一次tcp连接及断开的抓包

利用tcpdump对一次http请求进行抓包,以下是抓包结果,并会分几篇文章进行分析:

 

tcpdump -X -S -e -i eth1 /(src host 192.168.20.17 and not port 22/) or port 9900  

 
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
15:20:16.299527 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 62: IP 192.168.20.17.2513 > localhost.localdomain.9900: S 2733155023:2733155023(0) win 65535 <mss 1460,nop,nop,sackOK>
        0x0000:  4500 0030 aabb 4000 7b06 8ca1 c0a8 1411  E..0..@.{.......
        0x0010:  c0a8 3309 09d1 26ac a2e8 a2cf 0000 0000  ..3...&.........
        0x0020:  7002 ffff 447f 0000 0204 05b4 0101 0402  p...D...........
15:20:16.315251 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 62: IP localhost.localdomain.9900 > 192.168.20.17.2513: S 800828763:800828763(0) ack 2733155024 win 5840 <mss 1460,nop,nop,sackOK>
        0x0000:  4500 0030 0000 4000 4006 725d c0a8 3309  E..0..@.@.r]..3.
        0x0010:  c0a8 1411 26ac 09d1 2fbb ad5b a2e8 a2d0  ....&.../..[....
        0x0020:  7012 16d0 5087 0000 0204 05b4 0101 0402  p...P...........
15:20:16.303067 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: . ack 800828764 win 65535
        0x0000:  4500 0028 aabc 4000 7b06 8ca8 c0a8 1411  E..(..@.{.......
        0x0010:  c0a8 3309 09d1 26ac a2e8 a2d0 2fbb ad5c  ..3...&...../../
        0x0020:  5010 ffff 941b 0000 0000 0000 0000       P.............
15:20:16.304473 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 622: IP 192.168.20.17.2513 > localhost.localdomain.9900: P 2733155024:2733155592(568) ack 800828764 win 65535
        0x0000:  4500 0260 aabd 4000 7b06 8a6f c0a8 1411  E..`..@.{..o....
        0x0010:  c0a8 3309 09d1 26ac a2e8 a2d0 2fbb ad5c  ..3...&...../../
        0x0020:  5018 ffff 9344 0000 4745 5420 2f20 4854  P....D..GET./.HT
        0x0030:  5450 2f31 2e31 0d0a 5573 6572 2d41 6765  TP/1.1..User-Age
        0x0040:  6e74 3a20 4f70 6572 612f 392e 3830 2028  nt:.Opera/9.80.(
        0x0050:  5769                                     Wi
15:20:16.304486 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 54: IP localhost.localdomain.9900 > 192.168.20.17.2513: . ack 2733155592 win 6816
        0x0000:  4500 0028 42a4 4000 4006 2fc1 c0a8 3309  E..(B.@.@./...3.
        0x0010:  c0a8 1411 26ac 09d1 2fbb ad5c a2e8 a508  ....&.../../....
        0x0020:  5010 1aa0 7743 0000                      P...wC..
15:20:16.337412 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 257: IP localhost.localdomain.9900 > 192.168.20.17.2513: P 800828764:800828967(203) ack 2733155592 win 6816
        0x0000:  4500 00f3 42a6 4000 4006 2ef4 c0a8 3309  E...B.@.@.....3.
        0x0010:  c0a8 1411 26ac 09d1 2fbb ad5c a2e8 a508  ....&.../../....
        0x0020:  5018 1aa0 c950 0000 4854 5450 2f31 2e31  P....P..HTTP/1.1
        0x0030:  2033 3034 204e 6f74 204d 6f64 6966 6965  .304.Not.Modifie
        0x0040:  640d 0a44 6174 653a 2046 7269 2c20 3036  d..Date:.Fri,.06
        0x0050:  2041                                     .A
15:20:16.495726 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: . ack 800828967 win 65332
        0x0000:  4500 0028 aad5 4000 7b06 8c8f c0a8 1411  E..(..@.{.......
        0x0010:  c0a8 3309 09d1 26ac a2e8 a508 2fbb ae27  ..3...&...../..'
        0x0020:  5010 ff34 91e3 0000 0000 0000 0000       P..4..........
15:20:21.352228 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 54: IP localhost.localdomain.9900 > 192.168.20.17.2513: F 800828967:800828967(0) ack 2733155592 win 6816
        0x0000:  4500 0028 42a8 4000 4006 2fbd c0a8 3309  E..(B.@.@./...3.
        0x0010:  c0a8 1411 26ac 09d1 2fbb ae27 a2e8 a508  ....&.../..'....
        0x0020:  5011 1aa0 7677 0000                      P...vw..
15:20:21.355614 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: . ack 800828968 win 65332
        0x0000:  4500 0028 aca4 4000 7b06 8ac0 c0a8 1411  E..(..@.{.......
        0x0010:  c0a8 3309 09d1 26ac a2e8 a508 2fbb ae28  ..3...&...../..(
        0x0020:  5010 ff34 91e2 0000 0000 0000 0000       P..4..........
15:20:21.455779 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: F 2733155592:2733155592(0) ack 800828968 win 65332
        0x0000:  4500 0028 acb0 4000 7b06 8ab4 c0a8 1411  E..(..@.{.......
        0x0010:  c0a8 3309 09d1 26ac a2e8 a508 2fbb ae28  ..3...&...../..(
        0x0020:  5011 ff34 91e1 0000 0000 0000 0000       P..4..........
15:20:21.455790 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 54: IP localhost.localdomain.9900 > 192.168.20.17.2513: . ack 2733155593 win 6816
        0x0000:  4500 0028 42aa 4000 4006 2fbb c0a8 3309  E..(B.@.@./...3.
        0x0010:  c0a8 1411 26ac 09d1 2fbb ae28 a2e8 a509  ....&.../..(....
        0x0020:  5010 1aa0 7676 0000                      P...vv..

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值