¡¶¼ÆËã»úÍøÂ硷ʵÑéÖ¸µ¼Êé
ʵÑé5£º¼òµ¥Â·ÓÉÆ÷Éè¼ÆÓëʵÏÖ(Ñ¡×ö)
1.ʵÑéÄ¿µÄ
ÊìϤ²¢ÕÆÎÕ·ÓÉÆ÷µÄ¹¤×÷ÔÀí£»ÊìϤWinpcap±à³Ì£¬ÕÆÎÕÊý¾Ý°ü²¶»ñÓë·¢Ë͵ķ½·¨£»ÔÚÀí½âIPÐÒé¡¢ICMPÐÒéÓë·ÓÉ»ù±¾¹¤×÷ÔÀíµÄ»ù´¡ÉÏ£¬Íê³ÉÒ»¸ö£¨Èí¼þ£©Â·ÓÉÆ÷»ù±¾¹¦ÄܵÄÉè¼ÆÓë±à³ÌʵÏÖ¡£ 2.ʵÑé»·¾³
? ½ÓÈë¾ÖÓòÍøµÄPC»ú£»
? ²Ù×÷ϵͳ£ºWindows xp, Windows 7µÈ£» ? ÍÆ¼ö¿ª·¢¹¤¾ß£ºVisual Studio 2010£» ? ÍÆ¼ö±à³ÌÓïÑÔ£ºC++/ Visual C++£» ? º¯Êý¿â/¿ª·¢°ü£ºWinpcap¡£ 3.ʵÑéÄÚÈÝ
(1) ѧϰ²¢ÕÆÎÕwinpcap±à³Ì£º×ÔÐÐÍê³ÉWinPcap½Ì³ÌÖеÄÄÚÈÝ£¬´Ó¶øÕÆÎÕwinpcap±à³Ì¡£ÄÚÈݰüÀ¨µ«²»ÏÞÓÚ£º
a) »ñÈ¡É豸ÁÐ±í£»
b) ´ò¿ªÒ»¸öÊÊÅäÆ÷²¢×¥°ü£¨·Ö×飩£» c) ½âÎö·Ö×飻 d) ·¢ËÍ·Ö×飻
ѧϰÄÚÈݼ°Ô´³ÌÐò²Î¼ûWinPcap¹Ù·½½Ì³Ì£º
http://www.winpcap.org/docs/docs_412/html/group_wpcap_tut.html¡£ (2) ÀûÓÃwinpcap¿ª·¢°üʵÏÖ¼òµ¥Â·ÓɳÌÐò£¬¸Ã·ÓɳÌÐòÓ¦¸ÃÖÁÉÙ°üÀ¨ÒÔϹ¦ÄÜ£º
a) IPÊý¾Ý°ü²¶»ñºÍת·¢£» b) ARPÇëÇóÓë½âÎö£»
c) ÖØÐ¼ÆËãIPÊý¾Ý°üµÄÍ·²¿Ð£ÑéºÍ£»
d) ´¦ÀíIPÊý¾Ý°üµÄÍ·²¿Ð£ÑéºÍ£»´¦ÀíIPÊý¾Ý°üµÄTTLÖµ£» e) ¾²Ì¬Â·Óɱíά»¤¡£
ÔÚÏÂͼËùʾµÄÍêÁ˹ýÍØÆË½á¹¹ÖУ¬µ±Ëù¿ª·¢µÄ·ÓÉÆ÷³ÌÐò²¿Êð²¢ÔËÐÐÔÚ¼ÆËã»úCÉÏʱ£¬Ëü½«£¨×÷Ϊһ¸ö·ÓÉÆ÷£©Äܹ»Á¬Í¨Á½¸ö×ÓÍø£¬ÕýÈ·µØ²¶»ñ¡¢×ª·¢À´×Ô¼ÆËã»úAºÍ¼ÆËã»úBµÄ·Ö×飬ʹµÃÁ½¸ö×ÓÍøÖеÄÖ÷»úÄܹ»»¥Ïà·ÃÎÊ
49
¡¶¼ÆËã»úÍøÂ硷ʵÑéÖ¸µ¼Êé
192.168.1.9210.10.1.10¼ÆËã»úC¸Ã»úÆ÷ÉèÖÃΪ˫IP£º192.168.1.4410.10.1.44¼ÆËã»úAĬÈÏÍø¹ØÉèΪ£º192.168.1.44¼ÆËã»úBĬÈÏÍø¹ØÉèΪ£º10.10.1.44ͼ5-1 ʵ
ÑéÑéÖ¤»·¾³ÅäÖÃʾÒâͼ
4.ʵÑ鷽ʽ
ÿλͬѧ¶ÀÁ¢ÉÏ»ú±à³ÌʵÑ飬ʵÑéÖ¸µ¼½ÌʦÏÖ³¡Ö¸µ¼¡£ 5.²Î¿¼ÄÚÈÝ
(1) WinPcap¼ò½é
Winpcap (windows packet capture)ÊÇwindowsƽ̨ÏÂÒ»¸öÃâ·Ñ¡¢¹«¹²µÄÍøÂç·ÃÎÊϵͳ¡£¿ª·¢WinpcapÏîÄ¿µÄÄ¿µÄÔÚÓÚΪwin32Ó¦ÓóÌÐòÌṩ·ÃÎÊÍøÂçµ×²ãµÄÄÜÁ¦¡£ËüÓÃÓÚwindowsϵͳϵÄÖ±½ÓµÄÍøÂç±à³Ì¡£¹ØÓÚWinpcapµÄ½éÉÜÇë²ÎÔÄ
http://baike.http://www.china-audit.com//link?url=rQt7NLzLCFGDO8Fd2XoM3yMvpqRhA4NU6xjLdWtoS_JkMLVfgQ9mspXhMceA5RVYIl9CnA2w66uEPrSlUXKq3_¡£
Winpcap¿ª·¢°ü¿ÉÒÔÔÚhttp://www.winpcap.org/ÉÏÏÂÔØ£¬WinpcapµÄ¼¼ÊõÎĵµ¿ÉÒÔ´Óhttp://www.winpcap.org/docs/default.htmÏÂÔØ¡£¸½Â¼Öиø³öÁËÖ÷Òªº¯ÊýµÄ˵Ã÷Îĵµ¡£
(2) WinpcapÖ÷Òªº¯Êý¼°¹¦ÄܽéÉÜ
Winpcap²¿·ÖÖ÷Òªº¯Êý¼°Æä¹¦ÄܽéÉÜÈçÏ£º
(1).int pcap_findalldevs_ex(char * source, struct pcap_rmtauth * auth, pcap_if_t ** alldevs, char * errbuf)
º¯Êý¹¦ÄÜ:
Create a list of network devices that can be opened with pcap_open(). ²ÎÊý˵Ã÷:
source:a char* buffer that keeps the 'source localtion', according to the new WinPcap syntax. This source will be examined looking for adapters (local or remote) or pcap files£¬The strings that must be prepended to the 'source' in order to define if we want local/remote adapters or files is defined in the new Source Specification Syntax .
auth:a pointer to a pcap_rmtauth structure. This pointer keeps the information required to authenticate the RPCAP connection to the remote host. This parameter is not meaningful in case of a query to the local host: in that case it can be NULL.
alldevs:a 'struct pcap_if_t' pointer, which will be properly allocated inside this function.
50
Ïà¹ØÍÆ¼ö£º