Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Sniffer packet capture analysis

Shulou Source: shulou.com Published: 2022-06-01 05:07:38 10月02日 Update

Bag grab analysis

Native IP address: 192.168.2.93

FTP server: 192.168.2.212

TCP connection (three-way handshake)

TCP first handshake: 192.168.2.93 sends a request connection (SYN=1) to 192.168.2.212

TCP second handshake: 192.168.2.212 response 192.168.2.93 confirm connection (ACK=1,SYN=1)

TCP third handshake: 192.168.2.93 response 192.168.2.212 (ACK=1)

TCP disconnect (four-way handshake)

1. First handshake: 192.168.2.212 sends a disconnect request to 192.168.2.93

two。 The second handshake

3. The third handshake

4. The fourth handshake

TCP header

1 Source port: 192.168.2.93 port

2. Destination port: 192.168.2.212 port

3. Serial number

4 confirmation number

5. Length of the head

six. Control information

7 window size

8. Checksum

9. Emergency pointer

10. Optional

11. Data

IP header

1 version number, head length

2 Service types

3. Total length

4. Identification code

5. Packet segmentation flag

6 slice offset

7. Survival time

8. Protocol (protocol used in the upper layer: UDP,TCP)

9. Header error checksum

10. Source IP address

11. Destination IP address

twelve。 Options and filled area

Frame header

1. Destination MAC address: MAC address of 192.168.2.212

two。 Source MAC address: MAC address of 192.168.2.93

3. Protocol type (protocol used in the upper layer: IP,IPX)

Tags: Address port target length upper layer header first second handshake type service analysis information area size header sequence serial number pointer data time Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology Redmi Docker OPPO Reno macOS