{"id":1426,"date":"2020-03-23T00:04:24","date_gmt":"2020-03-22T16:04:24","guid":{"rendered":"http:\/\/blog.coolcoding.cn\/?p=1426"},"modified":"2021-01-19T18:40:09","modified_gmt":"2021-01-19T10:40:09","slug":"tcpdump","status":"publish","type":"post","link":"https:\/\/blog.coolcoding.cn\/?p=1426","title":{"rendered":"tcpdump\u3001windump"},"content":{"rendered":"\n<p>\u7528\u4e4b\u524d\uff0c\u5148\u7528ifconfig\u5217\u51fa\u5f53\u524d\u8bbe\u5907\u7684\u7f51\u7edc\u63a5\u53e3\uff0c\u793a\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ifconfig\n\neth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500\n        inet 172.16.53.206  netmask 255.255.240.0  broadcast 172.16.63.255\n        ether 00:16:3e:11:fc:e4  txqueuelen 1000  (Ethernet)\n        RX packets 26585809  bytes 16352217278 (15.2 GiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 18579541  bytes 13413764446 (12.4 GiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0<\/code><\/pre>\n\n\n\n<p>\u90a3\u4e48\u5f53\u524d\u7f51\u7edc\u9996\u9009\u63a5\u53e3\u4e3aeth0<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u7b5b\u900980\u7aef\u53e3\ntcpdump -i eth0 port 80\n\n\u7b5b\u900980\u7aef\u53e3\uff0c\u53ea\u629310\u4e2a\u5305\ntcpdump -i etch0 port 80 -c 10\n\n\u7b5b\u9009\uff1a\u4e0e8.8.8.8\u4ea4\u4e92\uff0c\u5e76\u4e1480\u7aef\u53e3\ntcpdump -i etch0 port host 8.8.8.8\n\n\u7b5b\u9009\u4e3b\u673a8.8.8.8\u53d1\u9001\u7684\u6240\u6709\u6570\u636e\ntcpdump -i eth0 src host 8.8.8.8\n\n\u7b5b\u9009\u6240\u6709\u9001\u5230\u4e3b\u673a8.8.8.8\u7684\u6570\u636e\u5305\ntcpdump -i eth0 dst host 8.8.8.8<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>\u4ee5\u4e0b\u4e3a\u53ef\u9009\u8f93\u51fa\u9009\u9879\uff1a\n-e   \u8f93\u51fa\u7684\u6bcf\u884c\u4e2d\u90fd\u5c06\u5305\u62ec\u6570\u636e\u94fe\u8def\u5c42\u5934\u90e8\u4fe1\u606f\uff0c\u4f8b\u5982\u6e90MAC\u548c\u76ee\u6807MAC\u3002\n-q   \u5feb\u901f\u6253\u5370\u8f93\u51fa\u3002\u5373\u6253\u5370\u5f88\u5c11\u7684\u534f\u8bae\u76f8\u5173\u4fe1\u606f\uff0c\u4ece\u800c\u8f93\u51fa\u884c\u90fd\u6bd4\u8f83\u7b80\u77ed\u3002\n-X   \u8f93\u51fa\u5305\u7684\u5934\u90e8\u6570\u636e\uff0c\u4f1a\u4ee516\u8fdb\u5236\u548cASCII\u4e24\u79cd\u65b9\u5f0f\u540c\u65f6\u8f93\u51fa\n-XX  \u6bd4-X\u66f4\u8be6\u7ec6\n-v   \u5f53\u5206\u6790\u548c\u6253\u5370\u7684\u65f6\u5019\uff0c\u4ea7\u751f\u8be6\u7ec6\u7684\u8f93\u51fa\n-vv  \u6bd4-v\u66f4\u8be6\u7ec6\n-vvv \u6bd4-vv\u66f4\u8be6\u7ec6\n-w   \u63a5\u6587\u4ef6\u540d\uff0c\u53ef\u5199\u5230\u6587\u4ef6\u4e2d\n\n\u4ee5\u4e0b\u4e3a\u914d\u7f6e\u9009\u9879\uff1a\n-n   \u5bf9\u5730\u5740\u4ee5\u6570\u5b57\u65b9\u5f0f\u663e\u5f0f\uff0c\u5426\u5219\u663e\u5f0f\u4e3a\u4e3b\u673a\u540d\uff0c\u4e5f\u5c31\u662f\u8bf4-n\u9009\u9879\u4e0d\u505a\u4e3b\u673a\u540d\u89e3\u6790\u3002\n-nn  \u9664\u4e86-n\u7684\u4f5c\u7528\u5916\uff0c\u8fd8\u628a\u7aef\u53e3\u663e\u793a\u4e3a\u6570\u503c\uff0c\u5426\u5219\u663e\u793a\u7aef\u53e3\u670d\u52a1\u540d\u3002\n-P   \u6307\u5b9a\u8981\u6293\u53d6\u7684\u5305\u662f\u6d41\u5165\u8fd8\u662f\u6d41\u51fa\u7684\u5305\u3002\u53ef\u4ee5\u7ed9\u5b9a\u7684\u503c\u4e3ain\/out\/inout \u9ed8\u8ba4inout\n     -Pin \/ -Pout \/ -Pinout\n-s len  \u8bbe\u7f6e\u6700\u5927\u6293\u5305\u957f\u5ea6\uff0c\u4e0d\u8bbe\u7f6e\u9ed8\u8ba4\u4e3a65535<\/code><\/pre>\n\n\n\n<p>\u5728Windows\u73af\u5883\u4e0b\u7684\u540d\u79f0\u4e3aWinDump\uff0c\u5b98\u65b9\u7f51\u5740\u4e3a\uff1a<br> <a href=\"https:\/\/www.winpcap.org\/\">https:\/\/www.winpcap.org\/<\/a> <\/p>\n\n\n\n<p><br>\u5728Windows10\u73af\u5883\u4e0b\u76f4\u63a5\u8fd0\u884c\u4f1a\u4e22\u5931DLL\uff0c\u9700\u8981\u5b89\u88c5Win10Pcap-v10.2-5002.msi\uff1b<\/p>\n\n\n\n<p>\u70b9\u51fb\u8fd9\u91cc\u6253\u5305\u4e0b\u8f7d<\/p>\n\n\n\n<div class=\"wp-block-file\"><a href=\"http:\/\/blog.coolcoding.cn\/wp-content\/uploads\/2020\/03\/windump.zip\">windump+Win10Pcap<\/a><a href=\"http:\/\/blog.coolcoding.cn\/wp-content\/uploads\/2020\/03\/windump.zip\" class=\"wp-block-file__button\" download><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u7528\u4e4b\u524d\uff0c\u5148\u7528ifconfig\u5217\u51fa\u5f53\u524d\u8bbe\u5907\u7684\u7f51\u7edc\u63a5\u53e3\uff0c\u793a\u4f8b\uff1a \u90a3\u4e48\u5f53\u524d\u7f51\u7edc\u9996\u9009\u63a5\u53e3\u4e3aeth0 \u5728Windows\u73af [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=\/wp\/v2\/posts\/1426"}],"collection":[{"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1426"}],"version-history":[{"count":10,"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=\/wp\/v2\/posts\/1426\/revisions"}],"predecessor-version":[{"id":1440,"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=\/wp\/v2\/posts\/1426\/revisions\/1440"}],"wp:attachment":[{"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1426"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.coolcoding.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}