Sniffer packet capture analysis
Bag grab analysis
Native IP address: 192.168.2.93
FTP server: 192.168.2.212
TCP connection (three-way handshake)
TCP first handshake: 192.168.2.93 sends a request connection (SYN=1) to 192.168.2.212
TCP second handshake: 192.168.2.212 response 192.168.2.93 confirm connection (ACK=1,SYN=1)
TCP third handshake: 192.168.2.93 response 192.168.2.212 (ACK=1)
TCP disconnect (four-way handshake)
1. First handshake: 192.168.2.212 sends a disconnect request to 192.168.2.93
two。 The second handshake
3. The third handshake
4. The fourth handshake
TCP header
1 Source port: 192.168.2.93 port
2. Destination port: 192.168.2.212 port
3. Serial number
4 confirmation number
5. Length of the head
six. Control information
7 window size
8. Checksum
9. Emergency pointer
10. Optional
11. Data
IP header
1 version number, head length
2 Service types
3. Total length
4. Identification code
5. Packet segmentation flag
6 slice offset
7. Survival time
8. Protocol (protocol used in the upper layer: UDP,TCP)
9. Header error checksum
10. Source IP address
11. Destination IP address
twelve。 Options and filled area
Frame header
1. Destination MAC address: MAC address of 192.168.2.212
two。 Source MAC address: MAC address of 192.168.2.93
3. Protocol type (protocol used in the upper layer: IP,IPX)