Ⅰ wireshark 怎么过滤 ip
滤器规则没host说滤器都认看滤器使用规则至于ip.addr == 192.168.3.23表达显示源ip址或者目ip址192.168.3.23所数回据包wireshark捕捉本身经该网答卡所数据包至于说想捕捉本机所包太明白啥意思难道N张网卡想通张网卡捕捉所网卡数据包想能张网卡默认捕捉本机所包
Ⅱ wireshark杩囨护瑙勫垯鏈夊摢浜
wireshark杩囨护瑙勫垯锛
涓銆両P杩囨护锛氬寘鎷鏉ユ簮IP鎴栬呯洰鏍嘔P绛変簬鏌愪釜IP
姣斿傦細ip.src addr==192.168.0.208 or ip.src addr eq 192.168.0.208 鏄剧ず鏉ユ簮IP
ip.dst addr==192.168.0.208 or ip.dst addr eq 192.168.0.208 鏄剧ず鐩鏍嘔P
浜屻佺鍙h繃婊わ細
姣斿傦細tcp.port eq 80 // 涓嶇$鍙f槸鏉ユ簮鐨勮繕鏄鐩鏍囩殑閮芥樉绀
tcp.port == 80
tcp.port eq 2722
tcp.port eq 80 or udp.port eq 80
tcp.dstport == 80 // 鍙鏄総cp鍗忚鐨勭洰鏍囩鍙80
tcp.srcport == 80 // 鍙鏄総cp鍗忚鐨勬潵婧愮鍙80
杩囨护绔鍙h寖鍥
tcp.port >= 1 and tcp.port 涓夈佸崗璁杩囨护锛歵cp
udp
arp
icmp
http
smtp
ftp
dns
msnms
ip
ssl
绛夌瓑
鎺掗櫎ssl鍖咃紝濡!ssl 鎴栬 not ssl
鍥涖佸寘闀垮害杩囨护锛
姣斿傦細
udp.length == 26 杩欎釜闀垮害鏄鎸噓dp鏈韬鍥哄畾闀垮害8鍔犱笂udp涓嬮潰閭e潡鏁版嵁鍖呬箣鍜
tcp.len >= 7 鎸囩殑鏄痠p鏁版嵁鍖(tcp涓嬮潰閭e潡鏁版嵁),涓嶅寘鎷瑃cp鏈韬
ip.len == 94 闄や簡浠ュお缃戝ご鍥哄畾闀垮害14,鍏跺畠閮界畻鏄痠p.len,鍗充粠ip鏈韬鍒版渶鍚
frame.len == 119 鏁翠釜鏁版嵁鍖呴暱搴,浠巈th寮濮嬪埌鏈鍚
浜斻乭ttp妯″紡杩囨护锛
渚嬪瓙:
http.request.method == 鈥淕ET鈥
http.request.method == 鈥淧OST鈥
http.request.uri == 鈥/img/logo-e.gif鈥
http contains 鈥淕ET鈥
http contains 鈥淗TTP/1.鈥
// GET鍖呭寘鍚鏌愬ご瀛楁
http.request.method == 鈥淕ET鈥 && http contains 鈥淗ost: 鈥
http.request.method == 鈥淕ET鈥 && http contains 鈥淯ser-Agent: 鈥
// POST鍖呭寘鍚鏌愬ご瀛楁
http.request.method == 鈥淧OST鈥 && http contains 鈥淗ost: 鈥
http.request.method == 鈥淧OST鈥 && http contains 鈥淯ser-Agent: 鈥
// 鍝嶅簲鍖呭寘鍚鏌愬ご瀛楁
http contains 鈥淗TTP/1.1 200 OK鈥 && http contains 鈥淐ontent-Type: 鈥
http contains 鈥淗TTP/1.0 200 OK鈥 && http contains 鈥淐ontent-Type: 鈥濆叚銆佽繛鎺ョ and / or
涓冦佽〃杈惧紡锛!(arp.src==192.168.1.1) and !(arp.dst.proto_ipv4==192.168.1.243)
鍏銆乪xpert.message鏄鐢ㄦ潵瀵筰nfo淇℃伅杩囨护锛屼富瑕侀厤鍚坈ontains鏉ヤ娇鐢