1. wireshark怎麼沒法添加過濾器
添加過濾器的方法:capture->option->capture-filter
如果不行你換個版本的軟體試試,有可能是軟體版本的問題
2. wireshark 怎樣過濾http協議內容
在wireshark軟體的那個filter框框裡面輸入http,就能只過濾HTTP協議的內容了。
3. wireshark榪囨護瑙勫垯鏈夊摢浜
wireshark榪囨護瑙勫垯錛
涓銆両P榪囨護錛氬寘鎷鏉ユ簮IP鎴栬呯洰鏍嘔P絳変簬鏌愪釜IP
姣斿傦細ip.src addr==192.168.0.208 or ip.src addr eq 192.168.0.208 鏄劇ず鏉ユ簮IP
ip.dst addr==192.168.0.208 or ip.dst addr eq 192.168.0.208 鏄劇ず鐩鏍嘔P
浜屻佺鍙h繃婊わ細
姣斿傦細tcp.port eq 80 // 涓嶇$鍙f槸鏉ユ簮鐨勮繕鏄鐩鏍囩殑閮芥樉紺
tcp.port == 80
tcp.port eq 2722
tcp.port eq 80 or udp.port eq 80
tcp.dstport == 80 // 鍙鏄総cp鍗忚鐨勭洰鏍囩鍙80
tcp.srcport == 80 // 鍙鏄総cp鍗忚鐨勬潵婧愮鍙80
榪囨護絝鍙h寖鍥
tcp.port >= 1 and tcp.port 涓夈佸崗璁榪囨護錛歵cp
udp
arp
icmp
http
smtp
ftp
dns
msnms
ip
ssl
絳夌瓑
鎺掗櫎ssl鍖咃紝濡!ssl 鎴栬 not ssl
鍥涖佸寘闀垮害榪囨護錛
姣斿傦細
udp.length == 26 榪欎釜闀垮害鏄鎸噓dp鏈韜鍥哄畾闀垮害8鍔犱笂udp涓嬮潰閭e潡鏁版嵁鍖呬箣鍜
tcp.len >= 7 鎸囩殑鏄痠p鏁版嵁鍖(tcp涓嬮潰閭e潡鏁版嵁),涓嶅寘鎷瑃cp鏈韜
ip.len == 94 闄や簡浠ュお緗戝ご鍥哄畾闀垮害14,鍏跺畠閮界畻鏄痠p.len,鍗充粠ip鏈韜鍒版渶鍚
frame.len == 119 鏁翠釜鏁版嵁鍖呴暱搴,浠巈th寮濮嬪埌鏈鍚
浜斻乭ttp妯″紡榪囨護錛
渚嬪瓙:
http.request.method == 鈥淕ET鈥
http.request.method == 鈥淧OST鈥
http.request.uri == 鈥/img/logo-e.gif鈥
http contains 鈥淕ET鈥
http contains 鈥淗TTP/1.鈥
// GET鍖呭寘鍚鏌愬ご瀛楁
http.request.method == 鈥淕ET鈥 && http contains 鈥淗ost: 鈥
http.request.method == 鈥淕ET鈥 && http contains 鈥淯ser-Agent: 鈥
// POST鍖呭寘鍚鏌愬ご瀛楁
http.request.method == 鈥淧OST鈥 && http contains 鈥淗ost: 鈥
http.request.method == 鈥淧OST鈥 && http contains 鈥淯ser-Agent: 鈥
// 鍝嶅簲鍖呭寘鍚鏌愬ご瀛楁
http contains 鈥淗TTP/1.1 200 OK鈥 && http contains 鈥淐ontent-Type: 鈥
http contains 鈥淗TTP/1.0 200 OK鈥 && http contains 鈥淐ontent-Type: 鈥濆叚銆佽繛鎺ョ and / or
涓冦佽〃杈懼紡錛!(arp.src==192.168.1.1) and !(arp.dst.proto_ipv4==192.168.1.243)
鍏銆乪xpert.message鏄鐢ㄦ潵瀵筰nfo淇℃伅榪囨護錛屼富瑕侀厤鍚坈ontains鏉ヤ嬌鐢
4. wireshark鎬庝箞娌℃硶娣誨姞榪囨護鍣
鏂規硶/姝ラ
榪囨護婧恑p銆佺洰鐨剗p銆傚湪wireshark鐨勮繃婊よ勫垯妗咶ilter涓杈撳叆榪囨護鏉′歡銆傚傛煡鎵劇洰鐨勫湴鍧涓192.168.101.8鐨勫寘錛宨p.dst==192.168.101.8錛涙煡鎵炬簮鍦板潃涓篿p.src==1.1.1.1錛
絝鍙h繃婊ゃ傚傝繃婊80絝鍙o紝鍦‵ilter涓杈撳叆錛宼cp.port==80錛岃繖鏉¤勫垯鏄鎶婃簮絝鍙e拰鐩鐨勭鍙d負80鐨勯兘榪囨護鍑烘潵銆備嬌鐢╰cp.dstport==80鍙榪囨護鐩鐨勭鍙d負80鐨勶紝tcp.srcport==80鍙榪囨護婧愮鍙d負80鐨勫寘錛
鍗忚榪囨護姣旇緝綆鍗曪紝鐩存帴鍦‵ilter妗嗕腑鐩存帴杈撳叆鍗忚鍚嶅嵆鍙錛屽傝繃婊HTTP鐨勫崗璁錛
http妯″紡榪囨護銆傚傝繃婊get鍖咃紝http.request.method=="GET",榪囨護post鍖咃紝http.request.method=="POST"錛
5
榪炴帴絎and鐨勪嬌鐢ㄣ傝繃婊や袱縐嶆潯浠舵椂錛屼嬌鐢╝nd榪炴帴錛屽傝繃婊ip涓192.168.101.8騫朵笖涓篽ttp鍗忚鐨勶紝ip.src==192.168.101.8 and http銆