利用tcpdump对一次http请求进行抓包,以下是抓包结果,并会分几篇文章进行分析:
tcpdump -X -S -e -i eth1 /(src host 192.168.20.17 and not port 22/) or port 9900
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
15:20:16.299527 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 62: IP 192.168.20.17.2513 > localhost.localdomain.9900: S 2733155023:2733155023(0) win 65535 <mss 1460,nop,nop,sackOK>
0x0000: 4500 0030 aabb 4000 7b06 8ca1 c0a8 1411 E..0..@.{.......
0x0010: c0a8 3309 09d1 26ac a2e8 a2cf 0000 0000 ..3...&.........
0x0020: 7002 ffff 447f 0000 0204 05b4 0101 0402 p...D...........
15:20:16.315251 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 62: IP localhost.localdomain.9900 > 192.168.20.17.2513: S 800828763:800828763(0) ack 2733155024 win 5840 <mss 1460,nop,nop,sackOK>
0x0000: 4500 0030 0000 4000 4006 725d c0a8 3309 E..0..@.@.r]..3.
0x0010: c0a8 1411 26ac 09d1 2fbb ad5b a2e8 a2d0 ....&.../..[....
0x0020: 7012 16d0 5087 0000 0204 05b4 0101 0402 p...P...........
15:20:16.303067 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: . ack 800828764 win 65535
0x0000: 4500 0028 aabc 4000 7b06 8ca8 c0a8 1411 E..(..@.{.......
0x0010: c0a8 3309 09d1 26ac a2e8 a2d0 2fbb ad5c ..3...&...../../
0x0020: 5010 ffff 941b 0000 0000 0000 0000 P.............
15:20:16.304473 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 622: IP 192.168.20.17.2513 > localhost.localdomain.9900: P 2733155024:2733155592(568) ack 800828764 win 65535
0x0000: 4500 0260 aabd 4000 7b06 8a6f c0a8 1411 E..`..@.{..o....
0x0010: c0a8 3309 09d1 26ac a2e8 a2d0 2fbb ad5c ..3...&...../../
0x0020: 5018 ffff 9344 0000 4745 5420 2f20 4854 P....D..GET./.HT
0x0030: 5450 2f31 2e31 0d0a 5573 6572 2d41 6765 TP/1.1..User-Age
0x0040: 6e74 3a20 4f70 6572 612f 392e 3830 2028 nt:.Opera/9.80.(
0x0050: 5769 Wi
15:20:16.304486 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 54: IP localhost.localdomain.9900 > 192.168.20.17.2513: . ack 2733155592 win 6816
0x0000: 4500 0028 42a4 4000 4006 2fc1 c0a8 3309 E..(B.@.@./...3.
0x0010: c0a8 1411 26ac 09d1 2fbb ad5c a2e8 a508 ....&.../../....
0x0020: 5010 1aa0 7743 0000 P...wC..
15:20:16.337412 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 257: IP localhost.localdomain.9900 > 192.168.20.17.2513: P 800828764:800828967(203) ack 2733155592 win 6816
0x0000: 4500 00f3 42a6 4000 4006 2ef4 c0a8 3309 E...B.@.@.....3.
0x0010: c0a8 1411 26ac 09d1 2fbb ad5c a2e8 a508 ....&.../../....
0x0020: 5018 1aa0 c950 0000 4854 5450 2f31 2e31 P....P..HTTP/1.1
0x0030: 2033 3034 204e 6f74 204d 6f64 6966 6965 .304.Not.Modifie
0x0040: 640d 0a44 6174 653a 2046 7269 2c20 3036 d..Date:.Fri,.06
0x0050: 2041 .A
15:20:16.495726 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: . ack 800828967 win 65332
0x0000: 4500 0028 aad5 4000 7b06 8c8f c0a8 1411 E..(..@.{.......
0x0010: c0a8 3309 09d1 26ac a2e8 a508 2fbb ae27 ..3...&...../..'
0x0020: 5010 ff34 91e3 0000 0000 0000 0000 P..4..........
15:20:21.352228 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 54: IP localhost.localdomain.9900 > 192.168.20.17.2513: F 800828967:800828967(0) ack 2733155592 win 6816
0x0000: 4500 0028 42a8 4000 4006 2fbd c0a8 3309 E..(B.@.@./...3.
0x0010: c0a8 1411 26ac 09d1 2fbb ae27 a2e8 a508 ....&.../..'....
0x0020: 5011 1aa0 7677 0000 P...vw..
15:20:21.355614 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: . ack 800828968 win 65332
0x0000: 4500 0028 aca4 4000 7b06 8ac0 c0a8 1411 E..(..@.{.......
0x0010: c0a8 3309 09d1 26ac a2e8 a508 2fbb ae28 ..3...&...../..(
0x0020: 5010 ff34 91e2 0000 0000 0000 0000 P..4..........
15:20:21.455779 00:22:19:4f:7a:09 > 00:22:19:4f:7c:f2, ethertype IPv4 (0x0800), length 60: IP 192.168.20.17.2513 > localhost.localdomain.9900: F 2733155592:2733155592(0) ack 800828968 win 65332
0x0000: 4500 0028 acb0 4000 7b06 8ab4 c0a8 1411 E..(..@.{.......
0x0010: c0a8 3309 09d1 26ac a2e8 a508 2fbb ae28 ..3...&...../..(
0x0020: 5011 ff34 91e1 0000 0000 0000 0000 P..4..........
15:20:21.455790 00:22:19:4f:7c:f2 > 00:22:19:4f:7a:09, ethertype IPv4 (0x0800), length 54: IP localhost.localdomain.9900 > 192.168.20.17.2513: . ack 2733155593 win 6816
0x0000: 4500 0028 42aa 4000 4006 2fbb c0a8 3309 E..(B.@.@./...3.
0x0010: c0a8 1411 26ac 09d1 2fbb ae28 a2e8 a509 ....&.../..(....
0x0020: 5010 1aa0 7676 0000 P...vv..