免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 4715 | 回复: 1
打印 上一主题 下一主题

freebsd下tcpdump抓包结果分析 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2008-05-27 01:00 |只看该作者 |倒序浏览
23:23:42.494448 IP 192.168.0.104.51368 > 220.181.5.32.http: S 1976626103:1976626103(0) win 65535 <mss 1460,nop,wscale 0,nop,nop
,timestamp 8417217 0,sackOK,eol>
23:23:42.680345 IP 220.181.5.32.http > 192.168.0.104.51368: S 1126164847:1126164847(0) ack 1976626104 win 5792 <mss 1452,sackOK
,timestamp 291339246 8417217,nop,wscale 2>
23:23:42.680405 IP 192.168.0.104.51368 > 220.181.5.32.http: . ack 1 win 65535 <nop,nop,timestamp 8417403 291339246>
23:23:42.680567 IP 192.168.0.104.51368 > 220.181.5.32.http: P 1:472(471) ack 1 win 65535 <nop,nop,timestamp 8417404 291339246>
23:23:42.833863 IP 220.181.5.32.http > 192.168.0.104.51368: P 1:1065(1064) ack 39 win 65535
23:23:42.855278 IP 220.181.5.32.http > 192.168.0.104.51368: . ack 472 win 1716 <nop,nop,timestamp 291339421 8417404>
23:23:42.855333 IP 192.168.0.104.51368 > 220.181.5.32.http: . ack 1065 win 65535 <nop,nop,timestamp 8417578 291339421>
23:23:42.870610 IP 220.181.5.32.http > 192.168.0.104.51368: . 1:1409(140 ack 472 win 1716 <nop,nop,timestamp 291339423 841740
4>
23:23:42.883701 IP 220.181.5.32.http > 192.168.0.104.51368: . 1409:2817(140 ack 472 win 1716 <nop,nop,timestamp 291339423 841
7404>
23:23:42.883756 IP 192.168.0.104.51368 > 220.181.5.32.http: . ack 2817 win 64488 <nop,nop,timestamp 8417607 291339423>
23:23:42.905938 IP 192.168.0.104.60600 > 121.32.136.231.http: S 3947955703:3947955703(0) win 65535 <mss 1460,nop,wscale 0,nop,n
op,timestamp 8417629 0,sackOK,eol>
23:23:42.929682 IP 121.32.136.231.http > 192.168.0.104.60600: S 2953600786:2953600786(0) ack 3947955704 win 16384 <mss 1452,nop
,wscale 0,nop,nop,timestamp 0 0,nop,nop,sackOK>
23:23:42.929741 IP 192.168.0.104.60600 > 121.32.136.231.http: . ack 1 win 65535 <nop,nop,timestamp 8417653 0>
23:23:42.930081 IP 192.168.0.104.60600 > 121.32.136.231.http: P 1:482(481) ack 1 win 65535 <nop,nop,timestamp 8417653 0>
23:23:42.946209 IP 192.168.0.104.51368 > 220.181.5.32.http: F 472:472(0) ack 2817 win 65535 <nop,nop,timestamp 8417669 29133942
3>
23:23:42.962775 IP 220.181.5.32.http > 192.168.0.104.51368: . 2817:4225(140 ack 472 win 1716 <nop,nop,timestamp 291339515 841
7607>
23:23:42.962832 IP 192.168.0.104.51368 > 220.181.5.32.http: R 1976626575:1976626575(0) win 0
23:23:42.976096 IP 220.181.5.32.http > 192.168.0.104.51368: . 4225:5633(140 ack 472 win 1716 <nop,nop,timestamp 291339515 841
7607>
23:23:42.976119 IP 192.168.0.104.51368 > 220.181.5.32.http: R 1976626575:1976626575(0) win 0
23:23:42.989407 IP 220.181.5.32.http > 192.168.0.104.51368: . 5633:7041(140 ack 472 win 1716 <nop,nop,timestamp 291339515 841
7607>
23:23:42.989446 IP 192.168.0.104.51368 > 220.181.5.32.http: R 1976626575:1976626575(0) win 0
23:23:42.999901 IP 121.32.136.231.http > 192.168.0.104.60600: FP 1:968(967) ack 482 win 65054 <nop,nop,timestamp 36720840 84176

53>
23:23:42.999953 IP 192.168.0.104.60600 > 121.32.136.231.http: . ack 969 win 65273 <nop,nop,timestamp 8417723 36720840>
23:23:43.012800 IP 192.168.0.104.59402 > 121.32.136.231.http: S 1086537433:1086537433(0) win 65535 <mss 1460,nop,wscale 0,nop,n
op,timestamp 8417736 0,sackOK,eol>
23:23:43.028852 IP 192.168.0.104.60600 > 121.32.136.231.http: F 482:482(0) ack 969 win 65535 <nop,nop,timestamp 8417752 3672084
0>
23:23:43.120174 IP 121.32.136.231.http > 192.168.0.104.59402: S 1414591349:1414591349(0) ack 1086537434 win 16384 <mss 1452,nop
,wscale 0,nop,nop,timestamp 0 0,nop,nop,sackOK>
23:23:43.120238 IP 192.168.0.104.59402 > 121.32.136.231.http: . ack 1 win 65535 <nop,nop,timestamp 8417843 0>
23:23:43.120426 IP 192.168.0.104.59402 > 121.32.136.231.http: P 1:771(770) ack 1 win 65535 <nop,nop,timestamp 8417844 0>
23:23:43.121385 IP 121.32.136.231.http > 192.168.0.104.60600: . ack 483 win 65054 <nop,nop,timestamp 36720842 8417752>
23:23:43.340601 IP 121.32.136.231.http > 192.168.0.104.59402: FP 1:412(411) ack 771 win 64765 <nop,nop,timestamp 36720844 84177

上面是freebsd下抓包的结果,很多地方都不是太明白,尤其是加颜色的部分,希望大家能够指点一下。最好是能够将整个流程都说一下说不定就成为精华了。谢谢!

论坛徽章:
0
2 [报告]
发表于 2008-05-27 15:16 |只看该作者
是太难了??!!
还是太简单阿!
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP