http://windtear.net/archives/2004/04/05/000244.html
D:/>windump -h
windump version current-cvs.tcpdump.org, based on tcpdump version current-cvs.tcpdump.org
WinPcap version 3.0 alpha, based on libpcap version current-cvs.tcpdump.org
Usage: windump [-aAdDeflnNOpqRStuvxX] [-B size] [-c count] [ -C file_size ]
[ -F file ] [ -i interface ] [ -r file ] [ -s snaplen ]
[ -T type ] [ -w file ] [ -E algo:secret ] [ expression ]
% tcpdump -h
tcpdump version 3.6.3
libpcap version 0.6
Usage: tcpdump [-adeflnNOpqRStuvxX] [-c count] [ -F file ]
[ -i interface ] [ -r file ] [ -s snaplen ]
[ -T type ] [ -U user ] [ -w file ] [ expression ]
發信人: windtear (看成敗 人生豪邁), 信區: THUNet
標 題: [簡易FAQ] 怎麼知道誰中毒了
發信站: BBS 水木清華站 (Sun Nov 2 21:22:21 2003), 轉信
[簡易FAQ] 怎麼知道誰中毒了
Q: 怎麼知道誰中毒了
A: 抓包
Q: 怎麼抓包
A: WinDump
Q: 哪裏有
A: http://windump.polito.it/
Q: 連不上
A: 用代理 或者
http://ipcn.org/windump/WinDump.exe
http://ipcn.org/windump/WinPcap_3_0.exe
(如果不想用 alpha 版本
http://ipcn.org/windump/WinDump.v3.6.2.exe
http://ipcn.org/windump/2.3-WinPcap.exe
)
Q: 怎麼用
A: 先裝 WinPcap_3_0.exe
再裝 WinDump.exe
開始->運行
%SystemRoot%
拷貝粘貼 WinDump.exe
開始->運行
cmd
WinDump.exe -h
Q: 看不懂
A: http://windump.polito.it/docs/manual.htm
http://windump.polito.it/misc/faq.htm
A: WinDump.exe -nn icmp
21:06:50.845294 IP 166.111.168.203 > 166.111.169.255: icmp 72: echo request seq 16436
21:06:51.023851 IP 166.111.168.203 > 166.111.170.17: icmp 72: echo request seq 21044
21:06:51.063603 IP 166.111.168.203 > 166.111.170.21: icmp 72: echo request seq 22068
21:06:51.133730 IP 166.111.168.203 > 166.111.170.28: icmp 72: echo request seq 23860
21:06:51.163858 IP 166.111.168.203 > 166.111.170.31: icmp 72: echo request seq 24628
Q: 誰中毒了
A: 166.111.168.203
Q: 我只想要 238 段的
A: WinDump.exe -nn icmp and src net 166.111.238.0/24
Q: 怎麼知道中毒的166.111.168.203是誰
A: 如是靜態IP:看靜態IP分配信息
如不是:
ping 166.111.168.203
arp -a
找到 166.111.168.203 的 mac
166.111.168.203 00-50-ba-45-91-6f dynamic
00-50-ba-45-91-6f
Q: 然後呢
A: 到 3900(3300) 1100 查哪個端口
A:
--_--> 3900
Address found on port 17:
Canonical address Type
00-50-ba-45-91-6f Dynamic
or ----> 3900www
Success!
Address found on port 17
-----> 1100
Location VLAN ID Permanent
Unit 1 Port 12 1 No
Q: 不會
A: 發信到 [email protected]
windump
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.