WiresharkÊÇÒ»¿î·Ç³£°ôµÄUnixºÍWindowsÉϵĿªÔ´ÍøÂçÐÒé·ÖÎöÆ÷¡£WiresharkÖÐÎÄ°æ¿ÉÒÔʵʱ¼ì²âÍøÂçͨѶÊý¾Ý£¬Ò²¿ÉÒÔ¼ì²âÆäץȡµÄÍøÂçͨѶÊý¾Ý¿ìÕÕÎļþ¡£WiresharkÖÐÎÄ°æ¿ÉÒÔͨ¹ýͼÐνçÃæä¯ÀÀÕâЩÊý¾Ý£¬¿ÉÒԲ鿴ÍøÂçͨѶÊý¾Ý°üÖÐÿһ²ãµÄÏêϸÄÚÈÝ¡£WiresharkÓµÓÐÐí¶àÇ¿´óµÄÌØÐÔ£º°üº¬ÓÐÇ¿ÏÔʾ¹ýÂËÆ÷ÓïÑÔ£¨rich display filter language£©ºÍ²é¿´TCP»á»°Öع¹Á÷µÄÄÜÁ¦£»Ëü¸üÖ§³ÖÉÏ°ÙÖÖÐÒéºÍýÌåÀàÐÍ£» ÓµÓÐÒ»¸öÀàËÆtcpdump(Ò»¸öLinuxϵÄÍøÂçÐÒé·ÖÎö¹¤¾ß)µÄÃûΪtetherealµÄµÄÃüÁîÐа汾¡£
ÌØÉ«¹¦ÄÜ£º
Wireshark£¨Ç°³ÆEthereal£©ÊÇÒ»¸öÍøÂç·â°ü·ÖÎöÈí¼þ¡£ÍøÂç·â°ü·ÖÎöÈí¼þµÄ¹¦ÄÜÊÇߢȡÍøÂç·â°ü, ²¢¾¡¿ÉÄÜÏÔʾ³ö×îΪÏêϸµÄÍøÂç·â°ü×ÊÁÏ¡£ÍøÂç·â°ü·ÖÎöÈí¼þµÄ¹¦ÄÜ¿ÉÏëÏñ³É "µç¹¤¼¼Ê¦Ê¹Óõç±íÀ´Á¿²âµçÁ÷¡¢µçѹ¡¢µç×è" µÄ¹¤×÷ - Ö»Êǽ«³¡¾°ÒÆÖ²µ½ÍøÂçÉÏ£¬²¢½«µçÏßÌæ»»³ÉÍøÂçÏß¡£
ÔÚ¹ýÈ¥£¬ÍøÂç·â°ü·ÖÎöÈí¼þÊǷdz£°º¹ó£¬»òÊÇרÃÅÊôÓÚÓªÀûÓõÄÈí¼þ¡£EtherealµÄ³öÏָıäÁËÕâÒ»ÇС£ÔÚGNU GPLͨÓÃÐí¿ÉÖ¤µÄ±£ÕÏ·¶Î§µ×Ï£¬Ê¹ÓÃÕß¿ÉÒÔÒÔÃâ·ÑµÄ´ú¼ÛÈ¡µÃÈí¼þÓëÆä³ÌʽÂ룬²¢ÓµÓÐÕë¶ÔÆäÔʼÂëÐ޸ļ°¿ÍÖÆ»¯µÄȨÀû¡£EtherealÊÇÄ¿Ç°È«ÊÀ½ç×î¹ã·ºµÄÍøÂç·â°ü·ÖÎöÈí¼þÖ®Ò»
Wireshakr×¥°ü½çÃæ
˵Ã÷£ºÊý¾Ý°üÁбíÇøÖв»Í¬µÄÐÒéʹÓÃÁ˲»Í¬µÄÑÕÉ«Çø·Ö¡£ÐÒéÑÕÉ«±êʶ¶¨Î»Ôڲ˵¥À¸View --> Coloring Rules¡£ÈçÏÂËùʾ
WireShark Ö÷Òª·ÖΪÕ⼸¸ö½çÃæ
1. Display Filter(ÏÔʾ¹ýÂËÆ÷)£¬ ÓÃÓÚÉèÖùýÂËÌõ¼þ½øÐÐÊý¾Ý°üÁбí¹ýÂË¡£²Ëµ¥Â·¾¶£ºAnalyze --> Display Filters¡£
2. Packet List Pane(Êý¾Ý°üÁбí)£¬ ÏÔʾ²¶»ñµ½µÄÊý¾Ý°ü£¬Ã¿¸öÊý¾Ý°ü°üº¬±àºÅ£¬Ê±¼ä´Á£¬Ô´µØÖ·£¬Ä¿±êµØÖ·£¬ÐÒ飬³¤¶È£¬ÒÔ¼°Êý¾Ý°üÐÅÏ¢¡£ ²»Í¬ÐÒéµÄÊý¾Ý°üʹÓÃÁ˲»Í¬µÄÑÕÉ«Çø·ÖÏÔʾ¡£
3. Packet Details Pane(Êý¾Ý°üÏêϸÐÅÏ¢), ÔÚÊý¾Ý°üÁбíÖÐÑ¡ÔñÖ¸¶¨Êý¾Ý°ü£¬ÔÚÊý¾Ý°üÏêϸÐÅÏ¢ÖлáÏÔʾÊý¾Ý°üµÄËùÓÐÏêϸÐÅÏ¢ÄÚÈÝ¡£Êý¾Ý°üÏêϸÐÅÏ¢Ãæ°åÊÇ×îÖØÒªµÄ£¬ÓÃÀ´²é¿´ÐÒéÖеÄÿһ¸ö×ֶΡ£¸÷ÐÐÐÅÏ¢·Ö±ðΪ
£¨1£©Frame: ÎïÀí²ãµÄÊý¾ÝÖ¡¸Å¿ö
£¨2£©Ethernet II: Êý¾ÝÁ´Â·²ãÒÔÌ«ÍøÖ¡Í·²¿ÐÅÏ¢
£¨3£©Internet Protocol Version 4: »¥ÁªÍø²ãIP°üÍ·²¿ÐÅÏ¢
£¨4£©Transmission Control Protocol: ´«Êä²ãTµÄÊý¾Ý¶ÎÍ·²¿ÐÅÏ¢£¬´Ë´¦ÊÇTCP
£¨5£©Hypertext Transfer Protocol: Ó¦ÓòãµÄÐÅÏ¢£¬´Ë´¦ÊÇHTTPÐÒé
TCP°üµÄ¾ßÌåÄÚÈÝ
´ÓÏÂͼ¿ÉÒÔ¿´µ½wireshark²¶»ñµ½µÄTCP°üÖеÄÿ¸ö×ֶΡ£
4. Dissector Pane(Êý¾Ý°ü×Ö½ÚÇø)¡£
Wireshark¹ýÂËÆ÷ÉèÖÃ
³õѧÕßʹÓÃwiresharkʱ£¬½«»áµÃµ½´óÁ¿µÄÈßÓàÊý¾Ý°üÁÐ±í£¬ÒÔÖÁÓÚºÜÄÑÕÒµ½×Ô¼º×Ô¼º×¥È¡µÄÊý¾Ý°ü²¿·Ö¡£wireshar¹¤¾ßÖÐ×Ô´øÁËÁ½ÖÖÀàÐ͵ĹýÂËÆ÷£¬Ñ§»áʹÓÃÕâÁ½ÖÖ¹ýÂËÆ÷»á°ïÖúÎÒÃÇÔÚ´óÁ¿µÄÊý¾ÝÖÐѸËÙÕÒµ½ÎÒÃÇÐèÒªµÄÐÅÏ¢¡£
£¨1£©×¥°ü¹ýÂËÆ÷
²¶»ñ¹ýÂËÆ÷µÄ²Ëµ¥À¸Â·¾¶ÎªCapture --> Capture Filters¡£ÓÃÓÚÔÚץȡÊý¾Ý°üÇ°ÉèÖá£
ÈçºÎʹÓã¿¿ÉÒÔÔÚץȡÊý¾Ý°üÇ°ÉèÖÃÈçÏ¡£
ip host 60.207.246.216 and icmp±íʾֻ²¶»ñÖ÷»úIPΪ60.207.246.216µÄICMPÊý¾Ý°ü¡£»ñÈ¡½á¹ûÈçÏ£º
£¨2£©ÏÔʾ¹ýÂËÆ÷
ÏÔʾ¹ýÂËÆ÷ÊÇÓÃÓÚÔÚץȡÊý¾Ý°üºóÉèÖùýÂËÌõ¼þ½øÐйýÂËÊý¾Ý°ü¡£Í¨³£ÊÇÔÚץȡÊý¾Ý°üʱÉèÖÃÌõ¼þÏà¶Ô¿í·º£¬×¥È¡µÄÊý¾Ý°üÄÚÈݽ϶àʱʹÓÃÏÔʾ¹ýÂËÆ÷ÉèÖÃÌõ¼þ¹ËÂÇÒÔ·½±ã·ÖÎö¡£Í¬ÑùÉÏÊö³¡¾°£¬ÔÚ²¶»ñʱδÉèÖò¶»ñ¹æÔòÖ±½Óͨ¹ýÍø¿¨½øÐÐץȡËùÓÐÊý¾Ý°ü£¬ÈçÏÂ
Ö´ÐÐping www.huawei.com»ñÈ¡µÄÊý¾Ý°üÁбíÈçÏÂ
¹Û²ìÉÏÊö»ñÈ¡µÄÊý¾Ý°üÁÐ±í£¬º¬ÓдóÁ¿µÄÎÞЧÊý¾Ý¡£Õâʱ¿ÉÒÔͨ¹ýÉèÖÃÏÔʾÆ÷¹ýÂËÌõ¼þ½øÐÐÌáÈ¡·ÖÎöÐÅÏ¢¡£ip.addr == 211.162.2.183 and icmp¡£²¢½øÐйýÂË¡£
ÉÏÊö½éÉÜÁË×¥°ü¹ýÂËÆ÷ºÍÏÔʾ¹ýÂËÆ÷µÄ»ù±¾Ê¹Ó÷½·¨¡£ÔÚ×éÍø²»¸´ÔÓ»òÕßÁ÷Á¿²»´óÇé¿öÏ£¬Ê¹ÓÃÏÔʾÆ÷¹ýÂËÆ÷½øÐÐ×¥°üºó´¦Àí¾Í¿ÉÒÔÂú×ãÎÒÃÇʹÓá£ÏÂÃæ½éÉÜÒ»ÏÂÁ½Õß¼äµÄÓï·¨ÒÔ¼°ËüÃǵÄÇø±ð¡£