﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>BlogJava-paulwong-随笔分类-WIRESHARK</title><link>http://www.blogjava.net/paulwong/category/53765.html</link><description /><language>zh-cn</language><lastBuildDate>Fri, 26 Jul 2013 07:28:25 GMT</lastBuildDate><pubDate>Fri, 26 Jul 2013 07:28:25 GMT</pubDate><ttl>60</ttl><item><title>WIRESHARK资源</title><link>http://www.blogjava.net/paulwong/archive/2013/07/23/401871.html</link><dc:creator>paulwong</dc:creator><author>paulwong</author><pubDate>Tue, 23 Jul 2013 07:25:00 GMT</pubDate><guid>http://www.blogjava.net/paulwong/archive/2013/07/23/401871.html</guid><wfw:comment>http://www.blogjava.net/paulwong/comments/401871.html</wfw:comment><comments>http://www.blogjava.net/paulwong/archive/2013/07/23/401871.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/paulwong/comments/commentRss/401871.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/paulwong/services/trackbacks/401871.html</trackback:ping><description><![CDATA[需求：要抓同一网络上某一设备，如平板的网络传输包以进行分析，访问哪些网址等。<br />
<br />
软件：WIRESHARK，金山的WIFI共享<br />
<br />
环境：由于WIRESHARK只能抓本电脑(安装此软件上的PC)的包，因此要在装一个无线网卡，再安装一个金山的WIFI共享软件，将此无线网卡作为热点共享出去。另一设备通过WIFI连上此热点。这样此设备上的所有都经过此无线网卡，就可以被WIRESHARK抓到。<br /><br /><div>1.将无线网卡连上路由，产生IP1</div><div>2.启动CONNECTIFY ME，共享来源选IP1</div><div>3.客户端通过WIFI连CONNECTIFY ME</div><div>4.则客户端向INTERNET发送请求时，请求是通过IP1发送的，收到的回应是通过CONNECTIFY ME返回的</div>
<br />
使用：打开WIRESHARK，选择抓哪个网卡，再配置过滤条件，点击开始即可。现总结了下这个过滤条件：<br />
<div style="background-color:#eeeeee;font-size:13px;border:1px solid #CCCCCC;padding-right: 5px;padding-bottom: 4px;padding-left: 4px;padding-top: 4px;width: 98%;word-break:break-all"><!--<br />
<br />
Code highlighting produced by Actipro CodeHighlighter (freeware)<br />
http://www.CodeHighlighter.com/<br />
<br />
-->ip.src&nbsp;==&nbsp;192.168.1.113&nbsp;&amp;&amp;&nbsp;http.request.method=="GET"&nbsp;&amp;&amp;&nbsp;http.user_agent&nbsp;contains&nbsp;"014440000001041"</div><br />都是以协议开头，属性名称，表达式符号，属性值，连接符号，其他表达式的这种格式。<br /><br /><br />wireshark过滤语法总结<br /><a href="http://blog.csdn.net/cumirror/article/details/7054496" target="_blank">http://blog.csdn.net/cumirror/article/details/7054496</a><img src ="http://www.blogjava.net/paulwong/aggbug/401871.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/paulwong/" target="_blank">paulwong</a> 2013-07-23 15:25 <a href="http://www.blogjava.net/paulwong/archive/2013/07/23/401871.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>