TCP/IP󳚟󲎜󰠎󲠑
󳞥tcpdump󳞦
7󰬗󳞮󳞶󰩆 󰱤󱎄 󰩼
󰎽
TCP󳚘󳚟󲎜󰠎󲠑
tcpdump󳛃󱍾󳙵󳚗󳙙
󰎨󲜠󳚟tcp󳜀󳛠󳛲󳛷󳚟󰎽󳛃󳚈󳙙󲂾󰩣
tcpdump
󳛼󳛲󳛷󳜞󳜫󳛞󳚟󳜀󳛠󳛲󳛷󳛃
󳜑󳛺󳛮󳜙󳜢󳛟󳚊󳚼󳛢󳜍󳜢󳛸󳞫
# tcpdump host tsuji and port 80
11:26:59.113561 tsuji.4376 >www.google.com.http: S
3898758850:3898758850(0) win 16384 <mss 1460>
(DF)
tcpdump󳚟
󰪍 HH:MM:SS.󳜍󳛓󳛞󳜜󱙫
󲎇󳛑󳛸󳜛󳛨 󳜊󳛨󳛷󳞥󳚯󳚐󳚠IP󳛑󳛸󳜛󳛨󳞦󳞫󳜌󳜫󳛷󱎳
󰎥󳛑󳛸󳜛󳛨 󳜊󳛨󳛷󳞥󳚯󳚐󳚠IP󳛑󳛸󳜛󳛨󳞦󳞫󳜌󳜫󳛷󱎳󳞷
󳜄󳜘󳛟
S󳞷SYN󳞥󳛢󳛼󳛞󳛦󳜖󳜢󱖽󱜈󱿼󰹴󳞦
P󳞷PUSH󳞥󰪍󳚜󳛶󳜫󳛮󳛃󲎇󳚼󳚹󳙷󱿼󰹴󳞦
F󳞷FIN󳞥󳛢󳛼󳛞󳛦󳜖󳜢󲚅󰧛󱿼󰹴󳞦
R󳞷RST󳞥󳛢󳛼󳛞󳛦󳜖󳜢󰗪󰨠󱿼󰹴󳞦
󳛦󳜫󳛠󳜢󳛨󱎳
󳜪󰨣󳚈󳙵󳛶󳜫󳛮󳚟󰬒󳚟󳛿󳛓󳛷󳚟󳛦󳜫󳛠󳜢󳛨󱎳
󳜪󳚯󳚘󳚜󲎇󳚔󳚐󳛶󳜫󳛮󳚟󰬒󰘬󳚟󳛿󳛓󳛷󳚟󳛦󳜫󳛠󳜢󳛨󱎳󳞨󳞮
󳜪󳛿󳛓󳛷󰧹
# tcpdump host tsuji and port 80
11:26:59.113561 tsuji.4376 >www.google.com.http: S
3898758850:3898758850(0) win 16384 <mss 1460>
(DF)
tcpdump󳚟
# tcpdump host tsuji and port 80
11:26:59.113561 tsuji.4376 >www.google.com.http: S
3898758850:3898758850(0) win 16384 <mss 1460>
(DF)
ACK󱎳 ACK:ACK󳞥󱖽󲂧󰙣󱝦󳞦󱎳
󳛕󳛒󳜢󳛸󳛕󳛤󳛓󳛩 󱫀󳚛󳛶󳜫󳛮󲙸
󳜄󳜘󳛟󳜐󳜢󳛷󱘸󰷧 (DF)󳞷󳜄󳜘󳛟󳜐󳜢󳛷󳞥󳜀󳛠󳛲󳛷󳞦󱘸󰷧󳜂󳛲󳛷ON
mss 󰬒󰉒󳜀󳛠󳛲󳛷󲙸󳛃󰢇󰎤󳚈󳚐󳛿󳛓󳛷󰧹󳚜󲛩
tcpdump󳚜󳚹󳚼
TCP󲀜󰏚
󳜪󳜪󳜪󳜌󳜫󳛷󱎳80
host tsuji󳚘󳚟TCP󳜀󳛠󳛲󳛷󳛃󰘴
%netscape
#tcpdump host tsuji and port 80
tsuji󳚘netscape󳛃󲈔󳚈󳙙
󳚎󳚟󰪍󳚟󳜀󳛠󳛲󳛷󳚟󰎽󳛃󲀜󰏚
TCP/IP󳚘󳚟󲎜
󰆗󰬰󱑸󳚛󰼗󳚽
󳛢󳛼󳛞󳛦󳜖󳜢󱖽󱜈
󳛶󳜫󳛮󲋠󲎇
󳛢󳛼󳛞󳛦󳜖󳜢󱢫󱋏
󳛢󳛼󳛞󳛦󳜖󳜢󱖽󱜈
21:19:27.445117 tsuji.4376 > www.google.com.http: S
3898758850:3898758850(0) win 16384 <mss 1460> (DF)
21:19:27.706707 www.google.com.http > tsuji.4376: S
3317888770:3317888770(0) ack 3898758851 win 32120
<mss 1460> (DF)
21:19:27.706813 tsuji.4376 > www.google.com.http: .
ack 1 win 17520 (DF)
󳛤󳜫󳛿 󳚜S(SYN)󳛃󲎇󳙙󳛢󳛼󳛞󳛦󳜖󳜢󱖽󱜈󳛃󱿼󰹴
󲎇󳛿󳛓󳛷󳞭󳙙󱫀󳛶󳜫󳛮󲙸󳞮󳞳KB󳙙󰬒󰉒󳜀󳛠󳛲󳛷󲙸󳞮󳞱󳞳󳞭B
ACK󳞥󳛦󳜫󳛠󳜢󳛨󱎳󳞨󳞮 󳞦󳛃󲎇
󳛞󳜘󳛓󳛑󳜢󳛷󳚜󳚻󳚟󳛢󳛼󳛞󳛦󳜖󳜢󱖽󱜈󳛃󱿼󰹴
󳚻󳚟󳛢󳛼󳛞󳛦󳜖󳜢󱖽󱜈󳛃 󲎜󱕒
󳛶󳜫󳛮󲋠󲎇
21:19:27.723972 tsuji.4376 > www.google.com.http: P
1:346(345) ack 1 win 17520 (DF)
󴏮
󴏮
󴏮
󴏮
󴏮
345 󳛿󳛓󳛷󳚟󳛦󳜫󳛠󳜢󳛨󳛃󱑯󱍶
P(PUSH)󳜄󳜘󳛟: 󲎠󳚵󳙼󳚜󳛶󳜫󳛮󳛃󳛑󳜆󳜙󳛠󳜫󳛦󳜖󳜢󳚜󰾜󳚊󳚹󳙷󰢇󰎤
ACK󱎳󳚜󳚹󳚻󳙙󳛤󳜫󳛿󳚠󳛞󳜘󳛓󳛑󳜢󳛷󳙼󳚺󲎇󳚆󳚽󳚐 346 󳚯
󳚘󳚟󳛶󳜫󳛮󳞥󳚕󳚯󳚻󲐫󳞦󳛃󳚘󳙾󳚐󳚄󳚙󳛃󱘈󳚊
21:19:27.977446 www.google.com.http > tsuji.4376: P
1:184(183) ack 346 win 32120 (DF)
󳛢󳛼󳛞󳛦󳜖󳜢󱢫󱋏
21:19:37.982740 www.google.com.http > tsuji.4376: F
1690:1690(0) ack 346 win 32120 (DF)
21:19:37.982849 tsuji.4376 > www.google.com.http: . ack
1691 win 17520 (DF)
F(FIN) 󳜂󳛲󳛷󳛃󱜈󳚗󳛞󳜘󳛓󳛑󳜢󳛷󳚜󳚻󳛢󳛼󳛞󳛦󳜖󳜢󳚟󲚅󰧛󱿼󰹴
FIN 󳚜󰏱󳚊󳚼 ACK 󳛃󲍪󳚊
󳛞󳜘󳛓󳛑󳜢󳛷󳛤󳜫󳛿󳚜󰳾󳚟󱋏󳛃󱼽󳙵󳙙󳛢󳛼󳛞󳛦󳜖󳜢󱢫
󰎨󱨇
󱭍󳚟󳜍󳛦󳜢󳚘
#tcpdump host hostname and port 80
󳚟󳛮󳜫󳜎󳛹󳜚󳙼󳚺
%netscape
󳜀󳛠󳛲󳛷󳚟󰎽󳛃󲃋󳚪󳙙TCP󳚟󳛃󱖽󲂧󳙚