捕获ARP包 Time Source Destination Protocol Info 169.43212 工bm79:1a:78 ohas192.168.0.17Te192168,11.221 179.433506D- Link f9:ef:9cIbm_79:1a:78 ARP 192.168.0.1isat00:13:46:f9:ef:9c b Frame 16(42 bytes on wire, 42 bytes captured) > Ethernet II, src: Ibm_79: 1a: 78(00: 0d: 60: 79: 1a: 78), Dst: Broadcast (ff: ff: ff: ff: ff: ff) y Destination Broadcast (ff: ff: ff: ff: ff: ff) Address: Broadcast (ff: ff: ff: ffff:ff) 目的MAC(网卡)地址填写广播地址 Multicast This is a MULTICaST fi a-tocaTTy Administrated Address: This is Not a factory default address v sour ce:Ibm_79:1a:78(00:0d:60:79:1a:78) Address:Ibm79:1a:78(00:0d:60:79:1a:78) Multicast: This is a unicast fram Locally Administrated Address: This is a FACTORY DEFAULT address Type: ARP (0x0806)+ 网络层协议类型(ARP) Address Resolution protocol(request) Hardware type: Ethernet (ox00o1 Protocol type: IP (OX0800) Hardware size: 6 Protocol size; 4 Opcode: request (oxooo1D ARP请求 请求者的MAC(网卡)地址 sender MAC address: Ibm_79: 1a: 78 (00: 0d: 60: 79: 1a: 78) ender ip address:192.168.11.221(192.168.11.221)← 请求者的P地址 Target MAc address:00:00:00_00:00:00(00:00:00:00:00:00) Target IP address:192.168,0.1(192.168.0,1) 查询对象的P地址 000十 f000d60791a78080600 0010 0020
捕获ARP包 ARP请求 查询对象的IP地址 请求者的IP地址 请求者的MAC(网卡)地址 目的MAC(网卡)地址填写广播地址 网络层协议类型(ARP)
ARP响应包 No.Time Source Destination Protocol Info 169.432127bm79:1a:78 Broadcast who has192.168.0.1?Te11192.168.11.221 192.168.0,115at00:13:46:19:ef:g b Frame 17 (60 bytes on wire, 60 bytes captured) 7 Ethernet II, src: D-Link_f9: ef: 9c (00: 13: 46: f9: ef: 9c), Dst: Ibm_79: 1a: 78 (00: od: 60: 79: 1a: 78) y Destination: Ibm_79: 1a: 78 (o0: od: 60: 79: 1a: 78) Address-:Ibm79:1a:78(00:0d:60:791a:78 目的MAC(网卡)地址填写请求者地址 Multicast This is a UNICAST frame ........=Locally Administrated Address: This is a FACTORY DEFAULT address 7 Source: D-Link_f9: ef: 9c (00: 13: 46: f9: ef: 9c) Address: D-Link_f9: ef: 9c (00: 13: 46: f9: ef: 90) Multicast: This is a unicast frame Locally Administrated Address: This is a FACTORY DEFAULT address Type: ARP (OX0806) Trai1er:00000000000000000o000000000000000o00 7 Address Resolution Protocol (reply) Hardware type: Ethernet (oxo001) Protocol type: IP (OX0800) Hardware si Protocol size: 4 opcode: reply (ox0oo2) ARP响 响应者的MAC(网卡)地址 Sender MAC address: D-Link_f9: ef: 9c (00: 13: 46: f9: ef: 9c Sender IP address:192.168.0.1(92.168:0,1)响应者的P地址 arget mAc address: Ibm_79: la: 78(00: od: 60: 79: 1a: 78) Target Ip address:192.168.11.221(192.168.11.221) 00000d60791a7800134619e19c080600
ARP响应包 目的MAC(网卡)地址填写请求者地址 ARP响应 响应者的MAC(网卡)地址 响应者的IP地址
捕获|包 No. Time ource De Destination ProtocolIn 232.1200860.0.0.0 255.255.255.255 DHCPDHCP Discover- Tr ansaction ID 0x44c3cf4 242.411667 255.255.255.255 DHCPDHCP Discover Transaction ID 0X14715801 20.184.161.174 PNG Frame 25 (67 bytes on wire, 67 bytes captured) b Ethernet II, Src: EdimaxCo-_36: 4e: d8 (00: 00: b4: 36: 4e: d8), Dst: unispher-_40: 8e: af (00: 90: 1a: 40: 8e: af) b PPP-over-Ethernet session b Point-to-Point Protocol Internet Protoco1,src:220.184.161.174(220.184.161.174),Dst:207.46.24.65(207.46.24.65 version: 4 Header length: 20 bytes P协议版本 b Differentiated services Field: 0xoo (DSCP 0x00: Default: ECN: 0x0o) Total Length: 45 Ident ification: 0x1666 (5734) A Flags: 0x04 (Dont Fragment) Fragment offset: o Time to live: 64 Protoco1:TcP(0×06) 高层协议类型 b Header check sum: oxbe&e [correct] source. 220.184.161.174(220.184.161,174) 源、目的P地址 estination:207.46.24.65(20746.24.65 b Transmission control Protocol, src Port: 1030 (1030), Dst Port: 1863(1863), Seg: 204886, Ack: 78343764. 00101376002f0021 0020 0030 00504e Version Type of service 0040470d0a Identification Fragment offset Time to live Protocol Header checksum Source address P数据包格式 Destination address Options(0 or more words)
捕获IP包 IP数据包格式 高层协议类型 源、目的IP地址 IP协议版本
捕获DNS包 DNS服务器地址 No.Time Source Destination Protocol. Info 56021.489006220.191.115.176202.96.64.68 DNS Standard query A ww. zju. edu. cn 56221.926514202.96.64.68 220.191.115.176DNs standard query response A 61.. 193.61 b User patag am protocol, src Port: 1969(1969), Dst Port: domain(53)6508 1202. 96. 64. 08) DNS服务端口 Transaction ID: 0x0003 Flags: 0x0100 (standard query) Response: Message is a query DNS查询请求 opcode: standard query (o) Truncated: Message is not truncated Recursion desired: Do query recursively Non-authent icated dat a ok: Non -aut henticated data is unacceptable uestions: 1 Answer rrs: Q Authority RRs: 0 Additional RRs: 0 y Quer 1es DNS查询内容:www.zju.edu.cn 7www.zju.ec du. cn: type A, class I Name:www.zju.educn DNS查询项目:地址 Type: A (Host address) Class:IN(0×0001) 地址类型: Internet 00000901a415525000 91a7888641100.AU%.y.x.d. 0010067d003e00214500003c1aa40000801 }.>,!E 0020c4f8dcbf73boca60404407b100350028 D...5 030a8
捕获DNS包 DNS查询请求 DNS服务端口 DNS服务器地址 DNS查询内容:www.zju.edu.cn DNS查询项目:地址 地址类型:Internet
DNS查询响应 N Destination I Protocol Info 56021.489006220191.115,176202.96.64.68 DNS standardqueryAwww.zju.edu.cn 514202。96。64.68 220.. 176 DNS Standard query response A 61. 175.193.61 b User Datagr am Protoco l, src Port: domain (53),Dst 7 Domain Name system (response Transaction ID: 0x0003 Flags: 0x8180 (standard query response, No error Response: Message is a response DNS查询响应 0000. opcode: standard query (o) Authoritative: server is not an authority for doma in Truncated: Message is not truncated Recursion desired: Do query recursively Recursion available: server can do recursive queries Answer authenticated: Answer/authority portion was not authenticated by the se 0000= Reply code: No error (o) Questions: 1 Answer RRs: 1 hority RI Additiona Rrs: 0 v Quer les wwzju. edu. cn: type A, c1 DNS查询请求内容 Name Type: A (Host address) Class: IN (OX0001) v Answers ywww.zju.educn:typeA,classIn,addr61.175.193.61 DNS查询结果 0 0070 706861c010
DNS查询响应 DNS查询响应 DNS查询请求内容 DNS查询结果