ÄÚÈÝ·¢²¼¸üÐÂʱ¼ä : 2025/12/20 10:08:41ÐÇÆÚÒ» ÏÂÃæÊÇÎÄÕµÄÈ«²¿ÄÚÈÝÇëÈÏÕæÔĶÁ¡£
ÔÚ°üÁбíÃæ°åʵʱ¸üв¶×½Êý¾Ý¡£Èç¹ûδѡ¶¨¸ÃÑ¡ÏÔÚWireshark²¶×½½áÊøÖ®Ç°½«²»ÄÜÏÔʾÊý¾Ý¡£Èç¹ûÑ¡ÖиÃÑ¡ÏWireshark½«Éú³ÉÁ½¸ö¶ÀÁ¢µÄ½ø³Ì£¬Í¨¹ý²¶×½½ø³Ì´«ÊäÊý¾Ý¸øÏÔʾ½ø³Ì¡£ Automatic scrolling in live capture
Ö¸¶¨WiresharkÔÚÓÐÊý¾Ý½øÈëʱʵʱ¹ö¶¯°üÁбíÃæ°å£¬ÕâÑùÄú½«Ò»Ö±ÄÜ¿´µ½×î½üµÄ°ü¡£·´Ö®£¬Ôò×îÐÂÊý¾Ý°ü»á±»·ÅÖÃÔÚÐÐÄ©£¬µ«²»»á×Ô¶¯¹ö¶¯Ãæ°å¡£Èç¹ûδÉèÖÃ\¸ÃÑ¡ÏÊÇ»ÒÉ«²»¿ÉÑ¡µÄ¡£
Hide capture info dialog
Ñ¡ÖиÃÑ¡Ï½«»áÒþ²Ø²¶×½ÐÅÏ¢¶Ô»°¿ò
4.5.5. Ãû³Æ½âÎöÉèÖÃ
Enable MAC name resolution
ÉèÖÃÊÇ·ñÈÃWireshark·ÒëMACµØÖ·ÎªÃû³Æ£¬¼ûµÚ 7.6 ½Ú ¡°Ãû³Æ½âÎö¡± Enable network name resolution
ÊÇ·ñÔÊÐíWireshark¶ÔÍøÂçµØÖ·½øÐнâÎö£¬¼ûµÚ 7.6 ½Ú ¡°Ãû³Æ½âÎö¡±
4.5.6. °´Å¥
½øÐÐÍêÉÏÊöÉèÖÃÒÔºó£¬Äã¿ÉÒÔµã»÷start°´Å¥½øÐв¶×½,Ò²¿ÉÒÔµã»÷CancelÍ˳ö²¶×½. ¿ªÊ¼²¶×½ÒÔºó£¬ÔÚÄãÊÕ¼¯µ½×ã¹»µÄÊý¾ÝʱÄã¿ÉÒÔÍ£Ö¹²¶×½¡£¼ûµÚ 4.9 ½Ú ¡°ÔÚ²¶×½¹ý³ÌÖС±
4.6. ²¶×½Îļþ¸ñʽ¡¢Ä£Ê½ÉèÖÃ
ÔÚ ²¶×½Ê±£¬libpcap ²¶×½ÒýÇæ(linux»·¾³ÏÂ)»áץȡÀ´×ÔÍø¿¨µÄ°ü´æ·ÅÔÚ(Ïà¶ÔÀ´Ëµ)½ÏСµÄºËÐÄ»º´æÄÚ¡£ÕâЩÊý¾ÝÓÉWireshark¶ÁÈ¡²¢±£´æµ½Óû§Ö¸¶¨µÄ²¶×½ÎļþÖС£ ±£´æ°üÊý¾Ýµ½²¶×½Îļþʱ£¬¿É²ÉÓòîÒìģʽ²Ù×÷¡£
Ìáʾ
´¦Àí´óÎļþ(Êý°ÙÕ×)½«»á±äµÃ·Ç³£Âý¡£Èç¹ûÄã¼Æ»®½øÐг¤Ê±¼ä²¶×½£¬»òÕß´¦ÓÚÒ»¸ö¸ßÍÌÍÂÁ¿µÄÍøÂçÖУ¬¿¼ÂÇ Ê¹ÓÃÇ°ÃæÌáµ½µÄ\¶àÎļþ\Ñ¡Ïî¡£¸ÃÑ¡Ïî¿ÉÒÔ½«²¶×½°ü·Ö¸îΪ¶à¸öСÎļþ¡£ÕâÑù¿ÉÄܸüÊʺÏÉÏÊö»·¾³¡£ ×¢Òâ
ʹÓöàÎļþ¿ÉÄÜ»áÇжÏÉÏÏÂÎĹØÁªÐÅÏ¢¡£Wireshark±£ÁôÔØÈë°üµÄÉÏÏÂÎÄÐÅÏ¢£¬ËùÒÔËü»á±¨¸æÉÏÏÂÎĹØÁªÎÊÌâ (ÀýÈçÁ÷ÎÊÌâ)ºÍ¹ØÁªÉÏÏÂÎÄÐÒéÐÅÏ¢(ÀýÈ磺ºÎ´¦Êý¾Ý²úÉú½¨Á¢½×¶Î£¬±ØÐë²éÕÒºóÐø°ü)¡£ÕâЩÐÅÏ¢½öÄÜÔÚÔØÈëÎļþÖÐÏÔʾ£¬Ê¹ÓöàÎļþģʽ¿ÉÄÜ»á½Ø¶ÏÕâÑùµÄÉÏÏÂÎÄ¡£Èç¹û½¨Á¢Á¬½Ó½×¶ÎÒѾ±£´æÔÚÒ»¸öÎļþÖУ¬ÄãÏëÒª¿´µÄÔÚÁíÒ»¸öÎļþÖУ¬Äã¿ÉÄÜÎÞ·¨¿´µ½¿ÉÓõÄÉÏÏÂÎĹØÁªÐÅÏ¢¡£ Ìáʾ
¹ØÓÚ²¶×½ÎļþµÄĿ¼ÐÅÏ¢£¬¿É¼û???
±í 4.1. ²¶×½ÎļþģʽѡÏî
\\Ñ¡\with n files\Ïî files\Ñ¡Ïî Ñ¡Ïî - - - - - x Mode Single temporary file Single named file Multiple files,continuous ×îÖÕÎļþÃüÃû·½Ê½ etherXXXXXX (where XXXXXX ÊÇÒ»¸ö¶ÀÁ¢Öµ) foo.cap foo_00001_20040205110102.cap, foo_00002_20040205110102.cap, ... foo.cap - foo.cap x foo.cap x Single temporary file
Multiple files,ring foo_00001_20040205110102.cap, buffer foo_00002_20040205110102.cap, ... ½«»á´´½¨²¢Ê¹ÓÃÒ»¸öÁÙʱÎļþ(ĬÈÏÑ¡Ïî).²¶×½Îļþ½áÊøºó£¬¸ÃÎļþ¿ÉÒÔÓÉÓû§Ö¸¶¨ÎļþÃû¡£
Single named file
ʹÓõ¥¶ÀÎļþ£¬Èç¹ûÄãÏë·Åµ½Ö¸¶¨Ä¿Â¼£¬Ñ¡Ôñ´Ëģʽ Multiple files,continuous
Óësingle name fileģʽÀàËÆ£¬²»Í¬µãÔÚÓÚ£¬µ±²¶×½´ïµ½¶àÎļþÇл»ÁÙ½çÌõ¼þʱ֮һʱ£¬»á´´½¨Ò»¸öÐÂÎļþÓÃÓÚ²¶×½
Multiple files,ring buffer
Óë\files continuous\ģʽÀàËÆ£¬²»Í¬Ö®´¦ÔÚÓÚ£¬´´½¨µÄÎļþÊýÄ¿¹Ì¶¨¡£µ±´ïµ½ring buffer with nֵʱ£¬»áÌæ»»µôµÚÒ»¸öÎļþ¿ªÊ¼²¶×½£¬Èç´ËÑ»·Íù¸´¡£
¸Ãģʽ¿ÉÒÔÏÞÖÆ×î´ó´ÅÅ̿ռäʹÓÃÁ¿£¬¼´Ê¹Î´ÏÞÖÆ²¶×½Êý¾ÝÊäÈ룬ҲֻÄܱ£Áô×îºó¼¸¸ö²¶×½Êý¾Ý¡£
4.7. Á´Â·²ã°üÍ·ÀàÐÍ
ÔÚͨ³£Çé¿öÏ£¬Äã²»ÐèҪѡÔñÁ´Â·²ã°üÍ·ÀàÐÍ¡£ÏÂÃæµÄ¶ÎÂäÃèÊöÁËÀýÍâµÄÇé¿ö£¬´ËʱѡÔñ°üÍ·ÀàÐÍÊÇÓбØÒªµÄ£¬ËùÒÔÄãÐèÒªÖªµÀÔõô×ö£º
Èç¹ûÄãÔÚijÖÖ°æ±¾BSD²Ù×÷ϵͳÏ´ÓijÖÖ802.11 É豸(ÎÞÏß¾ÖÓòÍøÉ豸)²¶×½Êý¾Ý£¬¿ÉÄÜÐèÒªÔÚ\ºÍ\ÖÐ×ö³öÑ¡Ôñ¡£\½«»áµ¼Ö²¶×½µ½µÄ°ü´øÓÐαÒÔÌ«ÍøÖ¡Í·(²»ÖªµÀÊDz»ÊÇÓ¦¸Ã½ÐαÊײ¿¸ü׼ȷЩ);\½«»áµ¼ÖÂËûÃÇ´øÓÐ802.11Ö¡Í·¡£Èç¹û²¶×½Ê±µÄÓ¦ÓóÌÐò²»Ö§³Ö\Ö¡Í·\£¬ÄãÐèҪѡÔñ\
Èç¹ûÄãʹÓÃEndace DAG card(ijÖÖÍøÂç¼àÊÓ¿¨)Á¬½Óµ½Í¬²½´®¿ÚÏß(ÒëÕß×¢£ºEÎÄΪsynchronous serial line£¬È¨ÇÒ·Òë×÷ǰÎİɣ¬Î´½Ó´¥¹ý´Ë¿¨¡¢Î´Êìïþ´ËÏßÃû³Æ)£¬¿ÉÄÜ»á³öÏÖ\over serial\»ò \HDLC\×Ô¼ºgoogleÈ¥)¹©Ñ¡Ôñ¡£¸ù¾ÝÄã×Ô¼ºµÄÇé¿öÑ¡Ôñ¶þÕßÖеÄÒ»¸ö¡£
Èç¹ûÄãʹÓÃEndace DAG card(ͬÉÏ)Á¬½Óµ½ATMÍøÂ磬½«»áÌṩ\¡¢\¹©Ñ¡Ôñ¡£Èç¹û²¶×½µÄͨÐÅÊÇRFC 1483·â×°IP(RFC 1483 LLC-encapsulated IP,²»·ÒëΪÃî)£¬»òÕßÐèÒªÔÚ²»Ö§³ÖSunATMÖ¡Í·µÄÓ¦ÓóÌÐòϲ¶×½£¬Ñ¡ÔñǰÕß¡£·´Ö®Ñ¡ÔñºóÕß¡£
Èç¹ûÄãÔÚÒÔÌ«Íø²¶×½£¬½«»áÌṩ\¡¢\¹©Ñ¡Ôñ£¬Èç¹ûÄúÊÇÔÚCisco Cable Modem Termination System(CMTSÊÇ˼¿ÆÍ¬ÖáµçÀÂÖն˵÷ÖÆ½âµ÷ϵͳ£¿)ϲ¶×½Êý¾Ý¡£Ëü»á½«DOCSIS(ͬÖáµçÀÂÊý¾Ý·þÎñ½Ó¿Ú)ͨÐÅ·ÅÖõ½ÒÔÌ«ÍøÖУ¬¹©²¶×½¡£´ËʱÐèҪѡÔñ\·´Ö®Ôò·´Ö®¡£
4.8. ²¶×½Ê±¹ýÂË
WiresharkʹÓÃlibpcap¹ýÂËÓï¾ä½øÐв¶×½¹ýÂË(what about winpcap?)¡£ÔÚtcpdumpÖ÷Ò³ÓнéÉÜ£¬µ«ÕâЩֻÊǹýÓÚ»ÞɬÄѶ®£¬ËùÒÔÕâÀï×öС·ù¶È½²½â¡£
Ìáʾ
Äã¿ÉÒÔ´Óhttp://wiki.wireshark.org/CaptureFiltersÕÒµ½²¶×½¹ýÂË·¶Àý.
ÔÚWireshark²¶×½Ñ¡Ïî¶Ô»°(¼ûͼ 4.2 ¡°\²¶×½Ñ¡Ïî\¶Ô»°¿ò¡±)¿òÊäÈë²¶×½¹ýÂË×ֶΡ£ÏÂÃæµÄÓï¾äÓеãÀàËÆÓÚtcpdump²¶×½¹ýÂËÓïÑÔ¡£ÔÚtcpdumpÖ÷Ò³http://www.tcpdump.org/tcpdump_man.html¿ÉÒÔ¿´µ½tcpdump±í´ïʽѡÏî½éÉÜ¡£
²¶×½¹ýÂ˵ÄÐÎʽΪ£ººÍȡֵ(and/or)½øÐнøÐлù±¾µ¥ÔªÁ¬½Ó£¬¼ÓÉÏ¿ÉÑ¡µÄ£¬¸ßÓÐÏÞ¼¶µÄnot: [not] primitive [and|or [not] primitive ...] Àý 4.1. ²¶×½À´×ÔÌØ¶¨Ö÷»úµÄtelnetÐÒé tcp port 23 and host 10.0.0.5
±¾Àý²¶×½À´×Ô»òÖ¸ÏòÖ÷»ú10.0.0.5µÄTelnet ͨÐÅ£¬Õ¹Ê¾ÁËÈçºÎÓÃandÁ¬½ÓÁ½¸ö»ù±¾µ¥Ôª¡£ÁíÍâÒ»¸öÀý×ÓÀý 4.2 ¡°²¶×½ËùÓв»ÊÇÀ´×Ô10.0.0.5µÄtelnet ͨÐÅ¡±Õ¹Ê¾ÈçºÎ²¶×½ËùÓв»ÊÇÀ´×Ô10.0.0.5µÄtelnet ͨÐÅ¡£ Àý 4.2. ²¶×½ËùÓв»ÊÇÀ´×Ô10.0.0.5µÄtelnet ͨÐÅ tcp host 23 and not src host 10.0.0.5
´Ë´¦±ÊÕß½¨ÒéÔö¼Ó¸ü¶à·¶Àý¡£µ«ÊDz¢Ã»ÓÐÌí¼Ó¡£
Ò»¸ö»ù±¾µ¥ÔªÍ¨³£ÊÇÏÂÃæÖеÄÒ»¸ö [src|dst] host
´Ë»ù±¾µ¥ÔªÔÊÐíÄã¹ýÂËÖ÷»úipµØÖ·»òÃû³Æ¡£Äã¿ÉÒÔÓÅÏÈÖ¸¶¨src|dst¹Ø¼ü´ÊÀ´Ö¸¶¨Äã¹Ø×¢µÄÊÇÔ´µØÖ·»¹ÊÇÄ¿±êµØÖ·¡£Èç¹ûδָ¶¨£¬ÔòÖ¸¶¨µÄµØÖ·³öÏÖÔÚÔ´µØÖ·»òÄ¿±êµØÖ·Öеİü»á±»×¥È¡¡£ ether [src|dst] host
´Ëµ¥ÔªÔÊÐíÄã¹ýÂËÖ÷»úÒÔÌ«ÍøµØÖ·¡£Äã¿ÉÒÔÓÅÏÈÖ¸¶¨¹Ø¼ü´Êsrc|dstÔڹؼü´ÊetherºÍhostÖ®¼ä£¬À´È·¶¨Äã¹Ø×¢µÄÊÇÔ´µØÖ·»¹ÊÇÄ¿±êµØÖ·¡£Èç¹ûδָ¶¨£¬Í¬ÉÏ¡£ gateway host
¹ýÂËͨ¹ýÖ¸¶¨host×÷ÎªÍø¹ØµÄ°ü¡£Õâ¾ÍÊÇÖ¸ÄÇЩÒÔÌ«ÍøÔ´µØÖ·»òÄ¿±êµØÖ·ÊÇhost£¬µ«Ô´ipµØÖ·ºÍÄ¿±êipµØÖ·¶¼²»ÊÇhostµÄ°ü
[src|dst] net
ͨ¹ýÍøÂçºÅ½øÐйýÂË¡£Äã¿ÉÒÔÑ¡ÔñÓÅÏÈÖ¸¶¨src|dstÀ´È·¶¨Äã¸ÐÐËȤµÄÊÇÔ´ÍøÂ绹ÊÇÄ¿±êÍøÂç¡£Èç¹ûÁ½¸ö¶¼Ã»Ö¸¶¨¡£Ö¸¶¨ÍøÂç³öÏÖÔÚÔ´»¹ÊÇÄ¿±êÍøÂçµÄ¶¼»á±»Ñ¡Ôñ¡£ÁíÍ⣬Äã¿ÉÒÔÑ¡Ôñ×ÓÍøÑÚÂë»òÕßCIDR(ÎÞÀà±ðÓòÐÎʽ)¡£ [tcp|udp] [src|dst] port ¹ýÂËtcp,udp¼°¶Ë¿ÚºÅ¡£¿ÉÒÔʹÓÃsrc|dstºÍtcp|udp¹Ø¼ü´ÊÀ´È·¶¨À´×ÔÔ´»¹ÊÇÄ¿±ê£¬tcpÐÒ黹ÊÇudpÐÒé¡£tcp|udp±ØÐë³öÏÖÔÚsrc|dst֮ǰ¡£ less|greater Ñ¡Ôñ³¤¶È·ûºÏÒªÇóµÄ°ü¡££¨´óÓÚµÈÓÚ»òСÓÚµÈÓÚ£© ip|ether proto Ñ¡ÔñÓÐÖ¸¶¨µÄÐÒéÔÚÒÔÌ«Íø²ã»òÊÇip²ãµÄ°ü ether|ip broadcast|multicast Ñ¡ÔñÒÔÌ«Íø/ip²ãµÄ¹ã²¥»ò¶à²¥ ´´½¨Ò»¸ö¸´ÔÓ¹ýÂ˱í´ïʽ£¬À´Ñ¡Ôñ°üµÄ×Ö½Ú»ò×Ö½Ú·¶Î§·ûºÏÒªÇóµÄ°ü¡£Çë²Î¿¼http://www.tcpdump.org/tcpdump_man.html 4.8.1. ×Ô¶¯¹ýÂËÔ¶³ÌͨÐÅ Èç¹ûWiresharkÊÇʹÓÃÔ¶³ÌÁ¬½ÓµÄÖ÷»úÔËÐеÄ(ÀýÈçʹÓÃSSH,X11 WindowÊä³ö£¬ÖÕ¶Ë·þÎñÆ÷)£¬Ô¶³ÌÁ¬½Ó±ØÐëͨ¹ýÍøÂç´«Ê䣬»áÔÚÄãÕæÕý¸ÐÐËȤµÄͨÐÅÖвúÉú´óÁ¿Êý¾Ý°ü(ͨ³£Ò²ÊDz»ÖØÒªµÄ) ÏëÒª±ÜÃâÕâÖÖÇé¿ö£¬wireshark¿ÉÒÔÉèÖÃΪÈç¹û·¢ÏÖÓÐÔ¶³ÌÁ¬½Ó(ͨ¹ý²ì¿´Ö¸¶¨µÄ»·¾³±äÁ¿)£¬×Ô¶¯´´½¨Ò»¸ö¹ýÂËÆ÷À´Æ¥ÅäÕâÖÖÁ¬½Ó¡£ÒÔ±ÜÃâ²¶×½Wireshark²¶×½Ô¶³ÌÁ¬½ÓͨÐÅ¡£ ÏÂÁл·¾³±äÁ¿¿ÉÒÔ½øÐзÖÎö SSH¡ª¡ªCONNECTION(ssh) [remote name]: 4.9. ÔÚ²¶×½¹ý³ÌÖÐ ²¶×½Ê±£¬»á³öÏÖÏÂÃæµÄ¶Ô»°¿ò ͼ 4.3. ²¶×½ÐÅÏ¢¶Ô»°¿ò ÉÏÊö¶Ô»°¿ò»áÏòÄãÏÔʾ²¶×½µ½°üµÄÊýÄ¿£¬²¶×½³ÖÐøÊ±¼ä¡£Ñ¡ÔñµÄ±»Í³¼ÆµÄÐÒéÎÞ·¨¸ü¸Ä(ʲôÄñÒâ˼£¿) Ìáʾ Õâ¸ö¶Ô»°¿ò¿ÉÒÔ±»Òþ²Ø£¬ÔÚǰ´ÎµÄ²¶×½Ñ¡Ïî¶Ô»°¿òÉèÖÃ\¼´¿É¡£ 4.9.1. Í£Ö¹²¶×½ ÔËÐÐÖеIJ¶×½Ï߳̿ÉÒÔÓÃÏÂÁз½·¨Í£Ö¹£º 1. ʹÓò¶×½ÐÅÏ¢¶Ô»°¿òÉϵÄ\ ×¢Òâ ²¶×½ÐÅÏ¢¶Ô»°¿òÓпÉÄܱ»Òþ²Ø£¬Èç¹ûÄãÑ¡ÔñÁË\ stop\°´Å¥Í£Ö¹¡£ 2. ʹÓò˵¥Ïî\3. ʹÓù¤¾ßÀ¸Ïî\ Stop\ Stop\ 4. ʹÓÿì½Ý¼ü:Ctrl+E 5. Èç¹ûÉèÖÃÁË´¥·¢Í£Ö¹µÄÌõ¼þ£¬²¶×½´ïµ½Ìõ¼þʱ»á×Ô¶¯Í£Ö¹¡£ 4.9.2. ÖØÐÂÆô¶¯²¶×½ ÔËÐÐÖеIJ¶×½½ø³Ì¿ÉÒÔ±»ÖØÐÂÆô¶¯¡£Õ⽫»áÒÆ³öÉϴβ¶×½µÄËùÓаü¡£Èç¹ûÄã²¶×½µ½Ò»Ð©Äã²»¸ÐÐËȤµÄ°ü£¬Äã²»Ïë±£ÁôËü£¬Õâ¸ö¹¦ÄÜÊ®·ÖÓÐÓá£ ÖØÐÂÆô¶¯ÊÇÒ»Ïî·½±ãµÄ¹¦ÄÜ£¬ÀàËÆÓÚÍ£Ö¹²¶×½ºó£¬Ôں̵ܶÄʱ¼äÄÚÁ¢¼´¿ªÊ¼²¶×½¡£ÒÔÏÂÁ½ÖÖ·½Ê½¿ÉÒÔʵÏÖÖØÐÂÆô¶¯²¶×½: 1. ʹÓò˵¥Ïî\2. ʹÓù¤¾ßÀ¸Ïî\ [12] Restart\ Restart\ ¼ÇµÃÔÚWindows°²×°ÄÇÒ»½Ú²ãÌáµ½Èç¹û×÷Ϊ·þÎñÆô¶¯¿ÉÒÔ±ÜÃâ·Ç¹ÜÀíÔ±ÎÞ·¨½øÐв¶×½£¬²»ÖªµÀ¶þÕßÄÜ·ñÏ໥ӡ֤¡£ [13] Íø¿¨ÔÚ¾ÖÓòÍøÄÚ»á½Óµ½ºÜ¶à²»ÊôÓÚ×Ô¼ºµÄ°ü£¬Ä¬ÈÏÇé¿öÏ£¬Íø¿¨»á²»¶ÔÕâЩ°ü½øÐд¦Àí¡£Ã²ËÆÉèÖÃΪÔÓÊÕģʽ£¬Wireshak»á¼àÌýËùÓеİü£¬µ«²¢²»×÷³öÏàÓ¦¡£ [14] ´ÖÂÔ²éÁËÒ»ÏÂ,δÕÒµ½¸Ã´ÊµÄºÏÊÊ·Òë,¶à¼ûÓÚWinpcapµÄÃèÊö£¬Èç¹û°Ñ¸Ãµ¥´Ê²ð·Ö£¬snap:µ¥Ôª£¬¿ìÕÕ£¬len:³¤¶È£¬Ëƺõ¾ÍÊǵ¥Î»³¤¶È£¬µ¥Ôª´óСµÄÒâ˼¡£ÔÚ¿´¿´¸Ã¶ÎÏÂÃæµÚ¶þ¸öÈç¹ûÖÐÌáµ½µÄsnapshot length,snaplenÓ¦¸ÃÊǶþÕߵļòдÐÎʽ£¬¿ìÕÕ³¤¶È