騫歌繍鐨勬槸錛學ireshark(綰塊波)涓嬈懼熀浜?winpcap/tcpdump 鐨勫紑婧愮綉緇滃崗璁垎鏋愯蔣浠跺vista鍜屾棤綰跨綉緇滅殑鍏煎閮藉緢濂姐備粬鐨勫墠韜氨鏄疎thereal銆備粬鍏峰浜嗗拰 Iris 鍚屾牱寮哄ぇ鐨?Decode 鑳藉姏錛岀敋鑷崇嚎鎬ф埅鍖呯殑鑳藉姏瓚呰繃 iris銆傝鐢ㄥソ鍒嗘瀽鍣ㄥ緢閲嶈鐨勪竴鐐瑰氨鏄緗ソ Filter(榪囨護鍣?錛屽湪榪欎竴鐐逛笂 Wireshark 鐨勮繃婊よ〃杈懼紡鏇存樉寮哄ぇ銆?/p>
鎴戜滑鏉ョ湅涓嚑涓畝鍗曠殑榪囨護鍣ㄤ緥瀛愶細
“ip.dst==211.244.254.1” (鎵鏈夌洰鏍囧湴鍧鏄?11.244.254.1鐨刬p鍖?
“tcp.port==80″ (鎵鏈塼cp绔彛鏄?0鐨勫寘)
浣犲彲浠ユ妸涓婅堪琛ㄨ揪寮忕敤 and 榪炴帴璧鋒潵
“(ip.dst==211.244.254.1) and (tcp.port==80)”
鎴栬呭啀紼嶅姞鍙樻崲
“(ip.dst==211.244.254.1) and !(tcp.port==80)” (鎵鏈夌洰鐨刬p鏄?11.244.254.1闈?80 绔彛)
浣跨敤琛ㄨ揪寮忚緗繃婊ゅ櫒姣斾箣鍦ㄧ晫闈笂閫夋嫨/濉┖鏇村姞蹇嵎鐏墊椿錛屽鏋滀綘涓嶇啛鎮夎繖浜涜〃杈懼紡錛學ireshark 涔熸彁渚涗簡璁劇疆鐣岄潰錛屽茍涓旀渶緇堢敓鎴愯〃杈懼紡錛岃繖鏍蜂篃鏂逛究浜嗕嬌鐢ㄨ呭涔犮?/p>
Wireshark 榪樻彁渚涗簡鏇撮珮綰х殑琛ㄨ揪寮忕壒鎬э紝璇風湅濡備笅琛ㄨ揪寮?/p>
(tcp.port==80) and (ip.dst==211.244.254.1) and (http[5:2]==7075)
瀵硅薄 http 灝辨槸 wireshark 瑙g爜浠ュ悗鐨?http 鏁版嵁閮ㄥ垎 http[5:2] 灝辨槸鎸囦粠 涓嬫爣 5 寮濮嬬殑涓や釜瀛楄妭錛岃鎬濊冧竴涓嬭繖鏍風殑http 璇鋒眰
GET /pu*****
鎬庝箞鏍鳳紝濡傛灉浣犲湪嫻忚鍣ㄤ腑璁塊棶 http://www.google.com/pu 鎴栬?http://www.google.com/put 鎴栬?http://www.google.com/pub 閮戒細琚褰曚笅鏉ワ紝鍖歸厤 *****pu***… 浜?/p>
榪欐牱鎴戜滑灝卞彲浠ユ柟渚跨殑灝嗘垜浠渶瑕佹嫻嬬殑鏌愪釜鐗瑰埆鐨勭綉緇滄寚浠よ繃婊ゅ嚭鏉ャ?/p>
姣斿鎴戝湪甯煇紜歡緙栧啓涓婁綅鏈虹▼搴忕殑鏃跺欙紝鎸囦護鎬繪槸浠ュ浐瀹氭牸寮忓彂閫佺殑錛屽緢瀹規槗鎴戜滑灝辮兘榪囨護鎺夌儲浜虹殑鏃犵敤鐨勪俊鎭紝澶уぇ鐨勬彁鍗囦簡宸ヤ綔鏁堢巼銆?/p>
杞嚜cp62鐨勪笓鏍忥紝http://blog.csdn.net/cp62/archive/2008/12/25/3603372.aspx