当前位置:网站首页>[226] instructions for Wireshark parameters
[226] instructions for Wireshark parameters
2022-07-24 06:23:00 【wheat berry】

The subject part ( See official account for the original :python treasure )
python treasure
https://mp.weixin.qq.com/mp/profile_ext?action=home&__biz=MzU5NjIyOTE4OQ==&scene=123#wechat_redirect
Wheat seedling DB treasure
https://www.xmmup.com/
One 、OSI Seven layer model
application layer : An interface between network services and end users .
The agreement has :HTTP FTP TFTP SMTP SNMP DNS TELNET HTTPS POP3 DHCP
The presentation layer : Presentation of data 、 Security 、 Compress .( The application layer has been incorporated into the five layer model )
The format is ,JPEG、ASCll、EBCDIC、 Encryption format, etc
The session layer : establish 、 management 、 Terminate the conversation .( The application layer has been incorporated into the five layer model )
Corresponding host process , Refers to the ongoing session between the local host and the remote host
Transport layer : Define the protocol port number of data transmission , And flow control and error checking .
The agreement has :TCP UDP, Once the packet leaves the network card, it will enter the network transmission layer
The network layer : Logical address addressing , Realize path selection between different networks .
The agreement has :ICMP IGMP IP(IPV4 IPV6)
Data link layer
Establish logical connections 、 Address the hardware 、 Error checking and other functions .( The protocol is defined by the underlying network )
Combining bits into bytes and then into frames , use MAC Address access media , To discover but not correct .
The physical layer : establish 、 maintain 、 Disconnect the physical connection .( The protocol is defined by the underlying network )

Two 、 Rules of packet capturing filter expression
1. Two layer screening
eth.addr==ff:ff:ff:ff:ff:ff Filter layer 2
eth.dst==xxxx Filter Source MAC The address is xxxx
eth.src==xxxx Filter The goal is MAC The address is xxxx
2. Three layer screening
ip.addr==x.x.x.x Filter three layers
ip.dst==x.x.x.x Filter source IP The address is x.x.x.x
ip.src==x.x.x.x Purpose of filtration IP The address is x.x.x.x
3. Port filtering
tcp.port ==80 The port of the source host or destination host is displayed as 80 A list of packets for
tcp.srcport==80 Display only TCP The source host port of the protocol is 80 A list of packets for
tcp.dstport==80 Display only TCP The destination host port of the protocol is 80 A list of packets for
4. Logical operators and/or/not
And && and
or || or
Not ! not example :
1. Grab the host address as 220.181.38.148,TCP The destination port is 80 Data packets of
ip.addr==220.181.38.148 && tcp.dstport==80
2. Grab the host for 220.181.38.148 perhaps 220.181.38.149
ip.addr==220.181.38.148||ip.addr==220.181.38.149 3、 ... and 、wireshark The term
SYN : Sign a , Indicates a request to establish a connection
Seq = 0 : The initial connection value is 0, The relative sequence number of the packet is from 0 Start , Indicates that no data has been sent yet
Ack =0: The initial connection value is 0, Number of packages received , Indicates that no data is currently received
FIN Indicates that the connection is closed
PSH Express DATA The data transfer
RST Indicates connection reset .
Frame: Overview of data frames in physical layer
Ethernet II: Data link layer Ethernet frame header information
Internet Protocol Version 4: The Internet layer IP Baotou department information
Transmission Control Protocol: Transport layer T Data segment header information for , Here is TCP
Hypertext Transfer Protocol: Application layer information , Here is HTTP agreement
Reference resources :
https://blog.csdn.net/Aaron_1999/article/details/104077610
https://blog.csdn.net/m0_37824357/article/details/124498592
Answer section
One 、wireshark Start interface

Two 、 adopt Menu bar The capture option selects the network card to listen

3、 ... and 、 After selecting the network card to monitor , The interface is as follows , You can grab all the packets through this network card

Four 、 Filter the packets you need to analyze ip.addr == ip Address

5、 ... and 、 First look at a few packets , Be familiar with it. wireshark The agreement

6、 ... and 、 Look at the transport layer of a packet ( A row is a bag )

7、 ... and 、 Look at the network layer of a packet ( A row is a bag )

Reference resources :
https://blog.csdn.net/qq_44275213/article/details/118873256
https://blog.csdn.net/m0_37824357/article/details/124498592

About Me: Wheat grains
● The author of this article : Wheat grains , Focus on python、 Data analysis 、 data mining 、 Machine learning related technologies , Also pay attention to the use of Technology
● Author's blog address :https://blog.csdn.net/u010986753
● The title of this series comes from the author's study notes , Partially collated from the network , If there is any infringement or improper place, please understand
● copyright , Welcome to share this article , Reprint please keep the source
● Personal micro signal :pythonbao Contact me and add wechat Group
● personal QQ:87605025
● QQ Communication group py_data :483766429
● official account :python treasure or DB treasure
● Provide OCP、OCM And the most practical skills training with high availability
● If there is anything wrong with the answer to the question , I also hope that you can criticize and correct , Common progress

If you find the article helpful , Click on my avatar below , Appreciate me !
With your support , The wheat grain will be better and better !
边栏推荐
- Unity (III) three dimensional mathematics and coordinate system
- unity2D横版游戏跳跃实时响应
- How to build a website full of ritual sense and publish it on the public website 1-2
- Kernel pwn 基础教程之 Heap Overflow
- Heap overflow of kernel PWN basic tutorial
- MySQL从基础到入门到高可用
- IP class notes (4)
- UE4:浅谈什么是GamePlay框架
- Getting started with Lunix commands - user and file permissions (Chmod details)
- IP作业(6)
猜你喜欢

Kernel pwn 基础教程之 Heap Overflow
![Quickly and simply set up FTP server, and achieve public network access through intranet [no need for public IP]](/img/2a/43ba2839b842e0901a550d2883b883.png)
Quickly and simply set up FTP server, and achieve public network access through intranet [no need for public IP]

Li Kou 986. Intersection of interval lists

数据集和预训练模型
![Map the intranet to the public network [no public IP required]](/img/d0/b391bcfcaeb4c7ad439e241334361b.png)
Map the intranet to the public network [no public IP required]

Do not rent servers, build your own personal business website (2)

IP notes (10)

Hololens2 development: use MRTK and simulate eye tracking

配置固定的远程桌面地址【内网穿透、无需公网IP】

IP notes (8)
随机推荐
ue4 换装系统 2.换装系统的场景捕捉
Leetcode剑指offer JZ9 双栈实现队列
Data warehouse and data warehouse modeling
如何建立一个仪式感点满的网站,并发布到公网 1-2
不租服务器,自建个人商业网站(4)
Top 10 vulnerability assessment and penetration testing tools
Hololens2 development: use MRTK and simulate eye tracking
IP课总结(3)
Unity2d game let characters move - Part 1
unity2D游戏之让人物动起来-上
力扣:1-两数之和
Set up a WordPress personal blog locally and launch it through the intranet (22)
leetcode剑指offer JZ42 连续子数组的最大和
Metersphere one stop open source continuous testing platform
IP notes (11)
Simple three-step fast intranet penetration
公网访问内网IIS网站服务器【无需公网IP】
Do not rent a server, build your own personal business website (how to buy a domain name)
三分钟记住20道性能测试经典面试题
Public access intranet IIS website server [no public IP required]