µÚÒ»²½ÊÇÕÒµ½PC·¢Ë͵½ÍøÂç·þÎñÆ÷µÄµÚÒ»¸öSYN±¨ÎÄ£¬Õâ±êʶÁËTCPÈý´ÎÎÕÊֵĿªÊ¼¡£
Èç¹ûÄãÕÒ²»µ½µÚÒ»¸öSYN±¨ÎÄ£¬Ñ¡ÔñEdit -> Find Packet²Ëµ¥Ñ¡ÏѡÔñDisplay Filter£¬ÊäÈë¹ýÂËÌõ¼þ£ºtcp.flags£¬Õâʱ»á¿´µ½Ò»¸öflagÁбíÓÃÓÚÑ¡Ôñ¡£Ñ¡ÔñºÏÊʵÄflag£¬tcp.flags.syn²¢ÇÒ¼ÓÉÏ==1¡£µã»÷Find£¬Ö®ºótraceÖеĵÚÒ»¸öSYN±¨Îľͻá¸ßÁÁ³öÀ´ÁË¡£
×¢Ò⣺Find PacketÒ²¿ÉÒÔÓÃÓÚËÑË÷Ê®Áù½øÖÆ×Ö·û£¬±ÈÈç¶ñÒâÈí¼þÐźţ¬»òËÑË÷×Ö·û´®£¬±ÈÈç×¥°üÎļþÖеÄÐÒéÃüÁî¡£
Ò»¸ö¿ìËÙ¹ýÂËTCP±¨ÎÄÁ÷µÄ·½Ê½ÊÇÔÚPacket List PanelÖÐÓÒ¼ü±¨ÎÄ£¬²¢ÇÒÑ¡ÔñFollow TCP Stream¡£Õâ¾Í´´½¨ÁËÒ»¸öÖ»ÏÔʾTCP»á»°±¨ÎĵÄ×Ô¶¯¹ýÂËÌõ¼þ¡£ ÕâÒ»²½Öè»áµ¯³öÒ»¸ö»á»°ÏÔʾ´°¿Ú£¬Ä¬ÈÏÇé¿öϰüº¬TCP»á»°µÄASCII´úÂ룬¿Í»§¶Ë±¨ÎÄÓúìÉ«±íʾ·þÎñÆ÷±¨ÎÄÔòΪÀ¶É«¡£
´°¿ÚÀàËÆÏÂͼËùʾ£¬¶ÔÓÚ¶ÁÈ¡ÐÒéÓÐÐ§ÔØºÉ·Ç³£ÓаïÖú£¬±ÈÈçHTTP£¬SMTP£¬FTP¡£
¸ü¸ÄΪʮÁù½øÖÆDumpģʽ²é¿´ÔغɵÄÊ®Áù½øÖÆ´úÂ룬ÈçÏÂͼËùʾ£º
¹Ø±Õµ¯³ö´°¿Ú£¬Wireshark¾ÍÖ»ÏÔʾËùÑ¡TCP±¨ÎÄÁ÷¡£ÏÖÔÚ¿ÉÒÔÇáËÉ·Ö±æ³ö3´ÎÎÕÊÖÐźš£
×¢Ò⣺ÕâÀïWireshark×Ô¶¯Îª´ËTCP»á»°´´½¨ÁËÒ»¸öÏÔʾ¹ýÂË¡£±¾ÀýÖУº(ip.addr eq 192.168.1.2 and ip.addr eq 209.85.227.19) and (tcp.port eq 80 and tcp.port eq 52336) SYN±¨ÎÄ£º
ͼÖÐÏÔʾµÄ5ºÅ±¨ÎÄÊÇ´Ó¿Í»§¶Ë·¢ËÍÖÁ·þÎñÆ÷¶ËµÄSYN±¨ÎÄ£¬´Ë±¨ÎÄÓÃÓÚÓë·þÎñÆ÷½¨Á¢Í¬²½£¬È·±£¿Í»§¶ËºÍ·þÎñÆ÷¶ËµÄͨÐŰ´´ÎÐò´«Êä¡£SYN±¨ÎĵÄÍ·²¿ÓÐÒ»¸ö32 bitÐòÁкš£µ×¶Ë¶Ô»°¿òÏÔʾÁ˱¨ÎÄһЩÓÐÓÃÐÅÏ¢È籨ÎÄÀàÐÍ£¬ÐòÁкš£ SYN/ACK±¨ÎÄ£º
7ºÅ±¨ÎÄÊÇ·þÎñÆ÷µÄÏìÓ¦¡£Ò»µ©·þÎñÆ÷½ÓÊÕµ½¿Í»§¶ËµÄSYN±¨ÎÄ£¬¾Í¶ÁÈ¡±¨ÎĵÄÐòÁкŲ¢ÇÒʹÓô˱àºÅ×÷ΪÏìÓ¦£¬Ò²¾ÍÊÇ˵Ëü¸æÖª¿Í»§»ú£¬·þÎñÆ÷½ÓÊÕµ½ÁËSYN±¨ÎÄ£¬Í¨¹ý¶ÔÔSYN±¨ÎÄÐòÁкżÓÒ»²¢ÇÒ×÷ΪÏìÓ¦±àºÅÀ´ÊµÏÖ£¬Ö®ºó¿Í»§¶Ë¾ÍÖªµÀ·þÎñÆ÷Äܹ»½ÓÊÕͨÐÅ¡£ ACK±¨ÎÄ£º
8ºÅ±¨ÎÄÊǿͻ§¶Ë¶Ô·þÎñÆ÷·¢Ë͵ÄÈ·Èϱ¨ÎÄ£¬¸æËß·þÎñÆ÷¿Í»§¶Ë½ÓÊÕµ½ÁË
SYN/ACK±¨ÎÄ£¬²¢ÇÒÓëǰһ²½Ò»Ñù¿Í»§¶ËÒ²½«ÐòÁкżÓÒ»£¬´Ë°ü·¢ËÍÍê±Ï£¬¿Í»§¶ËºÍ·þÎñÆ÷½øÈëESTABLISHED״̬£¬Íê³ÉÈý´ÎÎÕÊÖ¡£ ARP & ICMP£º
¿ªÆôWireshark×¥°ü¡£´ò¿ªWindows¿ØÖÆÌ¨´°¿Ú£¬Ê¹ÓÃpingÃüÁîÐй¤¾ß²é¿´ÓëÏàÁÚ»úÆ÷µÄÁ¬½Ó×´¿ö¡£
Í£Ö¹×¥°üÖ®ºó£¬WiresharkÈçÏÂͼËùʾ¡£
ARPºÍICMP±¨ÎÄÏà¶Ô½ÏÄѱæÈÏ£¬´´½¨Ö»ÏÔʾARP»òICMPµÄ¹ýÂËÌõ¼þ¡£
Ïà¹ØÍÆ¼ö£º