ãû×Ö·þÎñ»Ø´ðµÄ¸ñʽÊÇ
src>dst:idoprcodeflagsa/n/autypeclassdata(len)
helios.domain>h2opolo.1538:33/3/7A128.32.137.3(273)
helios.domain>h2opolo.1537:2NXDomain*0/1/0(97)
µÚÒ»¸öÀý×ÓÀï,helios»Ø´ðÁËh2opolo·¢³öµÄ±êʶΪ3µÄѯÎÊ,Ò»¹²ÊÇ3¸ö»Ø´ð¼Ç¼,3¸öÃû×Ö·þÎñ¼Ç¼ºÍ7¸ö¹ÜÀí½á¹¹¼Ç¼.µÚÒ»¸ö»Ø´ð¼Í¼µÄÀàÐÍÊÇA(µØÖ·),Êý¾ÝÊÇinternetµØÖ·128.32.137.3.»Ø´ðµÄÈ«³¤Îª273×Ö½Ú,²»°üÀ¨UDPºÍIP±¨Í·.×÷ΪA¼Ç¼µÄclass (C_IN)¿ÉÒÔºöÂÔop(ѯÎÊ)ºÍrcode(NoError).
ÔÚµÚ¶þ¸öÀý×ÓÀï,helios¶Ô±êʶΪ2µÄѯÎÊ×÷³öÓòÃû²»´æÔÚ(NXDomain)µÄ»Ø´ð,ûÓлشð¼Ç¼,Ò»¸öÃû×Ö·þÎñ¼Ç¼,¶øÇÒûÓйÜÀí½á¹¹.
`*'±íÃ÷ÉèÖÃÁËȨÍþ»Ø´ð(authoritativeanswer).ÓÉÓÚûÓлشð¼Ç¼,ÕâÀï¾Í²»ÏÔʾtype,classºÍdata.
ÆäËû±êÖ¾×Ö·û¿ÉÒÔÏÔʾΪ`-'(ûÓÐÉèÖõݹéÓÐЧ(RA))ºÍ`|'(ÉèÖÃÏûÏ¢½Ø¶Ì(TC)).Èç¹û`ÎÊÌâ'²¿·ÖûÓÐÓÐЧµÄÄÚÈÝ,¾ÍÏÔʾ`[nq]'.
×¢ÒâÃû×Ö·þÎñµÄѯÎʺͻشðÒ»°ã˵À´±È½Ï´ó,68×Ö½ÚµÄsnaplen¿ÉÄÜÎÞ·¨²¶×½µ½×ã¹»µÄ±¨ÎÄÄÚÈÝ.Èç¹ûÄãµÄÈ·ÔÚÑо¿Ãû×Ö·þÎñµÄÇé¿ö,¿ÉÒÔʹÓÃ-sÑ¡ÏîÔö´ó²¶×½»º³åÇø.`-s128'Ó¦¸ÃЧ¹û²»´íÁË.
NFSÇëÇóºÍÏìÓ¦
SunNFS(ÍøÂçÎļþϵͳ)µÄÇëÇóºÍÏìÓ¦ÏÔʾ¸ñʽÊÇ:
src.xid>dst.nfs:lenopargs
src.nfs>dst.xid:replystatlenopresults
sushi.6709>wrl.nfs:112readlinkfh21,24/10.73165
wrl.nfs>sushi.6709:replyok40readlink"../var"
sushi.201b>wrl.nfs:
144lookupfh9,74/4096.6878"xcolors"
wrl.nfs>sushi.201b:
replyok128lookupfh9,74/4134.3150
ÔÚµÚÒ»ÐÐ,Ö÷»úsushiÏòwrl·¢ËͺÅÂëΪ6709µÄ½»Ò׻Ự(×¢ÒâÔ´Ö÷»úºóÃæµÄÊý×ÖÊǽ»Ò׺Å,²»ÊǶ˿Ú).ÕâÏîÇëÇó³¤112×Ö½Ú,²»°üÀ¨UDPºÍIP ±¨Í·.ÔÚÎļþ¾ä±ú(fh)21,24/10.731657119ÉÏÖ´ÐÐreadlink(¶ÁÈ¡·ûºÅÁ¬½Ó)²Ù×÷.(Èç¹ûÔËÆø²»´í,¾ÍÏóÕâÖÖÇé¿ö,Îļþ¾ä±ú¿ÉÒÔÒÀ´Î·Òë³ÉÖ÷´ÎÉ豸ºÅ,i½ÚµãºÅ,ºÍʼþºÅ(generationnumber).)Wrl»Ø´ð`ok'ºÍÁ¬½ÓµÄÄÚÈÝ.
ÔÚµÚÈýÐÐ,sushiÇëÇówrlÔÚĿ¼Îļþ9,74/4096.6878ÖвéÕÒ`xcolors'.×¢ÒâÊý¾ÝµÄ´òÓ¡¸ñʽȡ¾öÓÚ²Ù×÷ÀàÐÍ.¸ñʽӦ¸ÃÊÇ¿ÉÒÔ×ÔÎÒ˵Ã÷µÄ.
¸ø³ö-v(verbose)Ñ¡Ïî¿ÉÒÔÏÔʾ¸½¼ÓÐÅÏ¢.ÀýÈç:
sushi.1372a>wrl.nfs:
148readfh21,11/12.1958192bytes@24576
wrl.nfs>sushi.1372a:
replyok1472readREG100664ids417/0sz29388
(-vͬʱʹËüÏÔʾIP±¨Í·µÄTTL,ID,ºÍ·ÖƬÓò,ÔÚÕâ¸öÀý×ÓÀï°ÑËüÃÇÊ¡ÂÔÁË.)ÔÚµÚÒ»ÐÐ,sushiÇëÇówrl´ÓÎļþ21,11/12.195µÄÆ«ÒÆÎ»ÖÃ24576¿ªÊ¼,¶ÁÈ¡8192×Ö½Ú.Wrl»Ø´ð`ok';µÚ¶þÐÐÏÔʾµÄ±¨ÎÄÊÇÓ¦´ðµÄµÚÒ»¸ö·ÖƬ,Òò´ËÖ»ÓÐ1472×Ö½Ú(ÆäÓàÊý¾ÝÔÚºóÐøµÄ·ÖƬÖд«¹ýÀ´,µ«ÓÉÓÚÕâЩ·ÖƬÀïûÓÐNFSÉõÖÁUDP±¨Í·,Òò´Ë¸ù¾ÝËùʹÓõĹýÂËÆ÷±í´ïʽ,ÓпÉÄܲ»ÏÔʾ).-vÑ¡Ï»áÏÔʾһЩÎļþÊôÐÔ(ËüÃÇ×÷ΪÎļþÊý¾ÝµÄ¸½´ø²¿·Ö´«»ØÀ´):ÎļþÀàÐÍ(ÆÕͨÎļþ``REG''),´æÈ¡Ä£Ê½(°Ë½øÖÆÊý),uidºÍgid,ÒÔ¼°Îļþ´óС.
Èç¹ûÔÙ¸øÒ»¸ö-vÑ¡Ïî(-vv),»¹ÄÜÏÔʾ¸ü¶àµÄϸ½Ú.
×¢ÒâNFSÇëÇóµÄÊý¾ÝÁ¿·Ç³£´ó,³ý·ÇÔö¼Ósnaplen,·ñÔòºÜ¶àϸ½ÚÎÞ·¨ÏÔʾ.ÊÔÒ»ÊÔ`-s192'Ñ¡Ïî.
NFSÓ¦´ð±¨ÎÄûÓÐÃ÷È·±êÃ÷RPC²Ù×÷.Òò´Ëtcpdump±£ÁôÓÐ``½üÀ´µÄ''ÇëÇó¼Ç¼,¸ù¾Ý½»Ò×ºÅÆ¥ÅäÓ¦´ð±¨ÎÄ.Èç¹ûÓ¦´ð±¨ÎÄûÓÐÏàÓ¦µÄÇëÇó±¨ÎÄ,Ëü¾ÍÎÞ·¨·ÖÎö.
KIPAppletalk(UDPÉϵÄDDP)
AppletalkDDP±¨ÎÄ·â×°ÔÚUDPÊý¾Ý±¨ÖÐ,½â°üºó°´DDP±¨ÎÄת´¢(Ò²¾ÍÊÇ˵,ºöÂÔËùÓеÄUDP±¨Í·ÐÅÏ¢).Îļþ/etc/atalk.namesÓÃÀ´°ÑappletalkÍøÂçºÍ½ÚµãºÅ·Òë³ÉÃû×Ö.Õâ¸öÎļþµÄÐиñʽÊÇ
numbername
1.254ether
16.1icsd-net
1.254.110ace
ǰÁ½Ðиø³öÁËappletalkµÄÍøÂçÃû³Æ.µÚÈýÐиø³öij¸öÖ÷»úµÄÃû×Ö(Ö÷»úºÍÍøÂçÒÀ¾ÝµÚÈý×éÊý×ÖÇø·Ö-ÍøÂçºÅÒ»¶¨ÊÇÁ½×éÊý×Ö,Ö÷»úºÅÒ»¶¨ÊÇÈý×éÊý×Ö.) ºÅÂëºÍÃû×ÖÓÿհ׷û(¿Õ¸ñ»òtab)¸ô¿ª./etc/atalk.namesÎļþ¿ÉÒÔ°üº¬¿ÕÐлò×¢ÊÍÐÐ(ÒÔ`#'¿ªÊ¼µÄÐÐ).
AppletalkµØÖ·°´Õâ¸ö¸ñʽÏÔʾ
net.host.port
144.1.209.2>icsd-net.112.220
office.2>icsd-net.112.220
jssmag.149.235>icsd-net.2
(Èç¹û²»´æÔÚ/etc/atalk.names,»òÕßÀïÃæÈ±ÉÙÓÐЧÏîÄ¿,¾ÍÒÔÊý×ÖÐÎʽÏÔʾµØÖ·.)µÚÒ»¸öÀý×ÓÀï,ÍøÂç144.1µÄ209½ÚµãµÄNBP (DDP¶Ë¿Ú2)ÏòÍøÂçicsdµÄ112½ÚµãµÄ220¶Ë¿Ú·¢ËÍÊý¾Ý.µÚ¶þÐкÍÉÏÃæÒ»Ñù,Ö»ÊÇÖªµÀÁËÔ´½ÚµãµÄÈ«³Æ(`office').µÚÈýÐÐÊÇ´ÓÍøÂç jssmagµÄ149½ÚµãµÄ235¶Ë¿ÚÏòicsd-netµÄNBP¶Ë¿Ú¹ã²¥(×¢Òâ¹ã²¥µØÖ·(255)Òþº¬ÔÚÎÞÖ÷»úºÅµÄÍøÂçÃû×ÖÖÐ-ËùÒÔÔÚ /etc/atalk.namesÖÐÇø·Ö½ÚµãÃûºÍÍøÂçÃûÊǸöºÃÖ÷Òâ).
Tcpdump¿ÉÒÔ·ÒëNBP(Ãû×ÖÁª½áÐÒé)ºÍATP(Appletalk½»»¥ÐÒé)µÄ±¨ÎÄÄÚÈÝ.ÆäËûÐÒéֻת´¢ÐÒéÃû³Æ(»òºÅÂë,Èç¹û»¹Ã»¸øÕâ¸öÐÒé×¢²áÃû³Æ)ºÍ±¨ÎÄ´óС.
NBP±¨ÎĵÄÊä³ö¸ñʽ¾ÍÏóÏÂÃæµÄÀý×Ó:
icsd-net.112.220>jssmag.2:nbp-lkup190:"=:LaserWriter@*"
jssmag.209.2>icsd-net.112.220:nbp-reply190:"RM1140:LaserWriter@*"250
techpit.2>icsd-net.112.220:nbp-reply190:"techpit:LaserWriter@*"186
µÚÒ»ÐÐÊÇÍøÂçicsdµÄ112Ö÷»úÔÚÍøÂçjssmagÉϵĹ㲥,¶ÔÃû×Ölaserwriter×öÃû×Ö²éѯÇëÇó.Ãû×Ö²éѯÇëÇóµÄnbp±êʶºÅÊÇ190.µÚ¶þÐÐÏÔʾµÄÊǶÔÕâ¸öÇëÇóµÄ»Ø´ð(×¢ÒâËüÃÇÓÐͬÑùµÄ±êʶºÅ),Ö÷»újssmag.209±íʾÔÚËüµÄ250¶Ë¿Ú×¢²áÁËÒ»¸ölaserwriterµÄ×ÊÔ´,Ãû×ÖÊÇ "RM1140".µÚÈýÐÐÊÇÕâ¸öÇëÇóµÄÆäËû»Ø´ð,Ö÷»útechpitµÄ186¶Ë¿ÚÓÐlaserwriter×¢²áµÄ"techpit".
ATP±¨ÎĸñʽÈçÏÂÀýËùʾ:
jssmag.209.165>helios.132:atp-req12266<0-7>0xae030001
helios.132>jssmag.209.165:atp-resp12266:0(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:1(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:2(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:3(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:4(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:5(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:6(512)0xae040000
helios.132>jssmag.209.165:atp-resp*12266:7(512)0xae040000
jssmag.209.165>helios.132:atp-req12266<3,5>0xae030001
helios.132>jssmag.209.165:atp-resp12266:3(512)0xae040000
helios.132>jssmag.209.165:atp-resp12266:5(512)0xae040000
jssmag.209.165>helios.132:atp-rel12266<0-7>0xae030001
jssmag.209.133>helios.132:atp-req*12267<0-7>0xae030002
Jssmag.209ÏòÖ÷»úhelios·¢Æð12266ºÅ½»Ò×,ÇëÇó8¸ö±¨ÎÄ(`<0-7>').ÐÐβµÄÊ®Áù½øÖÆÊýÊÇÇëÇóÖÐ`userdata'ÓòµÄÖµ.
Ò³:
[1]