tcpdump ?linux unix下的抓包工具。
默認(rèn)只抓68個(gè)字節(jié)
tcpdump -i eth0 -s 0 -w file.pcap
tcpdump -i eth0 port 22
讀取抓包文件
tcpdump -r file.pcap
tcpdump 篩選
tcpdump -n -r http.cap | awk '{print $3}' | sort | uniq
tcpdump -n src host ip -r http.cap
tcpdump -n dst host ip -r http.cap
tcpdump -n port 53 -r http.cap
tcpdump -n -X udp port -r http.cap
tcpdump 高級(jí)篩選
tcpdump -A -n 'tcp[13]=24' -r http.cap