Wireshark学习资料:https://wiki.wireshark.org/FrontPage
Gotchas
Some filter fields match against multipleprotocol fields. For example, "ip.addr" matches against both the IP source and destination addresses in the IP header. The same is true for "tcp.port", "udp.port", "eth.addr", and others. It's important to note that
- ip.addr == 10.43.54.65
is equivalent to ip.src == 10.43.54.65 or ip.dst == 10.43.54.65
目的:通过此软件抓取手机IOS APP软件的包的数据
1. 首先去官网下载软件包:https://www.wireshark.org/#download
2. 获取电脑的MAC电脑的IP地址
3. 确保你的手机和电脑是同一个网(此处我的电脑是有线,电脑开了wifi给手机使用)
4.选择网络的连接方式(双击它就可以了)
因为我这边是USB转以太网,所以我选择 USB Ethernet:en5
5. 抓包的地址输入,点击右边小尖执行,然后点击左边的第一个按钮执行抓包动作
6. 抓包结果分析与查看
7.因为抓到的包的数据很多,暂停抓包,然后此刻需要筛选你想要的数据
8. 点击某一条抓包的数据,然后右键追踪流--TCP流。,可以看到如下的清晰数据流