1、抓包
tcpdump -i any -s 65535 -w /tmp/http.cap “port 80”
tcpdump -i any -s 65535 -w /home/http.cap ‘(((src host 172.16.0.1) or (dst host 172.16.0.2)) and ((port 90) or (port 80)))’
2、wireshark打开http.cap
可以按以下四种过滤
http.request.uri.path == “/url/you/want/find”
http.request_number == 1
ip.src == 172.16.0.1
ip.dst == 172.16.0.2