精通wireshark - 分析

DNS

https://www.cnblogs.com/smillepro/articles/10573460.html

https://www.cnblogs.com/xzjf/p/7684035.html

 

Response:标识该消息为查询消息还是响应消息

Opcode :标记了查询消息的状态 

0 :标准查询

1:逆向查询

2:服务器请求状态

3:未分配

4:通告

5:更新

6-15:未分配

响应消息

0 :没有错误

1:格式错误

2:服务器故障

3:域名错误

4:未使用

5:拒绝

TYPE类型

FTP

21 port 控制信道

20 port 数据信道

ftp暴力破解: ftp.request.command=="PASS"

HTTP

服务器没有处理请求会回复:RST ACK数据包

查看服务器类型

 

302  found  重定向 

SMTP

 

客户端 - 服务端模式的协议

port:25 

响应码大于350表示网络出现了影响网络性能的错误。

 

TCP  面向消息的协议

UDP 面向事务的协议

SYN 同步  

ACK 确认   

RST 重置

FIN 结束

PSH 推送

URG 紧急

CWR 拥塞窗口减小

ACK的真实值

 

 

 

 

  • 1
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
Use Wireshark 2 to overcome real-world network problems Key Features Delve into the core functionalities of the latest version of Wireshark Master network security skills with Wireshark 2 Efficiently find the root cause of network-related issues Book Description Wireshark, a combination of a Linux distro (Kali) and an open source security framework (Metasploit), is a popular and powerful tool. Wireshark is mainly used to analyze the bits and bytes that flow through a network. It efficiently deals with the second to the seventh layer of network protocols, and the analysis made is presented in a form that can be easily read by people. Mastering Wireshark 2 helps you gain expertise in securing your network. We start with installing and setting up Wireshark2.0, and then explore its interface in order to understand all of its functionalities. As you progress through the chapters, you will discover different ways to create, use, capture, and display filters. By halfway through the book, you will have mastered Wireshark features, analyzed different layers of the network protocol, and searched for anomalies. You’ll learn about plugins and APIs in depth. Finally, the book focuses on pocket analysis for security tasks, command-line utilities, and tools that manage trace files. By the end of the book, you'll have learned how to use Wireshark for network security analysis and configured it for troubleshooting purposes. What you will learn Understand what network and protocol analysis is and how it can help you Use Wireshark to capture packets in your network Filter captured traffic to only show what you need Explore useful statistic displays to make it easier to diagnose issues Customize Wireshark to your own specifications Analyze common network and network application protocols Who this book is for If you are a security professional or a network enthusiast and are interested in understanding the internal working of networks, and if you have some prior knowledge of using Wireshark, then this book is for you. Table of Contents Installing Wireshark 2 Capturing Traffic Filtering Traffic Customizing Wireshark Statistics Introductory Analysis Network Protocol Analysis Application Protocol Analysis I Application Protocol Analysis II Command-Line Tools A Troubleshooting Scenario
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值