笔者比较low,直接使用360软件管理直接下载
必须root权限才能抓包
su -
tcpdump -i any -w /tmp/test.cap
Ctrl + C 结束抓包
sz /tmp/test.cap
笔者用sz下载到本地
| 语法 | 说明 |
|---|---|
| eth.addr == ff:ff:ff:ff:ff:ff | mac地址过滤 |
| eth.src== ff:ff:ff:ff:ff:ff | 源mac地址过滤 |
| eth.dst == ff:ff:ff:ff:ff:ff | 目标mac地址过滤 |
| IP | IP协议 |
| ip.addr == 192.0.2.1 | ip地址过滤 |
| ip.dst == 192.168.8.112 | 目标地址过滤 |
| ip.src == 113.134.212.235 | 源地址过滤 |
| tcp | TCP协议 |
| tcp.port == 20032 | tcp 端口过滤 |
| tcp.srcport == 20032 | tcp源端口过滤 |
| tcp.dstport == 20032 | tcp目标端口过滤 |
| udp | UDP协议 |
| udp.port == 20032 | udp端口过滤 |
| udp.srcport == 20032 | udp源端口过滤 |
| udp.dstport == 20032 | udp目标地址过滤 |
| http | HTTP协议 |
| http.request | http请求 |
| http.request.method == POST | http的POST请求过滤 |
| http.response | http请求 |
| http.response | http响应 |
| http.response.code == 302 | 响应状态码过滤 |
https://www.wireshark.org/docs/dfref/
| 语法 | 说明 |
|---|---|
| not(!) | 非 |
| and(&&) | 且 |
| or(}}) | 或 |