- 论坛徽章:
- 0
|
11:39:53.076222 IP (tos 0x0, ttl 128, id 17, offset 0, flags [none], proto 17, length: 96) 192.168.1.112.netbios-ns > 192.168.1.255.netbios-ns:
>>> NBT UDP PACKET(137): REGISTRATION; REQUEST; BROADCAST
TrnID=0x8002
OpCode=5
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=1
QuestionRecords:
Name=F0AC6E9940EF48E NameType=0x20 (Server)
QuestionType=0x20
QuestionClass=0x1
ResourceRecords:
Name=F0AC6E9940EF48E NameType=0x20 (Server)
ResType=0x20
ResClass=
WARNING: Short packet. Try increasing the snap length
11:39:53.826142 IP (tos 0x0, ttl 128, id 19, offset 0, flags [none], proto 17, length: 96) 192.168.1.112.netbios-ns > 192.168.1.255.netbios-ns:
>>> NBT UDP PACKET(137): REGISTRATION; REQUEST; BROADCAST
TrnID=0x8002
OpCode=5
NmFlags=0x1
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=1
QuestionRecords:
Name=F0AC6E9940EF48E NameType=0x20 (Server)
QuestionType=0x20
QuestionClass=0x1
我不用-vv参数能够看到很多类似192.168.1.116.netbios-dgm > 192.168.1.255.netbios-dgm:这样的包,有时候感觉其发包规律很不正常——比如在一个比较长的时间内,某台机器会不断地高频率发这种包,这种情况下,该如何分析包呢?
请教各位。 |
|