2.
: Wireshark;
Wireshark.
- Wireshark ( );
- .
Wireshark.
2. Capture -> Options. (. 2.1):
. 2.1.
− Interface ;
, . , , .
− Buffer size ( 1 );
, .
− Capture packets in promiscuous mode .
− Limit each packet to ( ) ;
− Capture Filter ;
, , , . , .
− Capture File(s) ;
.
− Stop Capture ;
− Display Options ;
, .
− Name Resolution , .
3. Capture packets in promiscuous mode ( ). , .
4. MS-DOS ARP arp -d. Wireshark Capture. ping <_> ( IP- ). Ping , Stop.
|
|
Wireshark , . 2.2.
. 2.2. Wireshark
:
− ;
− ;
− ;
− ;
− ASCII.
( , , , ). , . , + , . , .
. , . : arp ARP, tcp , TCP.
5. ICMP- Filter icmp Apply.
, , .
, == ( eq). :
a.!= (ne) , : eth.type!= 0x0800;
b. > (gt) , : tcp.srcport > 1023;
c. < (lt) , : frame.pkt_len lt 60;
d. >= (ge) , : frame.pkt_len ge 60;
e. <= (le) , : tcp.dstport <=1023.