linux tcpdump 抓包

安装命令:yum install tcpdump -y

 

2.tcpdump命令

NAME

       tcpdump - dump traffic on a network

SYNOPSIS

       tcpdump [ -AbdDefhHIJKlLnNOpqStuUvxX# ] [ -B buffer_size ]

               [ -c count ]

               [ -C file_size ] [ -G rotate_seconds ] [ -F file ]

               [ -i interface ] [ -j tstamp_type ] [ -m module ] [ -M secret ]

               [ --number ] [ -Q|-P in|out|inout ]

               [ -r file ] [ -V file ] [ -s snaplen ] [ -T type ] [ -w file ]

               [ -W filecount ]

               [ -E spi@ipaddr algo:secret,...  ]

               [ -y datalinktype ] [ -z postrotate-command ] [ -Z user ]

               [ --time-stamp-precision=tstamp_precision ]

               [ --immediate-mode ] [ --version ]

               [ expression ]

 

3.基本应用

 

  • 过滤主机IP:tcpdump -i eth0  host 104.238.132.163  说明:过滤经过网卡0,且主机IP为104.238.132.163的数据包
  • 过滤端口:tcpdump -i eth0 det port 1234     说明:过滤经过网卡0,且端口为1234的数据包
  • 过滤指定协议的数据包:tcpdump -i eth0 udp   说明:过滤经过网卡0的udp协议数据包
  • 抓取本地环回数据包:tcpdump -i lo udp   说明:主要区别就是抓取的网卡,本地环回则取,lo,其它内容不变
  • 抓取特定类型的数据包:   
    • 抓取所有经过网卡1的SYN类型数据包 :tcpdump -i eth0 'tcp[tcpflags] = tcp-syn'
  • 逻辑过滤语句:tcpdump -i eth1 '((tcp) and ((dst net 172.16) and (not dst host 192.168.1.200)))' 说明:抓取所有经过网卡1,目的网络是172.16,但目的主机不是192.168.1.200的TCP数据 
  • 抓包存取: tcpdump -i eth1 host 172.16.7.206 and port 80 -w /tmp/xxx.cap  说明:抓取所有经过网卡1,目的主机为
  • 172.16.7.206的端口80的网络数据并存储

 4. 遇到的问题

  1. tcpdump: packet printing is not supported for link type NFLOG: use -w               
    是因为默认网卡的问题,则通过ifconfig 查看一下当前的网卡信息
    
       
       
    1. ens33: flags=4163 <UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
    2. inet 192.168.6.128 netmask 255.255.255.0 broadcast 192.168.6.255
    3. inet6 fe80::ef0d:79fa:8ef6:3358 prefixlen 64 scopeid 0x20 <link>
    4. ether 00:0c:29:6e:fe:db txqueuelen 1000 (Ethernet)
    5. RX packets 1895 bytes 127294 (124.3 KiB)
    6. RX errors 0 dropped 0 overruns 0 frame 0
    7. TX packets 3245 bytes 803811 (784.9 KiB)
    8. TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
    9. lo: flags=73 <UP,LOOPBACK,RUNNING> mtu 65536
    10. inet 127.0.0.1 netmask 255.0.0.0
    11. inet6 ::1 prefixlen 128 scopeid 0x10 <host>
    12. loop txqueuelen 1000 (Local Loopback)
    13. RX packets 64 bytes 5568 (5.4 KiB)
    14. RX errors 0 dropped 0 overruns 0 frame 0
    15. TX packets 64 bytes 5568 (5.4 KiB)
    16. TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
    <p>对应的网卡是,ens33 ,则执行,tcpdump -i ens33 即可</p>
    </li>
    <li>抓包并写入文件中:tcpdump -i ens33 -c 5000 -w one.cap&nbsp;此条命令的意思是,监听ens33网卡,抓5000个包停止,并将文件写入one.cap文件中</li>
    <li>停止抓包:ctrl + c&nbsp; 或者 找到tcpdump 的进程id pid ,然后通过 kill -9 [pid] 去关闭
    <p>&nbsp;</p>
    </li>
    
<div class="content" style="width: 712px;">
	<a href="https://blog.csdn.net/RunBoying/article/details/7166378" target="_blank" title="tcpdump抓包规则常用命令">
	<h4 class="text-truncate oneline" style="width: 552px;">
			<em>tcpdump</em><em>抓包</em>规则常用命令		</h4>
	<div class="info-box d-flex align-content-center">
		<p class="date-and-readNum oneline">
			<span class="date hover-show">12-30</span>
			<span class="read-num hover-hide">
				阅读数 
				3万+</span>
			</p>
		</div>
	</a>
	<p class="content" style="width: 712px;">
		<a href="https://blog.csdn.net/RunBoying/article/details/7166378" target="_blank" title="tcpdump抓包规则常用命令">
			<span class="desc oneline">转载自:http://blog.sina.com.cn/s/blog_4a071ed80100sv13.html&nbsp;下面的例子全是以抓取eth0接口为例,如果不加”-ieth0”是表示抓取所有的接口包括...</span>
		</a>
		<span class="blog_title_box oneline ">
								<span class="type-show type-show-blog type-show-after">博文</span>
										<a target="_blank" href="https://blog.csdn.net/RunBoying">来自:	<span class="blog_title"> 工作记录--创造或收集原创</span></a>
											</span>
	</p>
</div>
</div>
<div class="comment-edit-box d-flex">
	<a id="commentsedit"></a>
	<div class="user-img">
		<a href="//me.csdn.net/u014576908" target="_blank">
			<img class="" src="https://avatar.csdn.net/D/B/B/3_u014576908.jpg">
		</a>
	</div>
	<form id="commentform">
		<input type="hidden" id="comment_replyId">
		<textarea class="comment-content" name="comment_content" id="comment_content" placeholder="想对作者说点什么"></textarea>
		<div class="opt-box"> <!-- d-flex -->
			<div id="ubbtools" class="add_code">
				<a href="#insertcode" code="code" target="_self"><i class="icon iconfont icon-daima"></i></a>
			</div>
			<input type="hidden" id="comment_replyId" name="comment_replyId">
			<input type="hidden" id="article_id" name="article_id" value="80970312">
			<input type="hidden" id="comment_userId" name="comment_userId" value="">
			<input type="hidden" id="commentId" name="commentId" value="">
			<div style="display: none;" class="csdn-tracking-statistics tracking-click" data-report-click="{&quot;mod&quot;:&quot;popu_384&quot;,&quot;dest&quot;:&quot;&quot;}"><a href="#" target="_blank" class="comment_area_btn">发表评论</a></div>
			<div class="dropdown" id="myDrap">
				<a class="dropdown-face d-flex align-items-center" data-toggle="dropdown" role="button" aria-haspopup="true" aria-expanded="false">
				<div class="txt-selected text-truncate">添加代码片</div>
				<svg class="icon d-block" aria-hidden="true">
					<use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#csdnc-triangledown"></use>
				</svg>
				</a>
				<ul class="dropdown-menu" id="commentCode" aria-labelledby="drop4">
					<li><a data-code="html">HTML/XML</a></li>
					<li><a data-code="objc">objective-c</a></li>
					<li><a data-code="ruby">Ruby</a></li>
					<li><a data-code="php">PHP</a></li>
					<li><a data-code="csharp">C</a></li>
					<li><a data-code="cpp">C++</a></li>
					<li><a data-code="javascript">JavaScript</a></li>
					<li><a data-code="python">Python</a></li>
					<li><a data-code="java">Java</a></li>
					<li><a data-code="css">CSS</a></li>
					<li><a data-code="sql">SQL</a></li>
					<li><a data-code="plain">其它</a></li>
				</ul>
			</div>  
			<div class="right-box">
				<span id="tip_comment" class="tip">还能输入<em>1000</em>个字符</span>
				<input type="button" class="btn btn-sm btn-cancel d-none" value="取消回复">
				<input type="submit" class="btn btn-sm btn-red btn-comment" value="发表评论">
			</div>
		</div>
	</form>
</div>

	<div class="comment-list-container">
	<a id="comments"></a>
	<div class="comment-list-box">
	</div>
	<div id="commentPage" class="pagination-box d-none"></div>
	
</div>
Linux系统-tcpdump常用抓包命令

07-24 阅读数 4万+

linux,tcpdump 博文 来自: shuaixio的博客

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_59" data-pid="59" data-report-click="{&quot;mod&quot;:&quot;kp_popu_59-78&quot;,&quot;keyword&quot;:&quot;&quot;}"><script type="text/javascript">
(function() {
    var s = "_" + Math.random().toString(36).slice(2);
    document.write('<div style="" id="' + s + '"></div>');
    (window.slotbydup = window.slotbydup || []).push({
        id: "u3491668",
        container:  s
    });
})();

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_60" data-pid="60" data-report-view="{&quot;mod&quot;:&quot;kp_popu_60-43&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_60-43&quot;,&quot;keyword&quot;:&quot;&quot;}"><div class="mediav_ad"><newsfeed class="newsfeed QIHOO__WEB__SO__1565861083795_929" id="QIHOO__WEB__SO__1565861083795_929" style="display:block;margin:0;padding:0;border:none;width:900px;height:84px;overflow-y:hidden;overflow-x:hidden;position:relative;text-align:left;"><info-div id="QIHOO__WEB__SO__1565861083795_929-info" style="zoom:1"><info-div class="QIHOO__WEB__SO__1565861083795_929 singleImage clk" data-href="https://ssxd.mediav.com/s?type=2&amp;r=20&amp;mv_ref=blog.csdn.net&amp;enup=CAABDheVvQgAAr2VFw4A&amp;mvid=MDkyNDkyODE2MTU1MzE2MTIwNDAwMTk&amp;bid=1387bd371c888c7e&amp;price=AAAAAF1VJNwAAAAAAAra0Kn4CQCGGam7rFisfA==&amp;finfo=DAABCAABAAABPwgAAgAAATIEAAM/SaKDMGiQjgAIAAIAAAADCgADX6sdXu6VujQIAAQAAAFVBgAGG4sGAAoAAAgADgAAAB4KAA8AAAAAADrmIwA&amp;ugi=FcTgigEVyNtrTBUCFUAVSBUAABW+6c2SDRaECBXIARaAvO+ajonIBRwWvuayjeKEpIAoFQAAAA&amp;uai=FeTGlAIlAhUEFuifjv23kYqrvwEV8gglt7DrmgglABUaFAAcFpa+1p6NoYKvOxUAAAA&amp;ubi=FeLnJBXaoK8CFZ69sxYVpPumWxUGFSIW/oHH+hQW6J+j5MHXjqu/ATQCFrDgECUGFYSyobkPFZ4BFQAkFBbi5yQA&amp;clickid=0&amp;cpx=__OFFSET_X__&amp;cpy=__OFFSET_Y__&amp;cs=__EVENT_TIME_START__&amp;ce=__EVENT_TIME_END__&amp;ldtype=2&amp;csign2=ELYW1NkCL3Z=&amp;url=http%3A%2F%2Fbaidu.code.mytanwan.com%2Fhtmlcode%2F26374.html" data-pv="https://ssxd.mediav.com/s?type=1&amp;r=20&amp;tid=MDkyNDkyODE2MTU1MzE2MTIwNDAwMTk&amp;finfo=DAABCAABAAABPwgAAgAAATIEAAM/SaKDMGiQjgAIAAIAAAADCgADX6sdXu6VujQIAAQAAAFVBgAGG4sGAAoAAAgADgAAAB4KAA8AAAAAADrmIwA&amp;mv_ref=blog.csdn.net&amp;enup=CAABDheVvQgAAr2VFw4A&amp;mvid=MDkyNDkyODE2MTU1MzE2MTIwNDAwMTk&amp;bid=1387bd371c888c7e&amp;ugi=FcTgigEVyNtrTBUCFUAVSBUAABW+6c2SDRaECBXIARaAvO+ajonIBRwWvuayjeKEpIAoFQAAAA&amp;uai=FeTGlAIlAhUEFuifjv23kYqrvwEV8gglt7DrmgglABUaFAAcFpa+1p6NoYKvOxUAAAA&amp;ubi=FeLnJBXaoK8CFZ69sxYVpPumWxUGFSIW/oHH+hQW6J+j5MHXjqu/ATQCFrDgECUGFYSyobkPFZ4BFQAkFBbi5yQA&amp;ds=1&amp;price=AAAAAF1VJNwAAAAAAAra0Kn4CQCGGam7rFisfA==,https://max-l.mediav.com/rtb?type=2&amp;ver=1&amp;v=CGQSEDEzODdiZDM3MWM4ODhjN2UYsqOKASCisEUoAWIXMDkyNDkyODE2MTU1MzE2MTIwNDAwMTmIAQA&amp;k=PUGunAAAAAA=&amp;w=AAAAAF1VJNwAAAAAAAra-FbqwV0CGapzDvM3zg&amp;i=OB9-gmu09DhE&amp;exp=BQBECgBEAQJEEgJEEwJEEABDIwBD&amp;z=1" data-clk="https://max-l.mediav.com/rtb?type=3&amp;ver=1&amp;v=CGQSEDEzODdiZDM3MWM4ODhjN2UYsqOKASCisEUoAWIXMDkyNDkyODE2MTU1MzE2MTIwNDAwMTlwAA&amp;k=xt+u7AAAAAA=&amp;i=OB9-gmu09DhE&amp;exp=BQBECgBEAQJEEgJEEwJEEABDIwBD&amp;x=__OFFSET_X__&amp;y=__OFFSET_Y__&amp;st=__EVENT_TIME_START__&amp;et=__EVENT_TIME_END__&amp;adw=__ADSPACE_W__&amp;adh=__ADSPACE_H__&amp;tc=&amp;turl=">
<info-div class="wrap">
    <info-div class="singleImage-img singleImage-img-left">
        <info-div class="img" style="background-image:url(https://s3m.mediav.com/galileo/301553-267cf6b7dafaed55b2b9d4f69f1ede29.gif)"><info-div class="ads-tag"></info-div></info-div>
    </info-div>
    <info-div class="singleImage-body singleImage-body-left">
        <info-div class="singleImage-title">别再玩假传奇了!这款传奇爆率9.8,你找到充值入口算我输!</info-div>
        <info-div class="singleImage-desc">贪玩游戏 · 顶新</info-div>
    </info-div>
linux抓包命令--tcpdump的使用
01-04

linux下抓包命令--tcpdump的使用 下载

		<div class="recommend-item-box blog-expert-recommend-box">
		<div class="d-flex">
			<div class="blog-expert-recommend">
				<div class="blog-expert">
					<div class="blog-expert-flexbox"></div>
				</div>
			</div>
		</div>
	</div>
linux 抓包工具---Tcpdump
10-17

Tcpdump主要是截获通过本机网络接口的数据,用以分析。Nmap是强大的端口扫描工具,可扫描任何主机或网络。Netstat可用来检查本机当前提供的服务及状态。这三者各有所长,结合起来,就可以比较透彻 下载

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_61" data-pid="61" data-report-view="{&quot;mod&quot;:&quot;kp_popu_61-622&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_61-622&quot;,&quot;keyword&quot;:&quot;&quot;}"><div><iframe width="852" frameborder="0" height="66" scrolling="no" src="https://pos.baidu.com/s?hei=66&amp;wid=852&amp;di=u3600846&amp;ltu=https%3A%2F%2Fblog.csdn.net%2Fbolatu_youshang%2Farticle%2Fdetails%2F80970312&amp;psi=926363e12eb71de420dbb2d65433202d&amp;par=1920x1040&amp;ccd=24&amp;pcs=1903x921&amp;cpl=14&amp;dri=0&amp;pss=1903x5712&amp;dtm=HTML_POST&amp;ltr=https%3A%2F%2Fwww.baidu.com%2Flink%3Furl%3DOgD5RSgxeBl9TmUub_4HSz4R6HDQKi-WatQLmrV2KfV4cxr3lLBgo5tOBylqLMGDoyCeUFnPlsLHg10IXxoGtXy66lVffOiU9uhG_ytji1S%26wd%3D%26eqid%3Dd72980f300091fcf000000065d552433&amp;chi=1&amp;cja=false&amp;exps=111000,119009,110011&amp;cfv=0&amp;tlm=1565861083&amp;tpr=1565861083987&amp;dis=0&amp;dc=3&amp;prot=2&amp;cdo=-1&amp;ari=2&amp;col=zh-CN&amp;tcn=1565861084&amp;dai=5&amp;ps=3753x602&amp;cec=UTF-8&amp;cce=true&amp;ant=0&amp;pis=-1x-1&amp;drs=1&amp;cmi=18&amp;ti=linux%20tcpdump%20%E6%8A%93%E5%8C%85&amp;psr=1920x1080"></iframe></div><script type="text/javascript" src="//rabc1.iteye.com/common/web/production/79m9.js?f=aszggcwz"></script></div></div>
<div class="recommend-item-box recommend-ad-box"><div id="kp_box_62" data-pid="62" data-report-view="{&quot;mod&quot;:&quot;kp_popu_62-623&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_62-623&quot;,&quot;keyword&quot;:&quot;&quot;}"><script type="text/javascript">
(function() {
    var s = "_" + Math.random().toString(36).slice(2);
    document.write('<div style="" id="' + s + '"></div>');
    (window.slotbydup = window.slotbydup || []).push({
        id: "u3600849",
        container:  s
    });
})();

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_63" data-pid="63" data-report-view="{&quot;mod&quot;:&quot;kp_popu_63-1405&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_63-1405&quot;,&quot;keyword&quot;:&quot;&quot;}"><script type="text/javascript">
    (function() {
        var s = "_" + Math.random().toString(36).slice(2);
        document.write('<div style="" id="' + s + '"></div>');
        (window.slotbydup = window.slotbydup || []).push({
            id: "u4221910",
            container: s
        });
    })();

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_64" data-pid="64" data-report-view="{&quot;mod&quot;:&quot;kp_popu_64-1379&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_64-1379&quot;,&quot;keyword&quot;:&quot;&quot;}"><script type="text/javascript">
    (function() {
        var s = "_" + Math.random().toString(36).slice(2);
        document.write('<div style="" id="' + s + '"></div>');
        (window.slotbydup = window.slotbydup || []).push({
            id: "u4221811",
            container: s
        });
    })();

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_65" data-pid="65" data-report-view="{&quot;mod&quot;:&quot;kp_popu_65-1378&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_65-1378&quot;,&quot;keyword&quot;:&quot;&quot;}"><script type="text/javascript">
    (function() {
        var s = "_" + Math.random().toString(36).slice(2);
        document.write('<div style="" id="' + s + '"></div>');
        (window.slotbydup = window.slotbydup || []).push({
            id: "u4221803",
            container: s
        });
    })();

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_66" data-pid="66" data-report-view="{&quot;mod&quot;:&quot;kp_popu_66-87&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_66-87&quot;,&quot;keyword&quot;:&quot;&quot;}"><div class="mediav_ad"><newsfeed class="newsfeed QIHOO__WEB__SO__1565861084061_630" id="QIHOO__WEB__SO__1565861084061_630" style="display:block;margin:0;padding:0;border:none;width:852px;height:60px;overflow-y:hidden;overflow-x:hidden;position:relative;text-align:left;"><info-div id="QIHOO__WEB__SO__1565861084061_630-info" style="zoom:1"><info-div class="QIHOO__WEB__SO__1565861084061_630 singleImage clk" data-href="https://ssxd.mediav.com/s?type=2&amp;r=20&amp;mv_ref=blog.csdn.net&amp;enup=CAABDheVvQgAAr2VFw4A&amp;mvid=MDkyNDkyODE2MTU1MzE2MTIwNDAwMTk&amp;bid=1387bd371c888c7e&amp;price=AAAAAF1VJNwAAAAAAArbeU3/morxFq3Si5cvXg==&amp;finfo=DAABCAABAAAAuggAAgAAAIkEAAM/VaMq3ajcHAAIAAIAAAADCgADX6smdjY4OJQIAAQAAACNBgAGG4sGAAoAAAgADgAAAB4KAA8AAAAAADrmIgA&amp;ugi=FcTgigEVyNtrTBUCFUAVSBUAABW+6c2SDRaECBXIARaAvO+ajonIBRwWvuayjeKEpIAoFQAAAA&amp;uai=FeTGlAIlAhUEFuifjv23kYqrvwEV8gglt7DrmgglABUaFAAcFpa+1p6NoYKvOxUAAAA&amp;ubi=FZDmJBW+2sYCFdbnqBcVjIL4WxUGFSIWmo3H+hQW6J+4y8udk6u/ATQEFrDgECUGFer77O4DFZ4BFQAkFBaQ5iQA&amp;clickid=0&amp;cpx=__OFFSET_X__&amp;cpy=__OFFSET_Y__&amp;cs=__EVENT_TIME_START__&amp;ce=__EVENT_TIME_END__&amp;ldtype=2&amp;csign2=OpO4Um1u22-=&amp;url=http%3A%2F%2Fy.code.17tanwan.com%2Fhtmlcode%2F37386.html" data-pv="https://ssxd.mediav.com/s?type=1&amp;r=20&amp;tid=MDkyNDkyODE2MTU1MzE2MTIwNDAwMTk&amp;finfo=DAABCAABAAAAuggAAgAAAIkEAAM/VaMq3ajcHAAIAAIAAAADCgADX6smdjY4OJQIAAQAAACNBgAGG4sGAAoAAAgADgAAAB4KAA8AAAAAADrmIgA&amp;mv_ref=blog.csdn.net&amp;enup=CAABDheVvQgAAr2VFw4A&amp;mvid=MDkyNDkyODE2MTU1MzE2MTIwNDAwMTk&amp;bid=1387bd371c888c7e&amp;ugi=FcTgigEVyNtrTBUCFUAVSBUAABW+6c2SDRaECBXIARaAvO+ajonIBRwWvuayjeKEpIAoFQAAAA&amp;uai=FeTGlAIlAhUEFuifjv23kYqrvwEV8gglt7DrmgglABUaFAAcFpa+1p6NoYKvOxUAAAA&amp;ubi=FZDmJBW+2sYCFdbnqBcVjIL4WxUGFSIWmo3H+hQW6J+4y8udk6u/ATQEFrDgECUGFer77O4DFZ4BFQAkFBaQ5iQA&amp;ds=2&amp;price=AAAAAF1VJNwAAAAAAArbeU3/morxFq3Si5cvXg==,https://max-l.mediav.com/rtb?type=2&amp;ver=1&amp;v=CGQSEDEzODdiZDM3MWM4ODhjN2UYsqOKASCisEUoAmIXMDkyNDkyODE2MTU1MzE2MTIwNDAwMTmIAQA&amp;k=nBOpPQAAAAA=&amp;w=AAAAAF1VJNwAAAAAAArbpFTCD9j8hhk9sEpwew&amp;i=OBD-gmu09Dhx&amp;exp=BQBECgBEAQJEEgJEEwJEEABDIwBD&amp;z=1" data-clk="https://max-l.mediav.com/rtb?type=3&amp;ver=1&amp;v=CGQSEDEzODdiZDM3MWM4ODhjN2UYsqOKASCisEUoAmIXMDkyNDkyODE2MTU1MzE2MTIwNDAwMTlwAA&amp;k=5rbnZQAAAAA=&amp;i=OBD-gmu09Dhx&amp;exp=BQBECgBEAQJEEgJEEwJEEABDIwBD&amp;x=__OFFSET_X__&amp;y=__OFFSET_Y__&amp;st=__EVENT_TIME_START__&amp;et=__EVENT_TIME_END__&amp;adw=__ADSPACE_W__&amp;adh=__ADSPACE_H__&amp;tc=&amp;turl=">
<info-div class="wrap">
    <info-div class="singleImage-img singleImage-img-left">
        <info-div class="img" style="background-image:url(https://s3m.mediav.com/galileo/301448-abeeb273809c18bd15e1df9bcf4a4f25.gif)"><info-div class="ads-tag"></info-div></info-div>
    </info-div>
    <info-div class="singleImage-body singleImage-body-left">
        <info-div class="singleImage-title">陈小春哭诉:员村土豪怒砸2亿请他代言这款0充值传奇!真经典!</info-div>
        <info-div class="singleImage-desc">贪玩游戏 · 顶新</info-div>
    </info-div>
<div class="recommend-item-box recommend-box-ident recommend-download-box clearfix" data-report-view="{&quot;mod&quot;:&quot;popu_614&quot;,&quot;dest&quot;:&quot;https://download.csdn.net/download/zhangliang_571/9539014&quot;,&quot;strategy&quot;:&quot;BlogCommendFromQuerySearch&quot;,&quot;index&quot;:&quot;43&quot;}" data-report-click="{&quot;mod&quot;:&quot;popu_614&quot;,&quot;dest&quot;:&quot;https://download.csdn.net/download/zhangliang_571/9539014&quot;,&quot;strategy&quot;:&quot;BlogCommendFromQuerySearch&quot;,&quot;index&quot;:&quot;43&quot;}">
	<a href="https://download.csdn.net/download/zhangliang_571/9539014" target="_blank">
		<div class="content clearfix">
			<div class="">
				<h4 class="text-truncate oneline clearfix">
					ftp 客户端实现,及<em>tcpdump</em> <em>抓包</em>过程					</h4>
				<span class="data float-right">06-02</span>
			</div>
			<div class="desc oneline">
					ftp 客户端实现,及tcpdump 抓包过程				</div>
			<span class="type-show type-show-download">下载</span>
		</div>
	</a>
</div>

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_67" data-pid="67" data-report-view="{&quot;mod&quot;:&quot;kp_popu_67-658&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_67-658&quot;,&quot;keyword&quot;:&quot;&quot;}"><script type="text/javascript">
(function() {
    var s = "_" + Math.random().toString(36).slice(2);
    document.write('<div style="" id="' + s + '"></div>');
    (window.slotbydup = window.slotbydup || []).push({
        id: "u3573058",
        container:  s
    });
})();

tcpdump中的Flags [S.]和Flags [.]是什么意思?------顺便看看三次握手包

06-27 阅读数 1万+

我们用telnet发起tcp连接,建立三次握手,抓包来看看:xxxxxx$sudotcpdump-ianyport19006-Xnlps0tcpdump:verboseoutputsuppressed... 博文 来自: stpeace的专栏

利用python脚本执行tcpdump抓包,支持传参、并发抓取多个包、文件循环覆盖抓取

11-07 阅读数 438

#!/usr/bin/envpython#AUTH:wangshengke@kedacom.com&amp;quot;&amp;quot;&amp;quot;tcpdump-iany-s0-w/opt... 博文

<div class="recommend-item-box recommend-ad-box"><div id="kp_box_68" data-pid="68" data-report-view="{&quot;mod&quot;:&quot;kp_popu_68-625&quot;,&quot;keyword&quot;:&quot;&quot;}" data-report-click="{&quot;mod&quot;:&quot;kp_popu_68-625&quot;,&quot;keyword&quot;:&quot;&quot;}"><div style=""><iframe width="852" frameborder="0" height="60" scrolling="no" src="//pos.baidu.com/s?hei=60&amp;wid=852&amp;di=u3565460&amp;ltu=https%3A%2F%2Fblog.csdn.net%2Fbolatu_youshang%2Farticle%2Fdetails%2F80970312&amp;psi=926363e12eb71de420dbb2d65433202d&amp;ps=7181x602&amp;psr=1920x1080&amp;cmi=18&amp;cdo=-1&amp;cce=true&amp;tcn=1565861084&amp;drs=1&amp;prot=2&amp;chi=1&amp;dis=0&amp;tpr=1565861083987&amp;ltr=https%3A%2F%2Fwww.baidu.com%2Flink%3Furl%3DOgD5RSgxeBl9TmUub_4HSz4R6HDQKi-WatQLmrV2KfV4cxr3lLBgo5tOBylqLMGDoyCeUFnPlsLHg10IXxoGtXy66lVffOiU9uhG_ytji1S%26wd%3D%26eqid%3Dd72980f300091fcf000000065d552433&amp;pcs=1903x921&amp;exps=111000,118009,110011&amp;tlm=1565861084&amp;cpl=14&amp;ti=linux%20tcpdump%20%E6%8A%93%E5%8C%85&amp;dai=8&amp;dtm=HTML_POST&amp;col=zh-CN&amp;ccd=24&amp;ant=0&amp;cfv=0&amp;pis=-1x-1&amp;ari=2&amp;cja=false&amp;cec=UTF-8&amp;par=1920x1040&amp;pss=1903x7234&amp;dri=0&amp;dc=3"></iframe></div><script type="text/javascript" src="//rabc1.iteye.com/common/openjs/m022.js?hcuzbzy=bi"></script></div></div>
                        <div class="recommend-loading-box">
            <img src="https://csdnimg.cn/release/phoenix/images/feedLoading.gif">
        </div>
        <div class="recommend-end-box" style="display: block;">
            <p class="text-center">没有更多推荐了,<a href="https://blog.csdn.net/" class="c-blue c-blue-hover c-blue-focus">返回首页</a></p>
        </div>
    </div>
</main>
Logo

更多推荐