Wiresahrk抓包过滤技术



CaptureFilters
DisplayFilters

Protocol Direction Host(s) Value Logical Operations Other expression
tcp dst 10.1.1.1 80 and tcp dst 10.2.2.2 3128:ether iparp rarptcp and udp
:srcdst src and dst src or dst :net porthostportrangehost
:not and|| or&&src portrange 2000-2500UDPTCP20002500

Protocol.String 1.String 2 Comparisonoperator Value LogicalOperations
ip.src.addr == 10.1.1.1 and
==
=
>=
and
or
notIP:ip.addrip.srcip.dst
:tcp.porttcp.srcporttcp.flag.syn1
tcp.port == 80 #
tcp.port eq 80 or udp.port eq 80
tcp.dstport == 80 #tcp80
tcp.srcport == 80 #tcp80
tcp.port >= 1 and tcp.port
2MAC

eth.dst == E4:D5:3D:A2:64:95 #MAC
eth.src eq E4:D5:3D:A2:64:95 #MAC
eth.addr eq E4:D5:3D:A2:64:95 #MACMACA0:00:00:04:C5:84
!eth.addr==e4:d5:3d:a2:64:95 #MAC

3IP
ip.src == 192.168.0.104 ip192.168.0.104

4
udp.length == 26 udp8udp
tcp.len >= 7 ip(tcp),tcp
ip.len == 94 14,ip.len,ip
frame.len == 119 ,eth
eth > ip or arp > tcp or udp > data

5http
http.request.method == GET
http.request.method == POST
http.request.uri == /img/logo-edu.gif
http contains GET
http contains HTTP/1.

6DHCP
DHCP
DHCPbootp.type==0x02Offer/Ack/NAK
bootp.type==0x02 and not ip.src==192.168.1.1
7DNS
dns.flags==0x0100https://wiki.wireshark.org/CaptureFilters

Network monitoradministrator ToolQQ
1Network monitorIP
(Network monitorwireshark)
2wireshark
3IP
4免费云主机域名
wireshark

相关推荐: linux如何查看jdk是什么版本

这篇文章主要介绍了linux如何查看jdk是什么版本的相关知识,内容详细易懂,操作简单快捷,具有一定借鉴价值,相信大家阅读完这篇linux如何查看jdk是什么版本文章都会有所收获,下面我们一起来看看吧。 查看方法:1、如果没有设置jdk环境变量,则需要先使用c…

免责声明:本站发布的图片视频文字,以转载和分享为主,文章观点不代表本站立场,本站不承担相关法律责任;如果涉及侵权请联系邮箱:360163164@qq.com举报,并提供相关证据,经查实将立刻删除涉嫌侵权内容。

(0)
打赏 微信扫一扫 微信扫一扫
上一篇 01/29 11:30
下一篇 01/29 11:30