- 论坛徽章:
- 0
|
下面抓取的是从linux pc SSH登录服务过程的数据包,由于80端口的数据包不好抓取;防火墙IP、服务器IP域名非真实的,请各位见谅,www.xxx.com外部IP是10.0.0.10,内部IP是192.168.1.15;这是linux pc访问服务器的大概路径
linux pc(host45) --> firewall --> router --> router --> firewall(crea-an/172.16.10.10) --> Internet --> www.xxx.com(10.0.0.10,ssh端口是30022)
一、在linux pc上抓数据包
[root@host45 root]# tcpdump -f -ieth0 -vs0 -f -w linux.pcap \(dst or src 10.0.0.10\) and \(! port 80\)
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
8 packets captured
16 packets received by filter
0 packets dropped by kernel
在linux pc上查看抓取的数据包
[root@host45 root]# tcpdump -r linux.pcap
reading from file linux.pcap, link-type EN10MB (Ethernet)
14:53:17.272328 IP host45.25158 > www.xxx.com.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23053732 0,nop,wscale 7>
14:53:20.270843 IP host45.25158 > www.xxx.com.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23056732 0,nop,wscale 7>
14:53:26.269339 IP host45.25158 > www.xxx.com.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23062732 0,nop,wscale 7>
14:53:38.266329 IP host45.25158 > www.xxx.com.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23074732 0,nop,wscale 7>
14:53:47.176380 IP www.xxx.com.30022 > host45.25158: R 0:0(0) win 5840
14:54:02.259312 IP host45.25158 > www.xxx.com.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23098733 0,nop,wscale 7>
14:54:50.245281 IP host45.25158 > www.xxx.com.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23146733 0,nop,wscale 7>
14:55:50.145502 IP www.xxx.com.30022 > host45.25158: R 0:0(0) win 5840
二、在服务器www.xxx.com抓取数据包
crea-an:~# tcpdump -f -ieth1 -vs0 -f -w linux.pcap \(dst or src 172.16.10.10\) and \(! port 80\)
tcpdump: listening on eth1, link-type EN10MB (Ethernet), capture size 65535 bytes
6 packets captured
6 packets received by filter
0 packets dropped by kernel
在服务器www.xxx.com查看抓取的数据包
crea-an:~# tcpdump -r linux.pcap
reading from file linux.pcap, link-type EN10MB (Ethernet)
14:53:18.037657 IP crea-an.13958 > 192.168.1.15.30022: S 1204969435:1204969435(0) win 5840 <mss 1430,sackOK,timestamp 23053732 0,nop,wscale 7>
14:53:21.036245 IP crea-an.13958 > 192.168.1.15.30022: S 1204969435:1204969435(0) win 5840 <mss 1430,sackOK,timestamp 23056732 0,nop,wscale 7>
14:53:27.034450 IP crea-an.13958 > 192.168.1.15.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23062732 0,nop,wscale 7>
14:53:39.032397 IP crea-an.13958 > 192.168.1.15.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23074732 0,nop,wscale 7>
14:54:03.028264 IP crea-an.13958 > 192.168.1.15.30022: S 1204969435:1204969435(0) win 5840 <mss 1460,sackOK,timestamp 23098733 0,nop,wscale 7>
14:54:51.016351 IP crea-an.13462 > 192.168.1.15.30022: S 1204969435:1204969435(0) win 5840 <mss 1430,sackOK,timestamp 23146733 0,nop,wscale 7>
三、在linux pc上SSH登录www.xxx.com服务器,直到超时
[root@host45 ~]# ssh 10.0.0.10 -p 30022 -i /usr/.ssh/crea.key
ssh: connect to host 10.0.0.10 port 30022: Connection timed out
一、二、三步骤同时进行的;linux pc就是在与www.xxx.com建立tcp连接的时候经常超时,而windows pc与www.xxx.com建立tcp连接的时候不会超时 |
|