¿´µ½Õ⣬ »ù±¾É϶ÔwireshakÓÐÁ˳õ²½Á˽⣬ ÏÖÔÚÎÒÃÇ¿´Ò»¸öTCPÈý´ÎÎÕÊÖµÄʵÀý
Èý´ÎÎÕÊÖ¹ý³ÌΪ
ÕâͼÎÒ¶¼¿´¹ýºÜ¶à±éÁË£¬ Õâ´ÎÎÒÃÇÓÃwiresharkʵ¼Ê·ÖÎöÏÂÈý´ÎÎÕÊֵĹý³Ì¡£
´ò¿ªwireshark, ´ò¿ªä¯ÀÀÆ÷ÊäÈë http://www.cr173.com
ÔÚwiresharkÖÐÊäÈëhttp¹ýÂË£¬ È»ºóÑ¡ÖÐGET /tankxiao HTTP/1.1µÄÄÇÌõ¼Ç¼£¬ÓÒ¼üÈ»ºóµã»÷"Follow TCP Stream",
ÕâÑù×öµÄÄ¿µÄÊÇΪÁ˵õ½Óëä¯ÀÀÆ÷´ò¿ªÍøÕ¾Ïà¹ØµÄÊý¾Ý°ü£¬½«µÃµ½ÈçÏÂͼ
ͼÖпÉÒÔ¿´µ½wireshark½Ø»ñµ½ÁËÈý´ÎÎÕÊÖµÄÈý¸öÊý¾Ý°ü¡£µÚËĸö°ü²ÅÊÇHTTPµÄ£¬ Õâ˵Ã÷HTTPµÄÈ·ÊÇʹÓÃTCP½¨Á¢Á¬½ÓµÄ¡£
µÚÒ»´ÎÎÕÊÖÊý¾Ý°ü
¿Í»§¶Ë·¢ËÍÒ»¸öTCP£¬±ê־λΪSYN£¬ÐòÁкÅΪ0£¬ ´ú±í¿Í»§¶ËÇëÇó½¨Á¢Á¬½Ó¡£ ÈçÏÂͼ
µÚ¶þ´ÎÎÕÊÖµÄÊý¾Ý°ü
·þÎñÆ÷·¢»ØÈ·ÈÏ°ü, ±ê־λΪ SYN,ACK. ½«È·ÈÏÐòºÅ(Acknowledgement Number)ÉèÖÃΪ¿Í»§µÄI S N¼Ó1ÒÔ.¼´0+1=1, ÈçÏÂͼ
µÚÈý´ÎÎÕÊÖµÄÊý¾Ý°ü
¿Í»§¶ËÔٴη¢ËÍÈ·ÈÏ°ü(ACK) SYN±ê־λΪ0,ACK±ê־λΪ1.²¢ÇÒ°Ñ·þÎñÆ÷·¢À´ACKµÄÐòºÅ×Ö¶Î+1,·ÅÔÚÈ·¶¨×Ö¶ÎÖз¢Ë͸ø¶Ô·½.²¢ÇÒÔÚÊý¾Ý¶Î·ÅдISNµÄ+1, ÈçÏÂͼ:
¾ÍÕâÑùͨ¹ýÁËTCPÈý´ÎÎÕÊÖ£¬½¨Á¢ÁËÁ¬½Ó
±¾Îĵ¼º½
- µÚ1Ò³: Ê×Ò³
- µÚ2Ò³: Wireshark ÏÔʾ¹ýÂË
- µÚ3Ò³: wiresharkÓë¶ÔÓ¦µÄOSIÆß²ãÄ£ÐÍ
- µÚ4Ò³: ʵÀý·ÖÎöTCPÈý´ÎÎÕÊÖ¹ý³Ì