LinuxÒÁµéÔ°ÂÛ̳'s Archiver

Roc.Ken ·¢±íÓÚ 2005-11-2 21:24

¡¾ÍƼö¡¿TCPDUMPÖÐÎÄÊÖ²á

ת×Ô£º [url]http://www.28600.com/article8/112-7340.htm[/url]
ÎÄÕÂÖкܶà¿Õ¸ñ±»ºöÂÔÁË£¬¿ÉÄÜÓ°ÏìÔĶÁ£»½¨ÒéÔĶÁ×îеÄÓ¢ÎÄÔ­°æ£º
[url]http://www.tcpdump.org/tcpdump_man.html[/url]
£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­£­

  Ãû³Æ(NAME)

  tcpdump-ת´¢ÍøÂçÉϵÄÊý¾ÝÁ÷

  ×ÜÀÀ(SYNOPSIS)

  tcpdump[-adeflnNOpqStvx][-ccount][-Ffile]

  [-iinterface][-rfile][-ssnaplen]

  [-Ttype][-wfile][expression]

  ÃèÊö(DESCRIPTION)

  Tcpdump´òÓ¡³öÔÚij¸öÍøÂç½çÃæÉÏ,Æ¥Åä²¼¶û±í´ïʽexpressionµÄ±¨Í·.

  ¶ÔÓÚSunOSµÄnit»òbpf½çÃæ:ÒªÔËÐÐtcpdump,Äã±ØÐëÓÐ/dev/nit»ò/dev/bpf*µÄ¶Á·ÃÎÊȨÏÞ.

  ¶ÔÓÚSolarisµÄdlpi:Äã±ØÐëÓÐÍøÂç·ÂÕæÉ豸(networkpseudodevice),Èç/dev/leµÄ¶Á·ÃÎÊȨÏÞ.

  ¶ÔÓÚHP-UXµÄdlpi:Äã±ØÐëÊÇroot,»òÕß°ÑËü°²×°³ÉrootµÄÉèÖÃuid³ÌÐò.¶ÔÓÚIRIXµÄsnoop:Äã±ØÐëÊÇroot,»òÕß°ÑËü°²×°³ÉrootµÄÉèÖÃuid³ÌÐò.¶ÔÓÚLinux:Äã±ØÐëÊÇroot,»òÕß°ÑËü°²×°³ÉrootµÄÉèÖÃuid³ÌÐò.

  ¶ÔÓÚUltrixºÍDigitalUNIX:Ò»µ©³¬¼¶Óû§Ê¹ÓÃpfconfig(8)¿ª·ÅÁËpromiscuous²Ù×÷ģʽ(promiscuous-mode),ÈκÎÓû§¶¼¿ÉÒÔÔËÐÐtcpdump.

  ¶ÔÓÚBSD:Äã±ØÐëÓÐ/dev/bpf*µÄ¶Á·ÃÎÊȨÏÞ.

  Ñ¡Ïî(OPTIONS)

  -a

  ÊÔ×ŰÑÍøÂçºÍ¹ã²¥µØÖ·×ª»»³ÉÃû³Æ.

  -c

  µ±ÊÕµ½count±¨ÎĺóÍ˳ö.

  -d

  °Ñ±àÒëºÃµÄ±¨ÎÄÆ¥ÅäÄ£°å(packet-matchingcode)·­Òë³É¿É¶ÁÐÎʽ,´«Íù±ê×¼Êä³ö,È»ºóÍ˳ö.

  -dd

  °Ñ±¨ÎÄÆ¥ÅäÄ£°å(packet-matchingcode)ÒÔC³ÌÐòƬ¶ÏµÄÐÎʽÊä³ö.

  -ddd

  °Ñ±¨ÎÄÆ¥ÅäÄ£°å(packet-matchingcode)ÒÔÊ®½øÖÆÊýÐÎʽÊä³ö(Ç°Ãæ¼ÓÉÏ×ÜÊý).

  -e

  Ã¿Ðж¼ÏÔʾÁ´Â·²ã±¨Í·.

  -f

  ÓÃÊý×ÖÐÎʽÏÔʾ'ÍⲿµÄ'»¥ÁªÍøµØÖ·,¶ø²»ÊÇ×Ö·ûÐÎʽ(Õâ¸öÑ¡ÏîÓÃÀ´ÈÆ¿ªÄÔ¿Ç»µ¹âµÄSUN»ÆÒ³·þÎñÆ÷µÄÎÊÌâ---Ò»°ã˵À´Ëü·­ÒëÍâ²¿ÍøÂçÊý×ÖµØÖ·µÄʱºò»á³¤ÆÚ¹ÒÆð).

  -F

  °ÑfileµÄÄÚÈÝÓÃ×÷¹ýÂ˱í´ïʽ.ºöÂÔÃüÁîÐÐÉϵıí´ïʽ.

  -i

  ¼àÌýinterface.Èç¹û²»Ö¸¶¨½Ó¿Ú,tcpdumpÔÚϵͳµÄ½Ó¿ÚÇåµ¥ÖÐ,ѰÕÒºÅÂë×îС,ÒѾ­ÅäÖúõĽӿÚ(loopback³ýÍâ).Ñ¡ÖеÄʱºò»áÖжÏÁ¬½Ó.

  -l

  Ðлº³å±ê×¼Êä³ö.¿ÉÓÃÓÚ²¶×½Êý¾ÝµÄͬʱ²é¿´Êý¾Ý.ÀýÈç,

  ``tcpdump-l|teedat''or``tcpdump-l>dat&tail-fdat''.

  -n

  ±ð°ÑµØÖ·×ª»»³ÉÃû×Ö(¾ÍÊÇ˵,Ö÷»úµØÖ·,¶Ë¿ÚºÅµÈ)

  -N

  ²»ÏÔʾÖ÷»úÃû×ÖÖеÄÓòÃû²¿·Ö.ÀýÈç,Èç¹ûʹÓÃÕâ¸öÑ¡Ïî,tcpdumpÖ»ÏÔʾ``nic'',¶ø²»ÊÇ``nic.ddn.mil''.

  -O

  ½ûÖ¹ÔËÐб¨ÎÄÆ¥ÅäÄ£°åµÄÓÅ»¯Æ÷.Ö»Óе±Ä㻳ÒÉÓÅ»¯Æ÷ÓÐbugʱ²ÅÓÐÓÃ.

  -p

  ½ûÖ¹°Ñ½Ó¿ÚÖóÉpromiscuousģʽ.×¢Òâ,½Ó¿ÚÓпÉÄÜÒòÆäËûÔ­Òò¶ø´¦ÓÚpromiscuousģʽ;Òò´Ë,'-p'²»ÄÜ×÷Ϊ`etherhost{local-hw-addr}»òetherbroadcast'µÄ¼òд.

  -q

  ¿ìËÙÊä³ö.ÏÔʾ½ÏÉÙµÄЭÒéÐÅÏ¢,Êä³öÐлá¶ÌÒ»µãµã.

  -r

  ´ÓfileÖжÁÈëÊý¾Ý±¨(ÎļþÊÇÓÃ-wÑ¡Ïî´´½¨µÄ).Èç¹ûfileÊÇ``-'',¾Í¶Á±ê×¼ÊäÈë.

  -s

  ´Óÿ¸ö±¨ÎÄÖнØÈ¡snaplen×Ö½ÚµÄÊý¾Ý,¶ø²»ÊÇȱʡµÄ68(Èç¹ûÊÇSunOSµÄNIT,×îСֵÊÇ96).68¸ö×Ö½ÚÊÊÓÃÓÚIP,ICMP,TCPºÍUDP,µ«ÊÇÓпÉÄܽصôÃû×Ö·þÎñÆ÷ºÍNFS±¨ÎĵÄЭÒéÐÅÏ¢(¼ûÏÂÃæ).Êä³öʱÈç¹ûÖ¸¶¨``[|proto]'',tcpdump¿ÉÒÔÖ¸³öÄÇЩ²¶×½Á¿¹ýСµÄÊý¾Ý±¨,ÕâÀïµÄprotoÊǽضϷ¢Éú´¦µÄЭÒé²ãÃû³Æ.×¢Òâ,²ÉÓøü´óµÄ²¶×½·¶Î§¼ÈÔö¼ÓÁË´¦Àí±¨ÎĵÄʱ¼ä,ÓÖÏàÓ¦µÄ¼õÉÙÁ˱¨ÎĵĻº³åÊýÁ¿,¿ÉÄܵ¼Ö±¨ÎĵĶªÊ§.ÄãÓ¦¸Ã°ÑsnaplenÉèµÄ¾¡Á¿Ð¡,Ö»ÒªÄܹ»ÈÝÄÉÄãÐèÒªµÄЭÒéÐÅÏ¢¾Í¿ÉÒÔÁË.

  -T

  °Ñͨ¹ý"expression"ÌôÑ¡³öÀ´µÄ±¨ÎĽâÊͳÉÖ¸¶¨µÄtype.ĿǰÒÑÖªµÄÀàÐÍÓÐ:rpc(Ô¶³Ì¹ý³Ìµ÷ÓÃRemoteProcedureCall),rtp(ʵʱӦÓÃЭÒéReal-TimeApplicationsprotocol),rtcp(ʵʱӦÓÿØÖÆÐ­ÒéReal-TimeApplicationscontrolprotocol),vat(¿ÉÊÓÒôƵ¹¤¾ßVisualAudioTool),ºÍwb(·Ö²¼Ê½°×°ådistributedWhiteBoard).

  -S

  ÏÔʾ¾ø¶ÔµÄ,¶ø²»ÊÇÏà¶ÔµÄTCPÐòÁкÅ.

  -t

  ½ûÖ¹ÏÔʾʱ´Á±êÖ¾.

  -tt

  ÏÔʾδ¸ñʽ»¯µÄʱ´Á±êÖ¾.

  -v

  (ÉÔ΢¶àÒ»µã)·±ËöµÄÊä³ö.ÀýÈç,ÏÔʾIPÊý¾Ý±¨ÖеÄÉú´æÖÜÆÚºÍ·þÎñÀàÐÍ.

  -vv

  ¸ü·±ËöµÄÊä³ö.ÀýÈç,ÏÔʾNFSÓ¦´ð±¨Îĵĸ½¼ÓÓò.

  -w

  °Ñԭʼ±¨ÎÄ´æ½øfile,¶ø²»ÊÇ·ÖÎöºÍÏÔʾ.ËüÃÇ¿ÉÒÔÒÔºóÓÃ-rÑ¡ÏîÏÔʾ.Èç¹ûfileÊÇ``-'',¾ÍдÍù±ê×¼Êä³ö.

  -x

  ÒÔ16½øÖÆÊýÐÎʽÏÔʾÿһ¸ö±¨ÎÄ(È¥µôÁ´Â·²ã±¨Í·ºó).¿ÉÒÔÏÔʾ½ÏСµÄÍêÕû±¨ÎÄ,·ñÔòÖ»ÏÔʾsnaplen¸ö×Ö½Ú.

  expression

  ÓÃÀ´Ñ¡ÔñҪת´¢µÄÊý¾Ý±¨.Èç¹ûûÓÐÖ¸¶¨expression,¾Íת´¢ÍøÂçµÄÈ«²¿±¨ÎÄ.·ñÔò,ֻת´¢Ïà¶ÔexpressionΪ`true'µÄÊý¾Ý±¨.

  expressionÒ»¸ö»ò¶à¸öÔ­Óï(primitive)×é³É.Ô­Óïͨ³£ÓÉÒ»¸ö±êʶ(id,Ãû³Æ»òÊý×Ö),ºÍ±êÊ¶Ç°ÃæµÄÒ»¸ö»ò¶à¸öÐÞÊÎ×Ó(qualifier)×é³É.ÐÞÊÎ×ÓÓÐÈýÖÖ²»Í¬µÄÀàÐÍ:

  type

  ÀàÐÍÐÞÊÎ×ÓÖ¸³ö±êʶÃû³Æ»ò±êʶÊý×Ö´ú±íʲôÀàÐ͵Ķ«Î÷.¿ÉÒÔʹÓõÄÀàÐÍÓÐhost,netºÍport.ÀýÈç,`hostfoo',`net128.3',`port20'.Èç¹û²»Ö¸¶¨ÀàÐÍÐÞÊÎ×Ó,¾ÍʹÓÃȱʡµÄhost.

  dir

  ·½ÏòÐÞÊÎ×ÓÖ¸³öÏà¶ÔÓÚ±êʶµÄ´«Êä·½Ïò(Êý¾ÝÊÇ´«È뻹ÊÇ´«³ö±êʶ).¿ÉÒÔʹÓõķ½ÏòÓÐsrc,dst,srcordstºÍsrcanddst.ÀýÈç, `srcfoo',`dstnet128.3',`srcordstportftp-data'.Èç¹û²»Ö¸¶¨·½ÏòÐÞÊÎ×Ó,¾ÍʹÓÃȱʡµÄsrcordst. ¶ÔÓÚ`null'Á´Â·²ã(¾ÍÊÇ˵ÏóslipÖ®ÀàµÄµãµ½µãЭÒé),ÓÃinboundºÍoutboundÐÞÊÎ×ÓÖ¸¶¨ËùÐèµÄ´«Êä·½Ïò.

  proto

  Ð­ÒéÐÞÊÎ×ÓÒªÇóÆ¥ÅäÖ¸¶¨µÄЭÒé.¿ÉÒÔʹÓõÄЭÒéÓÐ:ether,fddi,ip,arp,rarp,decnet,lat,sca,moprc,mopdl,tcpºÍudp.ÀýÈç,`ethersrcfoo',`arpnet128.3',`tcpport21'.Èç¹û²»Ö¸¶¨Ð­ÒéÐÞÊÎ×Ó,¾ÍʹÓÃËùÓзûºÏÀàÐ͵ÄЭÒé.ÀýÈç,`srcfoo'Ö¸`(ip»òarp»òrarp)srcfoo'(×¢ÒâºóÕß²»·ûºÏÓï·¨),`netbar'Ö¸`(ip»òarp»òrarp)netbar',`port53'Ö¸`(tcp»òudp)port53'.

  [`fddi'ʵ¼ÊÉÏÊÇ`ether'µÄ±ðÃû;·ÖÎöÆ÷°ÑËüÃÇÊÓΪ``ÓÃÔÚÖ¸¶¨ÍøÂç½Ó¿ÚÉϵÄÊý¾ÝÁ´Â·²ã.''FDDI±¨Í·°üº¬ÀàËÆÓÚÒÔ̫ЭÒéµÄÔ´Ä¿µØÖ·,¶øÇÒͨ³£°üº¬ÀàËÆÓÚÒÔ̫ЭÒéµÄ±¨ÎÄÀàÐÍ,Òò´ËÄã¿ÉÒÔ¹ýÂËFDDIÓò,¾ÍÏó·ÖÎöÒÔ̫ЭÒéÒ»Ñù.FDDI±¨Í·Ò²°üº¬ÆäËûÓò,µ«ÊÇÄã²»ÄÜÔÚ¹ýÂËÆ÷±í´ïʽÀïÏÔʽÃèÊö.]

  ×÷ΪÉÏÊöµÄ²¹³ä,ÓÐÒ»Ð©ÌØÊâµÄ`Ô­Óï'¹Ø¼ü×Ö,ËüÃDz»Í¬ÓÚÉÏÃæµÄģʽ:gateway,broadcast,less,greaterºÍÊýѧ±í´ïʽ.ÕâЩÔÚºóÃæÓÐÐðÊö.

  ¸ü¸´ÔӵĹýÂËÆ÷±í´ïʽ¿ÉÒÔͨ¹ýand,orºÍnotÁ¬½ÓÔ­ÓïÀ´×齨.ÀýÈç,`hostfooandnotportftpandnotportftp- data'.ΪÁËÉÙÇõã¼ü,¿ÉÒÔºöÂÔÏàͬµÄÐÞÊÎ×Ó.ÀýÈç,`tcpdstportftporftp-dataordomain'ʵ¼ÊÉϾÍÊÇ `tcpdstportftportcpdstportftp-dataortcpdstportdomain'.

  ÔÊÐíµÄÔ­ÓïÓÐ:

  dsthosthost

  Èç¹û±¨ÎÄÖÐIPµÄÄ¿µÄµØÖ·ÓòÊÇhost,ÔòÂß¼­ÎªÕæ.host¼È¿ÉÒÔÊǵØÖ·,Ò²¿ÉÒÔÊÇÖ÷»úÃû.

  srchosthost

  Èç¹û±¨ÎÄÖÐIPµÄÔ´µØÖ·ÓòÊÇhost,ÔòÂß¼­ÎªÕæ.

  hosthost

  Èç¹û±¨ÎÄÖÐIPµÄÔ´µØÖ·Óò»òÕßÄ¿µÄµØÖ·ÓòÊÇhost,ÔòÂß¼­ÎªÕæ.ÉÏÃæËùÓеÄhost±í´ïʽ¶¼¿ÉÒÔ¼ÓÉÏip,arp,»òrarp¹Ø¼ü×Ö×öǰ׺,¾ÍÏó:

  iphosthost

  ËüµÈ¼ÛÓÚ:

  etherproto\ipandhosthost

  Èç¹ûhostÊÇÓµÓжà¸öIPµØÖ·µÄÖ÷»úÃû,ËüµÄÿ¸öµØÖ·¶¼»á±»²éÑé.

  etherdstehost

  Èç¹û±¨ÎĵÄÒÔ̫ĿµÄµØÖ·ÊÇehost,ÔòÂß¼­ÎªÕæ.Ehost¼È¿ÉÒÔÊÇÃû×Ö(/etc/ethersÀïÓÐ),Ò²¿ÉÒÔÊÇÊý×Ö(ÓйØÊý×Ö¸ñʽÁí¼ûethers(3N)).

  ethersrcehost

  Èç¹û±¨ÎĵÄÒÔ̫ԴµØÖ·ÊÇehost,ÔòÂß¼­ÎªÕæ.

  etherhostehost

  Èç¹û±¨ÎĵÄÒÔ̫ԴµØÖ·»òÒÔ̫ĿµÄµØÖ·ÊÇehost,ÔòÂß¼­ÎªÕæ.

  gatewayhost

  Èç¹û±¨ÎİÑhostµ±×öÍø¹Ø,ÔòÂß¼­ÎªÕæ.Ò²¾ÍÊÇ˵,±¨ÎĵÄÒÔ̫Դ»òÄ¿µÄµØÖ·ÊÇhost,µ«ÊÇIPµÄÔ´Ä¿µØÖ·¶¼²»ÊÇhost.host±ØÐëÊǸöÖ÷»úÃû,¶øÇÒ±ØÐë´æÔÚ/etc/hostsºÍ/etc/ethersÖÐ.(Ò»¸öµÈ¼ÛµÄ±í´ïʽÊÇ

  etherhostehostandnothosthost

  ¶ÔÓÚhost/ehost,Ëü¼È¿ÉÒÔÊÇÃû×Ö,Ò²¿ÉÒÔÊÇÊý×Ö.)

  dstnetnet

  Èç¹û±¨ÎĵÄIPÄ¿µÄµØÖ·ÊôÓÚÍøÂçºÅnet,ÔòÂß¼­ÎªÕæ.net¼È¿ÉÒÔÊÇÃû×Ö(´æÔÚ/etc/networksÖÐ),Ò²¿ÉÒÔÊÇÍøÂçºÅ.(Ïê¼ûnetworks(4)).

  srcnetnet

  Èç¹û±¨ÎĵÄIPÔ´µØÖ·ÊôÓÚÍøÂçºÅnet,ÔòÂß¼­ÎªÕæ.

  netnet

  Èç¹û±¨ÎĵÄIPÔ´µØÖ·»òÄ¿µÄµØÖ·ÊôÓÚÍøÂçºÅnet,ÔòÂß¼­ÎªÕæ.

  netnetmaskmask

  Èç¹ûIPµØÖ·Æ¥ÅäÖ¸¶¨ÍøÂçÑÚÂë(netmask)µÄnet,ÔòÂß¼­ÎªÕæ.±¾Ô­Óï¿ÉÒÔÓÃsrc»òdstÐÞÊÎ.

  netnet/len

  Èç¹ûIPµØÖ·Æ¥ÅäÖ¸¶¨ÍøÂçÑÚÂëµÄnet,ÔòÂß¼­ÎªÕæ,ÑÚÂëµÄÓÐЧλ¿íΪlen.±¾Ô­Óï¿ÉÒÔÓÃsrc»òdstÐÞÊÎ.

  dstportport

  Èç¹û±¨ÎÄÊÇip/tcp»òip/udp,²¢ÇÒÄ¿µÄ¶Ë¿ÚÊÇport,ÔòÂß¼­ÎªÕæ.portÊÇÒ»¸öÊý×Ö,Ò²¿ÉÒÔÊÇ/etc/servicesÖÐ˵Ã÷¹ýµÄÃû×Ö(²Î¿´tcp(4P)ºÍudp(4P)).Èç¹ûʹÓÃÃû×Ö,Ôò¼ì²é¶Ë¿ÚºÅºÍЭÒé.Èç¹ûʹÓÃÊý×Ö,»òÕßÓжþÒåµÄÃû×Ö,ÔòÖ»¼ì²é¶Ë¿ÚºÅ(ÀýÈç,dstport513½«ÏÔʾtcp/loginµÄÊý¾ÝºÍudp/whoµÄÊý¾Ý,¶øportdomain½«ÏÔʾtcp/domainºÍudp/domainµÄÊý¾Ý).

  srcportport

  Èç¹û±¨ÎĵÄÔ´¶Ë¿ÚºÅÊÇport,ÔòÂß¼­ÎªÕæ.

  portport

  Èç¹û±¨ÎĵÄÔ´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚÊÇport,ÔòÂß¼­ÎªÕæ.ÉÏÊöµÄÈÎÒâÒ»¸ö¶Ë¿Ú±í´ïʽ¶¼¿ÉÒÔÓùؼü×Ötcp»òudp×öǰ׺,¾ÍÏó:

  tcpsrcportport

  ËüֻƥÅäÔ´¶Ë¿ÚÊÇportµÄTCP±¨ÎÄ.

  lesslength

  Èç¹û±¨Îĵij¤¶ÈСÓÚµÈÓÚlength,ÔòÂß¼­ÎªÕæ.ËüµÈͬÓÚ:

  len<=length.

  greaterlength

  Èç¹û±¨Îĵij¤¶È´óÓÚµÈÓÚlength,ÔòÂß¼­ÎªÕæ.ËüµÈͬÓÚ:

  len>=length.

  ipprotoprotocol

  Èç¹û±¨ÎÄÊÇIPÊý¾Ý±¨(²Î¼ûip(4P)),ÆäÄÚÈݵÄЭÒéÀàÐÍÊÇprotocol,ÔòÂß¼­ÎªÕæ.Protocol¿ÉÒÔÊÇÊý×Ö,Ò²¿ÉÒÔÊÇÏÂÁÐÃû³ÆÖеÄÒ»¸ö:icmp,igrp,udp,nd,»òtcp.×¢ÒâÕâЩ±êʶ·ûtcp,udp,ºÍicmpҲͬÑùÊǹؼü×Ö,ËùÒÔ±ØÐëÓ÷´Ð±¸Ü(\)תÒå,ÔÚC-shellÖÐÓ¦¸ÃÊÇ\\.

  etherbroadcast

  Èç¹û±¨ÎÄÊÇÒÔÌ«¹ã²¥±¨ÎÄ,ÔòÂß¼­ÎªÕæ.¹Ø¼ü×ÖetherÊÇ¿ÉÑ¡µÄ.

  ipbroadcast

  Èç¹û±¨ÎÄÊÇIP¹ã²¥±¨ÎÄ,ÔòÂß¼­ÎªÕæ.Tcpdump¼ì²éÈ«0ºÍÈ«1¹ã²¥Ô¼¶¨,²¢ÇÒ¼ì²é±¾µØµÄ×ÓÍøÑÚÂë.

  ethermulticast

  Èç¹û±¨ÎÄÊÇÒÔÌ«¶àÄ¿´«Ëͱ¨ÎÄ(multicast),ÔòÂß¼­ÎªÕæ.¹Ø¼ü×ÖetherÊÇ¿ÉÑ¡µÄ.Õâʵ¼ÊÉÏÊÇ`ether[0]&1!=0'µÄ¼òд.

  ipmulticast

  Èç¹û±¨ÎÄÊÇIP¶àÄ¿´«Ëͱ¨ÎÄ,ÔòÂß¼­ÎªÕæ.

  etherprotoprotocol

  Èç¹û±¨ÎÄЭÒéÊôÓÚÒÔÌ«ÀàÐ͵Äprotocol,ÔòÂß¼­ÎªÕæ.Protocol¿ÉÒÔÊÇÊý×Ö,Ò²¿ÉÒÔÊÇÃû×Ö,Èçip,arp,»òrarp.×¢ÒâÕâЩ±êʶ·ûÒ²Êǹؼü×Ö,ËùÒÔ±ØÐëÓ÷´Ð±¸Ü(\)תÒå.[Èç¹ûÊÇFDDI(ÀýÈç,`fddiprotocolarp'),ЭÒé±êʶÀ´×Ô802.2Âß¼­Á´Â·¿ØÖÆ(LLC)±¨Í·,Ëüͨ³£Î»ÓÚFDDI±¨Í·µÄ¶¥²ã.µ±¸ù¾ÝЭÒé±êʶ¹ýÂ˱¨ÎÄʱ,Tcpdump¼ÙÉèËùÓеÄFDDI±¨Îĺ¬ÓÐLLC±¨Í·,¶øÇÒLLC±¨Í·ÓõÄÊÇSNAP¸ñʽ.]

  decnetsrchost

  Èç¹ûDECNETµÄÔ´µØÖ·ÊÇhost,ÔòÂß¼­ÎªÕæ,¸ÃÖ÷»úµØÖ·µÄÐÎʽ¿ÉÄÜÊÇ``10.123'',»òÕßÊÇDECNETÖ÷»úÃû.[Ö»ÓÐÅäÖóÉÔËÐÐDECNETµÄUltrixϵͳ֧³ÖDECNETÖ÷»úÃû.]

  decnetdsthost

  Èç¹ûDECNETµÄÄ¿µÄµØÖ·ÊÇhost,ÔòÂß¼­ÎªÕæ.

  decnethosthost

  Èç¹ûDECNETµÄÔ´µØÖ·»òÄ¿µÄµØÖ·ÊÇhost,ÔòÂß¼­ÎªÕæ.

  ip,arp,rarp,decnet

  ÊÇ:

  etherprotop

  µÄ¼òдÐÎʽ,ÆäÖÐpΪÉÏÊöЭÒéµÄÒ»ÖÖ.

Roc.Ken ·¢±íÓÚ 2005-11-2 21:24

lat,moprc,mopdl

  ÊÇ:

  etherprotop

  µÄ¼òдÐÎʽ,ÆäÖÐpΪÉÏÊöЭÒéµÄÒ»ÖÖ.×¢ÒâtcpdumpĿǰ²»ÖªµÀÈçºÎ·ÖÎöÕâЩЭÒé.

  tcp,udp,icmp

  ÊÇ:

  ipprotop

  µÄ¼òдÐÎʽ,ÆäÖÐpΪÉÏÊöЭÒéµÄÒ»ÖÖ.

  exprrelopexpr

  Èç¹ûÕâ¸ö¹ØÏª*ÉÁ?ÔòÂß¼­ÎªÕæ,ÆäÖÐrelopÊÇ>,<,>=,<=,=,!=Ö®Ò»,exprÊÇÊýѧ±í´ïʽ,Óɳ£ÕûÊý(±ê×¼CÓï·¨ÐÎʽ),ÆÕͨµÄ¶þ½øÖÆÔËËã·û[+,-,*,/,&,|],Ò»¸ö³¤¶ÈÔËËã·û,ºÍÖ¸¶¨µÄ±¨ÎÄÊý¾Ý·ÃÎÊËã·û×é³É.Òª·ÃÎʱ¨ÎÄÄÚµÄÊý¾Ý,ʹÓÃÏÂÃæµÄÓï·¨:

  proto[expr:size]

  ProtoÊÇether,fddi,ip,arp,rarp,tcp,udp,oricmpÖ®Ò»,ͬʱҲָ³öÁËϱê²Ù×÷µÄЭÒé²ã.expr¸ø³ö×Ö½Úµ¥Î»µÄÆ«ÒÆÁ¿,¸ÃÆ«ÒÆÁ¿Ïà¶ÔÓÚÖ¸¶¨µÄЭÒé²ã.SizeÊÇ¿ÉÑ¡Ïî,Ö¸³ö¸ÐÐËȤµÄ×Ö½ÚÊý;Ëü¿ÉÒÔÊÇ1,2,4,ȱʡΪ1×Ö½Ú.Óɹؼü×Ölen¸ø³öµÄ³¤¶ÈÔËËã·ûÖ¸Ã÷±¨Îĵij¤¶È.

  ÀýÈç,`ether[0]&1!=0'²¶×½ËùÓеĶàÄ¿´«Ëͱ¨ÎÄ.±í´ïʽ`ip[0]&0xf!=5'²¶×½ËùÓдø¿ÉÑ¡ÓòµÄIP±¨ÎÄ.±í´ïʽ `ip[6:2]&0x1fff=0'Ö»²¶×½Î´·ÖƬºÍÆ¬Æ«ÒÆÎª0µÄÊý¾Ý±¨.ÕâÖÖ¼ì²éÒþº¬ÔÚtcpºÍudpϱê²Ù×÷ÖÐ.ÀýÈç,tcp[0]Ò»¶¨ÊÇ TCP±¨Í·µÄµÚÒ»¸ö×Ö½Ú,¶ø²»ÊÇÆäÖÐij¸öIPƬµÄµÚÒ»¸ö×Ö½Ú.

  Ô­Óï¿ÉÒÔÓÃÏÂÊö·½·¨½áºÏʹÓÃ:

  Ô°À¨»¡À¨ÆðÀ´µÄÔ­ÓïºÍ²Ù×÷·û(Ô°À¨»¡ÔÚShellÖÐÓÐרÓÃ,ËùÒÔ±ØÐëתÒå).

  È¡·´²Ù×÷(`!'or`not').

  Á¬½á²Ù×÷(`&&'or`and').

  »ò²Ù×÷(`||'or`or').

  È¡·´²Ù×÷ÓÐ×î¸ßÓÅÏȼ¶.»ò²Ù×÷ºÍÁ¬½á²Ù×÷ÓÐÏàͬµÄÓÅÏȼ¶,ÔËËãʱ´Ó×óµ½ÓÒ½áºÏ.×¢ÒâÁ¬½á²Ù×÷ÐèÒªÏÔʽµÄandËã·û,¶ø²»ÊDz¢ÁзÅÖÃ.

  Èç¹û¸ø³ö±êʶ·û,µ«Ã»¸ø¹Ø¼ü×Ö,ÄÇô°µÖ¸×î½üʹÓõĹؼü×Ö.ÀýÈç,

  nothostvsandace

  ×÷Ϊ

  nothostvsandhostace

  µÄ¼òдÐÎʽ,²»Ó¦¸ÃºÍ

  not(hostvsorace)

  »ìÏý.

  ±í´ïʽ²ÎÊý¿ÉÒÔ×÷Ϊµ¥¸ö²ÎÊý´«¸øtcpdump,Ò²¿ÉÒÔ×÷Ϊ¸´ºÏ²ÎÊý,ºóÕ߸ü·½±ãһЩ.Ò»°ã˵À´,Èç¹û±í´ïʽ°üº¬ShellÔª×Ö·û(metacharacter),´«µÝµ¥¸öÀ¨ÆðÀ´µÄ²ÎÊýÒªÈÝÒ×һЩ.¸´ºÏ²ÎÊýÔÚ±»½âÎöǰÓÿոñÁª½ÓÒ»Æð.

  Ê¾Àý(EXAMPLES)

  ÏÔʾËùÓнø³ösundownµÄ±¨ÎÄ:

  tcpdumphostsundown

  ÏÔʾheliosºÍÖ÷»úhot,aceÖ®¼äµÄ±¨ÎÄ´«ËÍ:

  tcpdumphostheliosand\(hotorace\)

  ÏÔʾaceºÍ³ýÁËheliosÒÔÍâµÄËùÓÐÖ÷»úµÄIP±¨ÎÄ:

  tcpdumpiphostaceandnothelios

  ÏÔʾ±¾µØµÄÖ÷»úºÍBerkeleyµÄÖ÷»úÖ®¼äµÄÍøÂçÊý¾Ý:

  tcpdumpnetucb-ether

  ÏÔʾËùÓÐͨ¹ýÍø¹ØsnupµÄftp±¨ÎÄ(×¢ÒâÕâ¸ö±í´ïʽ±»µ¥ÒýºÅÀ¨Æð,·ÀÖ¹shell½âÊÍÔ°À¨»¡):

  tcpdump'gatewaysnupand(portftporftp-data)'

  ÏÔʾ¼È²»ÊÇÀ´×Ô±¾µØÖ÷»ú,Ò²²»ÊÇ´«Íù±¾µØÖ÷»úµÄÍøÂçÊý¾Ý(Èç¹ûÄã°ÑÍø¹ØÍ¨Íùij¸öÆäËûÍøÂç,Õâ¸ö×ö·¨½«²»»á°ÑÊý¾Ý·¢ÍùÄãµÄ±¾µØÍøÂç).

  tcpdumpipandnotnetlocalnet

  ÏÔʾÿ¸öTCP»á»°µÄÆðʼºÍ½áÊø±¨ÎÄ(SYNºÍFIN±¨ÎÄ),¶øÇһỰ·½ÖÐÓÐÒ»¸öÔ¶³ÌÖ÷»ú.

  tcpdump'tcp[13]&3!=0andnotsrcanddstnetlocalnet'

  ÏÔʾ¾­¹ýÍø¹ØsnupÖдóÓÚ576×Ö½ÚµÄIPÊý¾Ý±¨:

  tcpdump'gatewaysnupandip[2:2]>576'

  ÏÔʾIP¹ã²¥»ò¶àÄ¿´«Ë͵ÄÊý¾Ý±¨,ÕâЩ±¨ÎIJ»ÊÇͨ¹ýÒÔÌ«ÍøµÄ¹ã²¥»ò¶àÄ¿´«ËÍÐÎʽ´«Ë͵Ä:

  tcpdump'ether[0]&1=0andip[16]>=224'

  ÏÔʾËùÓв»ÊÇ»ØÏìÇëÇó/Ó¦´ðµÄICMP±¨ÎÄ(Ò²¾ÍÊÇ˵,²»ÊÇping±¨ÎÄ):

  tcpdump'icmp[0]!=8andicmp[0]!=0"

  Êä³ö¸ñʽ(OUTPUTFORMAT)

  tcpdumpµÄÊä³ö¸ñʽȡ¾öÓÚЭÒé.ÏÂÃæµÄÃèÊö¸ø³ö´ó¶àÊý¸ñʽµÄ¼òҪ˵Ã÷ºÍ·¶Àý.

  Á´Â·²ã±¨Í·(LinkLevelHeaders)

  Èç¹û¸ø³ö'-e'Ñ¡Ïî¾ÍÏÔʾÁ´Â·²ã±¨Í·.ÔÚÒÔÌ«ÍøÉÏ,ÏÔʾ±¨ÎĵÄÔ´Ä¿µØÖ·,ЭÒéºÍ±¨Îij¤¶È.

  ÔÚFDDIÍøÂçÉÏ,'-e'Ñ¡Ïîµ¼ÖÂtcpdumpÏÔʾ³ö`Ö¡¿ØÖÆ(framecontrol)'Óò,Ô´Ä¿µØÖ·ºÍ±¨Îij¤¶È.(`Ö¡¿ØÖÆ'Óò¸ºÔð½âÊÍÆäÓàµÄ±¨ÎÄ.ÆÕͨ±¨ÎÄ(±ÈÈçËµÔØÓÐIPÊý¾Ý±¨)ÊÇ`Òì²½'±¨ÎÄ,ÓÅÏȼ¶½éÓÚ0µ½7;ÀýÈç,`async4'.ÕâЩ±»ÈÏÎªÔØÓÐ802.2Âß¼­Á´Â·¿ØÖÆ(LLC)±¨ÎÄ;Èç¹ûËüÃDz»ÊÇISOÊý¾Ý±¨»òÕßËùνµÄSNAP±¨ÎÄ,¾ÍÏÔʾ³öLLC±¨Í·.

  (×¢Òâ:ÒÔÏÂÃèÊöÖмÙÉèÄãÊìϤRFC-1144ÖÐ˵Ã÷µÄSLIPѹËõËã·¨.)

  ÔÚSLIPÁ´Â·ÉÏ,tcpdumpÏÔʾ³ö·½Ïòָʾ(``I''Ö¸inbound,``O''Ö¸outbound),±¨ÎÄÀàÐͺÍѹËõÐÅÏ¢.Ê×ÏÈÏÔʾµÄÊDZ¨ÎÄÀàÐÍ.ÓÐÈýÖÖÀàÐÍip,utcpºÍctcp.¶ÔÓÚip±¨ÎIJ»ÔÙÏÔʾ¸ü¶àµÄÁ´Â·ÐÅÏ¢.¶ÔÓÚTCP±¨ÎÄ,ÔÚÀàÐͺóÃæÏÔʾÁ¬½Ó±êʶ.Èç¹û±¨ÎÄÊÇѹËõ¹ýµÄ,¾ÍÏÔʾ³ö±àÂëµÄ±¨Í·.ÌØÊâÇéÐÎÒÔ*S+nºÍ*SA+nµÄÐÎʽÏÔʾ,ÕâÀïµÄnÊÇ˳ÐòºÅ(»ò˳ÐòºÅ¼°ÆäÈ·ÈÏ)·¢ÉúµÄ¸Ä±ä×ܺÍ.Èç¹û²»ÊÇÌØÊâÇéÐÎ,¾ÍÏÔʾ0»ò¶àÉÙ¸ö¸Ä±ä.¸Ä±äÓÉU(urgentpointer),W(window),A(ack),S(sequencenumber)ºÍI(packetID)Ö¸Ã÷,ºó¸úÒ»¸ö±ä»¯Á¿(+nor-n),»òÁíÒ»¸öÖµ(=n).×îºóÏÔʾ±¨ÎÄÖеÄÊý¾Ý×ܺÍ,ÒÔ¼°Ñ¹Ëõ±¨Í·µÄ³¤¶È.

  ÀýÈç,ÏÂÃæÒ»ÐÐÏÔʾÁËÒ»¸ö´«³öµÄѹËõµÄTCP±¨ÎÄ,ÓÐÒ»¸öÒþº¬µÄÁ¬½Ó±êʶ;È·ÈÏ(ack)µÄ±ä»¯Á¿ÊÇ6,˳ÐòºÅÊÇ49,±¨ÎÄIDÊÇ6;ÓÐÈý¸ö×Ö½ÚµÄÊý¾ÝºÍÁù¸ö×Ö½ÚµÄѹËõ±¨Í·:

  Octcp*A+6S+49I+63(6)

  ARP/RARP±¨ÎÄ

  Arp/rarp±¨ÎĵÄÊä³öÏÔʾÇëÇóÀàÐͼ°Æä²ÎÊý.Êä³ö¸ñʽÇãÏòÓÚÄܹ»×ÔÎÒ½âÊÍ.ÕâÀïÊÇÒ»¸ö¼òµ¥µÄÀý×Ó,À´×ÔÖ÷»úrtsgµ½Ö÷»úcsamµÄ'rlogin'¿ªÊ¼²¿·Ö:

  arpwho-hascsamtellrtsg

  arpreplycsamis-atCSAM

  µÚÒ»ÐÐ˵Ã÷rtsg·¢³öÒ»¸öarp±¨ÎÄѯÎÊinternetÖ÷»úcsamµÄÒÔÌ«ÍøµØÖ·.CsamÓÃËüµÄÒÔÌ«µØÖ·×÷Ó¦´ð(Õâ¸öÀý×ÓÖÐ,ÒÔÌ«µØÖ·ÊÇ´óдµÄ,internetµØÖ·ÎªÐ¡Ð´).

  Èç¹ûÓÃtcpdump-n¿´ÉÏÈ¥ÒªÇå³þһЩ:

  arpwho-has128.3.254.6tell128.3.254.68

  arpreply128.3.254.6is-at02:07:01:00:01:c4

  Èç¹ûÓÃtcpdump-e,¿ÉÒÔ¿´µ½Êµ¼ÊÉϵÚÒ»¸ö±¨ÎÄÊǹ㲥,µÚ¶þ¸ö±¨ÎÄÊǵ㵽µãµÄ:

  RTSGBroadcast080664:arpwho-hascsamtellrtsg

  CSAMRTSG080664:arpreplycsamis-atCSAM

  ÕâÀïµÚÒ»¸ö±¨ÎÄÖ¸³öÒÔÌ«ÍøÔ´µØÖ·ÊÇRTSG,Ä¿µÄµØÖ·ÊÇÒÔÌ«Íø¹ã²¥µØÖ·,ÀàÐÍÓòΪ16½øÖÆÊý0806(ÀàÐÍETHER_ARP),±¨ÎÄÈ«³¤64×Ö½Ú.

  TCP±¨ÎÄ

  (×¢Òâ:ÒÔϵÄÃèÊöÖмÙÉèÄãÊìϤRFC-793ÖÐ˵Ã÷µÄTCPЭÒé,Èç¹ûÄã²»Á˽âÕâ¸öЭÒé,ÎÞÂÛÊDZ¾ÎÄ»¹ÊÇtcpdump¶¼¶ÔÄãÓô¦²»´ó)

  Ò»°ã˵À´tcpЭÒéµÄÊä³ö¸ñʽÊÇ:

  src>dst:flagsdata-seqnoackwindowurgentoptions

  SrcºÍdstÊÇÔ´Ä¿IPµØÖ·ºÍ¶Ë¿Ú.FlagsÊÇS(SYN),F(FIN),P(PUSH)»òR(RST)»òµ¥¶ÀµÄ`.'(ÎÞ±êÖ¾),»òÕßÊÇËüÃǵÄ×éºÏ.Data-seqno˵Ã÷Á˱¾±¨ÎÄÖеÄÊý¾ÝÔÚÁ÷ÐòºÅÖеÄλÖÃ(¼ûÏÂÀý).AckÊÇÔÚÕâÌõÁ¬½ÓÉÏÐÅÔ´»úÏ£ÍûÏÂÒ»¸ö½ÓÊÕµÄ×Ö½ÚµÄÁ÷ÐòºÅ (sequencenumber).WindowÊÇÔÚÕâÌõÁ¬½ÓÉÏÐÅÔ´»ú½ÓÊÕ»º³åÇøµÄ×Ö½Ú´óС.Urg±íÃ÷±¨ÎÄÄÚÊÇ`½ô¼±(urgent)'Êý¾Ý. OptionsÊÇtcp¿ÉÑ¡±¨Í·,ÓüâÀ¨ºÅÀ¨Æð(ÀýÈç,).

  Src,dstºÍflags¿Ï¶¨´æÔÚ.ÆäËûÓòÒÀ¾Ý±¨ÎĵÄtcp±¨Í·ÄÚÈÝ,Ö»Êä³öÓбØÒªµÄ²¿·Ö.

  ÏÂÃæÊÇ´ÓÖ÷»úrtsgrloginµ½Ö÷»úcsamµÄ¿ªÊ¼²¿·Ö.

  rtsg.1023>csam.login:S768512:768512(0)win4096

  csam.login>rtsg.1023:S947648:947648(0)ack768513win4096

  rtsg.1023>csam.login:.ack1win4096

  rtsg.1023>csam.login:P1:2(1)ack1win4096

  csam.login>rtsg.1023:.ack2win4096

  rtsg.1023>csam.login:P2:21(19)ack1win4096

  csam.login>rtsg.1023:P1:2(1)ack21win4077

  csam.login>rtsg.1023:P2:3(1)ack21win4077urg1

  csam.login>rtsg.1023:P3:4(1)ack21win4077urg1

  µÚÒ»ÐÐÊÇ˵´ÓrtsgµÄtcp¶Ë¿Ú1023ÏòcsamµÄlogin¶Ë¿Ú·¢Ëͱ¨ÎÄ.S±êÖ¾±íÃ÷ÉèÖÃÁËSYN±êÖ¾.±¨ÎĵÄÁ÷ÐòºÅÊÇ768512,ûÓÐÊý¾Ý. (Õâ¸öд³É`first:last(nbytes)',Òâ˼ÊÇ`´ÓÁ÷ÐòºÅfirstµ½last,²»°üÀ¨last,ÓÐnbytes×Ö½ÚµÄÓû§Êý¾Ý'.)´ËʱûÓÐÉÓ´øÈ·ÈÏ(piggy-backedack),ÓÐЧµÄ½ÓÊÕ´°¿ÚÊÇ4096×Ö½Ú,ÓÐÒ»¸ö×î´ó¶Î´óС(max-segment-size)µÄÑ¡Ïî,ÇëÇóÉèÖÃmssΪ1024×Ö½Ú.

  CsamÓÃÀàËÆµÄÐÎʽӦ´ð,Ö»ÊÇÔö¼ÓÁËÒ»¸ö¶ÔrtsgSYNµÄÉÓ´øÈ·ÈÏ.È»ºóRtsgÈ·ÈÏcsamµÄSYN.`.'Òâζ×ÅûÓÐÉèÖñêÖ¾.Õâ¸ö±¨ÎIJ»°üº¬Êý¾Ý,Òò´ËÒ²¾ÍûÓÐÊý¾ÝµÄÁ÷ÐòºÅ.×¢ÒâÕâ¸öÈ·ÈÏÁ÷ÐòºÅÊÇÒ»¸öСÕûÊý(1).µ±tcpdumpµÚÒ»´Î·¢ÏÖÒ»¸ötcp»á»°Ê±,ËüÏÔʾ±¨ÎÄЯ´øµÄÁ÷ÐòºÅ.ÔÚËæºóÊÕµ½µÄ±¨ÎÄÀï,ËüÏÔʾµ±Ç°±¨ÎĺÍ×î³õÄǸö±¨ÎĵÄÁ÷ÐòºÅÖ®²î.ÕâÒâζ×Å´ÓµÚÒ»¸ö±¨ÎÄ¿ªÊ¼,ÒÔºóµÄÁ÷ÐòºÅ¿ÉÒÔÀí½â³ÉÊý¾ÝÁ÷ÖеÄÏà¶ÔÎ»ÒÆ asrelativebytepositionsintheconversation'sdatastream(withthefirstdatabyteeachdirectionbeing`1'). `-S'Ñ¡ÏîÄܹ»¸Ä±äÕâ¸öÌØÐÔ,Ö±½ÓÏÔʾԭʼµÄÁ÷ÐòºÅ.

  ÔÚµÚÁùÐÐ,rtsg´«¸øcsam19¸ö×Ö½ÚµÄÊý¾Ý(×Ö½Ú2µ½20).±¨ÎÄÖÐÉèÖÃÁËPUSH±êÖ¾.µÚÆßÐÐcsam±íÃ÷ËüÊÕµ½ÁËrtsgµÄÊý¾Ý,×Ö½ÚÐòºÅÊÇ 21,µ«²»°üÀ¨µÚ21¸ö×Ö½Ú.ÏÔÈ»´ó¶àÊýÊý¾ÝÔÚsocketµÄ»º³åÇøÄÚ,ÒòΪcsamµÄ½ÓÊÕ´°¿ÚÊÕµ½µÄÊý¾ÝСÓÚ19¸ö×Ö½Ú.ͬʱcsamÏòrtsg·¢ËÍÁËÒ»¸ö×Ö½ÚµÄÊý¾Ý.µÚ°ËºÍµÚ¾ÅÐÐÏÔʾcsam·¢ËÍÁËÁ½¸ö×ֽڵĽô¼±Êý¾Ýµ½rtsg.

  Èç¹û²¶×½ÇøÉèÖõĹýС,ÒÔÖÁÓÚtcpdump²»Äܲ¶×½µ½ÍêÕûµÄTCP±¨Í·,tcpdump»á¾¡¿ÉÄܵķ­ÒëÒѲ¶»ñµÄ²¿·Ö,È»ºóÏÔʾ``[|tcp]'',±íÃ÷ÎÞ·¨·­ÒëÆäÓಿ·Ö.Èç¹û±¨Í·°üº¬Ò»¸öαÔìµÄÑ¡Ïî (onewithalengththat'seithertoosmallorbeyondtheendoftheheader),tcpdumpÏÔʾ ``[badopt]''²¢ÇÒ²»ÔÙ·­ÒëÆäËûÑ¡Ï·Ö(ÒòΪËü²»¿ÉÄÜÅжϳö´ÓÄĶù¿ªÊ¼).Èç¹û±¨Í·³¤¶È±íÃ÷´æÔÚÑ¡Ïî,µ«ÊÇIPÊý¾Ý±¨³¤¶È²»¹»,²»¿ÉÄÜÕæµÄ±£´æÑ¡Ïî,tcpdump¾ÍÏÔʾ``[badhdrlength]''.

  UDP±¨ÎÄ

  UDP¸ñʽ¾ÍÏóÕâ¸örwho±¨ÎÄÏÔʾµÄ:

  actinide.who>broadcast.who:udp84

  ¾ÍÊÇ˵°ÑÒ»¸öudpÊý¾Ý±¨´ÓÖ÷»úactinideµÄwho¶Ë¿Ú·¢Ë͵½broadcast,Internet¹ã²¥µØÖ·µÄwho¶Ë¿Ú.±¨Îİüº¬84×Ö½ÚµÄÓû§Êý¾Ý.

  Ä³Ð©UDP·þÎñÄܹ»Ê¶±ð³öÀ´(´ÓÔ´Ä¿¶Ë¿ÚºÅÉÏ),Òò¶øÏÔʾ³ö¸ü¸ß²ãµÄЭÒéÐÅÏ¢.ÌØ±ðÊÇÓòÃû·þÎñÇëÇó(RFC-1034/1035)ºÍNFSµÄRPCµ÷ÓÃ(RFC-1050).

  UDPÓòÃû·þÎñÇëÇó(NameServerRequests)

  (×¢Òâ:ÒÔϵÄÃèÊöÖмÙÉèÄãÊìϤRFC-1035˵Ã÷µÄÓòÃû·þÎñЭÒé.Èç¹ûÄã²»ÊìϤÕâ¸öЭÒé,ÏÂÃæµÄÄÚÈݾÍÏóÊÇÌìÊé.)

  ÓòÃû·þÎñÇëÇóµÄ¸ñʽÊÇ

  src>dst:idop?flagsqtypeqclassname(len)

  h2opolo.1538>helios.domain:3+A?ucbvax.berkeley.edu.(37)

  Ö÷»úh2opolo·ÃÎÊheliosÉϵÄÓòÃû·þÎñ,ѯÎʺÍucbvax.berkeley.edu.¹ØÁªµÄµØÖ·¼Ç¼(qtype=A).²éѯºÅÊÇ `3'.`+'±íÃ÷ÉèÖÃÁ˵ݹéÇëÇó±êÖ¾.²éѯ³¤¶ÈÊÇ37×Ö½Ú,²»°üÀ¨UDPºÍIPÍ·.²éѯ²Ù×÷ÊÇÆÕͨµÄQuery²Ù×÷,Òò´ËopÓò¿ÉÒÔºöÂÔ.Èç¹ûopÉèÖÃ³ÉÆäËûʲô¶«Î÷,ËüÓ¦¸ÃÏÔʾÔÚ`3'ºÍ`+'Ö®¼ä.ÀàËÆµÄ,qclassÊÇÆÕͨµÄC_INÀàÐÍ,Ò²±»ºöÂÔÁË.ÆäËûÀàÐ͵ÄqclassÓ¦¸ÃÔÚ`A'ºóÃæÏÔʾ.

  Tcpdump»á¼ì²éһЩ²»¹æÔòÇé¿ö,ÏàÓ¦µÄ½á¹û×÷Ϊ²¹³äÓò·ÅÔÚ·½À¨ºÅÄÚ:Èç¹ûij¸ö²éѯ°üº¬»Ø´ð,Ãû×Ö·þÎñ»ò¹ÜÀí»ú¹¹²¿·Ö,¾Í°Ñancount, nscount,»òarcountÏÔʾ³É`[na]',`[nn]'»ò`[nau]',ÕâÀïµÄn´ú±íÏàÓ¦µÄÊýÁ¿.Èç¹ûÔÚµÚ¶þºÍµÚÈý×Ö½ÚÖÐ,ÈκÎÒ»¸ö»Ø´ðλ (AA,RA»òrcode)»òÈκÎÒ»¸ö`±ØÐëΪÁã'µÄλ±»ÖÃλ,¾ÍÏÔʾ`[b2&3=x]',ÕâÀïµÄxÊDZ¨Í·µÚ¶þºÍµÚÈý×Ö½ÚµÄ16½øÖÆÊý.

  UDPÃû×Ö·þÎñ»Ø´ð

  Ãû×Ö·þÎñ»Ø´ðµÄ¸ñʽÊÇ

  src>dst:idoprcodeflagsa/n/autypeclassdata(len)

  helios.domain>h2opolo.1538:33/3/7A128.32.137.3(273)

  helios.domain>h2opolo.1537:2NXDomain*0/1/0(97)

  µÚÒ»¸öÀý×ÓÀï,helios»Ø´ðÁËh2opolo·¢³öµÄ±êʶΪ3µÄѯÎÊ,Ò»¹²ÊÇ3¸ö»Ø´ð¼Ç¼,3¸öÃû×Ö·þÎñ¼Ç¼ºÍ7¸ö¹ÜÀí½á¹¹¼Ç¼.µÚÒ»¸ö»Ø´ð¼Í¼µÄÀàÐÍÊÇA(µØÖ·),Êý¾ÝÊÇinternetµØÖ·128.32.137.3.»Ø´ðµÄÈ«³¤Îª273×Ö½Ú,²»°üÀ¨UDPºÍIP±¨Í·.×÷ΪA¼Ç¼µÄclass (C_IN)¿ÉÒÔºöÂÔop(ѯÎÊ)ºÍrcode(NoError).

  ÔÚµÚ¶þ¸öÀý×ÓÀï,helios¶Ô±êʶΪ2µÄѯÎÊ×÷³öÓòÃû²»´æÔÚ(NXDomain)µÄ»Ø´ð,ûÓлشð¼Ç¼,Ò»¸öÃû×Ö·þÎñ¼Ç¼,¶øÇÒûÓйÜÀí½á¹¹.

  `*'±íÃ÷ÉèÖÃÁËȨÍþ»Ø´ð(authoritativeanswer).ÓÉÓÚûÓлشð¼Ç¼,ÕâÀï¾Í²»ÏÔʾtype,classºÍdata.

  ÆäËû±êÖ¾×Ö·û¿ÉÒÔÏÔʾΪ`-'(ûÓÐÉèÖõݹéÓÐЧ(RA))ºÍ`|'(ÉèÖÃÏûÏ¢½Ø¶Ì(TC)).Èç¹û`ÎÊÌâ'²¿·ÖûÓÐÓÐЧµÄÄÚÈÝ,¾ÍÏÔʾ`[nq]'.

  ×¢ÒâÃû×Ö·þÎñµÄѯÎʺͻشðÒ»°ã˵À´±È½Ï´ó,68×Ö½ÚµÄsnaplen¿ÉÄÜÎÞ·¨²¶×½µ½×ã¹»µÄ±¨ÎÄÄÚÈÝ.Èç¹ûÄãµÄÈ·ÔÚÑо¿Ãû×Ö·þÎñµÄÇé¿ö,¿ÉÒÔʹÓÃ-sÑ¡ÏîÔö´ó²¶×½»º³åÇø.`-s128'Ó¦¸ÃЧ¹û²»´íÁË.

  NFSÇëÇóºÍÏìÓ¦

  SunNFS(ÍøÂçÎļþϵͳ)µÄÇëÇóºÍÏìÓ¦ÏÔʾ¸ñʽÊÇ:

  src.xid>dst.nfs:lenopargs

  src.nfs>dst.xid:replystatlenopresults

  sushi.6709>wrl.nfs:112readlinkfh21,24/10.73165

  wrl.nfs>sushi.6709:replyok40readlink"../var"

  sushi.201b>wrl.nfs:

  144lookupfh9,74/4096.6878"xcolors"

  wrl.nfs>sushi.201b:

  replyok128lookupfh9,74/4134.3150

  ÔÚµÚÒ»ÐÐ,Ö÷»úsushiÏòwrl·¢ËͺÅÂëΪ6709µÄ½»Ò׻Ự(×¢ÒâÔ´Ö÷»úºóÃæµÄÊý×ÖÊǽ»Ò׺Å,²»ÊǶ˿Ú).ÕâÏîÇëÇó³¤112×Ö½Ú,²»°üÀ¨UDPºÍIP ±¨Í·.ÔÚÎļþ¾ä±ú(fh)21,24/10.731657119ÉÏÖ´ÐÐreadlink(¶ÁÈ¡·ûºÅÁ¬½Ó)²Ù×÷.(Èç¹ûÔËÆø²»´í,¾ÍÏóÕâÖÖÇé¿ö,Îļþ¾ä±ú¿ÉÒÔÒÀ´Î·­Òë³ÉÖ÷´ÎÉ豸ºÅ,i½ÚµãºÅ,ºÍʼþºÅ(generationnumber).)Wrl»Ø´ð`ok'ºÍÁ¬½ÓµÄÄÚÈÝ.

  ÔÚµÚÈýÐÐ,sushiÇëÇówrlÔÚĿ¼Îļþ9,74/4096.6878ÖвéÕÒ`xcolors'.×¢ÒâÊý¾ÝµÄ´òÓ¡¸ñʽȡ¾öÓÚ²Ù×÷ÀàÐÍ.¸ñʽӦ¸ÃÊÇ¿ÉÒÔ×ÔÎÒ˵Ã÷µÄ.

  ¸ø³ö-v(verbose)Ñ¡Ïî¿ÉÒÔÏÔʾ¸½¼ÓÐÅÏ¢.ÀýÈç:

  sushi.1372a>wrl.nfs:

  148readfh21,11/12.1958192bytes@24576

  wrl.nfs>sushi.1372a:

  replyok1472readREG100664ids417/0sz29388

  (-vͬʱʹËüÏÔʾIP±¨Í·µÄTTL,ID,ºÍ·ÖƬÓò,ÔÚÕâ¸öÀý×ÓÀï°ÑËüÃÇÊ¡ÂÔÁË.)ÔÚµÚÒ»ÐÐ,sushiÇëÇówrl´ÓÎļþ21,11/12.195µÄÆ«ÒÆÎ»ÖÃ24576¿ªÊ¼,¶ÁÈ¡8192×Ö½Ú.Wrl»Ø´ð`ok';µÚ¶þÐÐÏÔʾµÄ±¨ÎÄÊÇÓ¦´ðµÄµÚÒ»¸ö·ÖƬ,Òò´ËÖ»ÓÐ1472×Ö½Ú(ÆäÓàÊý¾ÝÔÚºóÐøµÄ·ÖƬÖд«¹ýÀ´,µ«ÓÉÓÚÕâЩ·ÖƬÀïûÓÐNFSÉõÖÁUDP±¨Í·,Òò´Ë¸ù¾ÝËùʹÓõĹýÂËÆ÷±í´ïʽ,ÓпÉÄܲ»ÏÔʾ).-vÑ¡Ï»áÏÔʾһЩÎļþÊôÐÔ(ËüÃÇ×÷ΪÎļþÊý¾ÝµÄ¸½´ø²¿·Ö´«»ØÀ´):ÎļþÀàÐÍ(ÆÕͨÎļþ``REG''),´æÈ¡Ä£Ê½(°Ë½øÖÆÊý),uidºÍgid,ÒÔ¼°Îļþ´óС.

  Èç¹ûÔÙ¸øÒ»¸ö-vÑ¡Ïî(-vv),»¹ÄÜÏÔʾ¸ü¶àµÄϸ½Ú.

  ×¢ÒâNFSÇëÇóµÄÊý¾ÝÁ¿·Ç³£´ó,³ý·ÇÔö¼Ósnaplen,·ñÔòºÜ¶àϸ½ÚÎÞ·¨ÏÔʾ.ÊÔÒ»ÊÔ`-s192'Ñ¡Ïî.

  NFSÓ¦´ð±¨ÎÄûÓÐÃ÷È·±êÃ÷RPC²Ù×÷.Òò´Ëtcpdump±£ÁôÓÐ``½üÀ´µÄ''ÇëÇó¼Ç¼,¸ù¾Ý½»Ò×ºÅÆ¥ÅäÓ¦´ð±¨ÎÄ.Èç¹ûÓ¦´ð±¨ÎÄûÓÐÏàÓ¦µÄÇëÇó±¨ÎÄ,Ëü¾ÍÎÞ·¨·ÖÎö.

  KIPAppletalk(UDPÉϵÄDDP)

  AppletalkDDP±¨ÎÄ·â×°ÔÚUDPÊý¾Ý±¨ÖÐ,½â°üºó°´DDP±¨ÎÄת´¢(Ò²¾ÍÊÇ˵,ºöÂÔËùÓеÄUDP±¨Í·ÐÅÏ¢).Îļþ/etc/atalk.namesÓÃÀ´°ÑappletalkÍøÂçºÍ½ÚµãºÅ·­Òë³ÉÃû×Ö.Õâ¸öÎļþµÄÐиñʽÊÇ

  numbername

  1.254ether

  16.1icsd-net

  1.254.110ace

  Ç°Á½Ðиø³öÁËappletalkµÄÍøÂçÃû³Æ.µÚÈýÐиø³öij¸öÖ÷»úµÄÃû×Ö(Ö÷»úºÍÍøÂçÒÀ¾ÝµÚÈý×éÊý×ÖÇø·Ö-ÍøÂçºÅÒ»¶¨ÊÇÁ½×éÊý×Ö,Ö÷»úºÅÒ»¶¨ÊÇÈý×éÊý×Ö.) ºÅÂëºÍÃû×ÖÓÿհ׷û(¿Õ¸ñ»òtab)¸ô¿ª./etc/atalk.namesÎļþ¿ÉÒÔ°üº¬¿ÕÐлò×¢ÊÍÐÐ(ÒÔ`#'¿ªÊ¼µÄÐÐ).

  AppletalkµØÖ·°´Õâ¸ö¸ñʽÏÔʾ

  net.host.port

  144.1.209.2>icsd-net.112.220

  office.2>icsd-net.112.220

  jssmag.149.235>icsd-net.2

  (Èç¹û²»´æÔÚ/etc/atalk.names,»òÕßÀïÃæÈ±ÉÙÓÐЧÏîÄ¿,¾ÍÒÔÊý×ÖÐÎʽÏÔʾµØÖ·.)µÚÒ»¸öÀý×ÓÀï,ÍøÂç144.1µÄ209½ÚµãµÄNBP (DDP¶Ë¿Ú2)ÏòÍøÂçicsdµÄ112½ÚµãµÄ220¶Ë¿Ú·¢ËÍÊý¾Ý.µÚ¶þÐкÍÉÏÃæÒ»Ñù,Ö»ÊÇÖªµÀÁËÔ´½ÚµãµÄÈ«³Æ(`office').µÚÈýÐÐÊÇ´ÓÍøÂç jssmagµÄ149½ÚµãµÄ235¶Ë¿ÚÏòicsd-netµÄNBP¶Ë¿Ú¹ã²¥(×¢Òâ¹ã²¥µØÖ·(255)Òþº¬ÔÚÎÞÖ÷»úºÅµÄÍøÂçÃû×ÖÖÐ-ËùÒÔÔÚ /etc/atalk.namesÖÐÇø·Ö½ÚµãÃûºÍÍøÂçÃûÊǸöºÃÖ÷Òâ).

  Tcpdump¿ÉÒÔ·­ÒëNBP(Ãû×ÖÁª½áЭÒé)ºÍATP(Appletalk½»»¥Ð­Òé)µÄ±¨ÎÄÄÚÈÝ.ÆäËûЭÒéֻת´¢Ð­ÒéÃû³Æ(»òºÅÂë,Èç¹û»¹Ã»¸øÕâ¸öЭÒé×¢²áÃû³Æ)ºÍ±¨ÎÄ´óС.

  NBP±¨ÎĵÄÊä³ö¸ñʽ¾ÍÏóÏÂÃæµÄÀý×Ó:

  icsd-net.112.220>jssmag.2:nbp-lkup190:"=:LaserWriter@*"

  jssmag.209.2>icsd-net.112.220:nbp-reply190:"RM1140:LaserWriter@*"250

  techpit.2>icsd-net.112.220:nbp-reply190:"techpit:LaserWriter@*"186

  µÚÒ»ÐÐÊÇÍøÂçicsdµÄ112Ö÷»úÔÚÍøÂçjssmagÉϵĹ㲥,¶ÔÃû×Ölaserwriter×öÃû×Ö²éѯÇëÇó.Ãû×Ö²éѯÇëÇóµÄnbp±êʶºÅÊÇ190.µÚ¶þÐÐÏÔʾµÄÊǶÔÕâ¸öÇëÇóµÄ»Ø´ð(×¢ÒâËüÃÇÓÐͬÑùµÄ±êʶºÅ),Ö÷»újssmag.209±íʾÔÚËüµÄ250¶Ë¿Ú×¢²áÁËÒ»¸ölaserwriterµÄ×ÊÔ´,Ãû×ÖÊÇ "RM1140".µÚÈýÐÐÊÇÕâ¸öÇëÇóµÄÆäËû»Ø´ð,Ö÷»útechpitµÄ186¶Ë¿ÚÓÐlaserwriter×¢²áµÄ"techpit".

  ATP±¨ÎĸñʽÈçÏÂÀýËùʾ:

  jssmag.209.165>helios.132:atp-req12266<0-7>0xae030001

  helios.132>jssmag.209.165:atp-resp12266:0(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:1(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:2(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:3(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:4(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:5(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:6(512)0xae040000

  helios.132>jssmag.209.165:atp-resp*12266:7(512)0xae040000

  jssmag.209.165>helios.132:atp-req12266<3,5>0xae030001

  helios.132>jssmag.209.165:atp-resp12266:3(512)0xae040000

  helios.132>jssmag.209.165:atp-resp12266:5(512)0xae040000

  jssmag.209.165>helios.132:atp-rel12266<0-7>0xae030001

  jssmag.209.133>helios.132:atp-req*12267<0-7>0xae030002

  Jssmag.209ÏòÖ÷»úhelios·¢Æð12266ºÅ½»Ò×,ÇëÇó8¸ö±¨ÎÄ(`<0-7>').ÐÐβµÄÊ®Áù½øÖÆÊýÊÇÇëÇóÖÐ`userdata'ÓòµÄÖµ.

Ò³: [1]

Powered by Discuz! Archiver 6.1.0  © 2001-2007 Comsenz Inc.