tcpdump使用范例

范例1. 只抓IPv4的smtp包,ip[0:1]表示ip头中的第一个字节(从0开始),长度为1;然后右移4位的值等于0x4;-S表示显示seq和ack序号的绝对值,而不是相对值。

tcpdump -i eth0 -S '(ip[0:1]>>4 = 0x4) and (tcp port 25)'

显示内容如下:

16:51:27.353122 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [S], seq 1321281134, win 14600, options 
[mss 1460,sackOK,TS val 942718477 ecr 0,nop,wscale 7], length 016:51:27.353901 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [S.], seq 1935336471, ack 1321281135, wi
n 14480, options [mss 1460,sackOK,TS val 1142756484 ecr 942718477,nop,wscale 6], length 016:51:27.354329 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [.], ack 1935336472, win 115, options [n
op,nop,TS val 942718479 ecr 1142756484], length 016:51:28.580959 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [P.], seq 1935336472:1935336521, ack 132
1281135, win 227, options [nop,nop,TS val 1142757712 ecr 942718479], length 4916:51:28.581314 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [.], ack 1935336521, win 115, options [n
op,nop,TS val 942719706 ecr 1142757712], length 0



16:51:36.277983 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [P.], seq 1321281135:1321281141, ack 193
5336521, win 115, options [nop,nop,TS val 942727402 ecr 1142757712], length 616:51:36.278031 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [.], ack 1321281141, win 227, options [n
op,nop,TS val 1142765409 ecr 942727402], length 016:51:36.278383 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [P.], seq 1935336521:1935336536, ack 132
1281141, win 227, options [nop,nop,TS val 1142765409 ecr 942727402], length 1516:51:36.278451 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [F.], seq 1935336536, ack 1321281141, wi
n 227, options [nop,nop,TS val 1142765409 ecr 942727402], length 016:51:36.278893 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [.], ack 1935336536, win 115, options [n
op,nop,TS val 942727403 ecr 1142765409], length 016:51:36.278894 IP 10.236.5.130.49320 > 10.236.5.127.smtp: Flags [F.], seq 1321281141, ack 1935336537, wi
n 115, options [nop,nop,TS val 942727403 ecr 1142765409], length 016:51:36.278934 IP 10.236.5.127.smtp > 10.236.5.130.49320: Flags [.], ack 1321281142, win 227, options [n
op,nop,TS val 1142765410 ecr 942727403], length 0

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值