Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Linux Scapy performs the detailed process of arp packet

Shulou Source: shulou.com Published: 2022-06-01 02:47:03 10月04日 Update

Root@hak:~# scapy

WARNING: No route found for IPv6 destination: (no default route?)

INFO: Can't import python ecdsa lib. Disabled certificate manipulation tools

Welcome to Scapy (unknown.version)

A=Ether () / ARP ()

A.show ()

# [Ethernet] #

Dst= 00:50:56:ef:49:1f

Src= 00:0c:29:e2:bb:15

Type= 0x806

# [ARP] #

Hwtype= 0x1

Ptype= 0x800

Hwlen= 6

Plen= 4

Op= who-has

Hwsrc= 00:0c:29:e2:bb:15

Psrc= 192.168.80.250

Hwdst= 00:00:00:00:00:00

Pdst= 0.0.0.0

Arp1=srp (Ether (src='00:0c:29:e2:bb:15',dst='FF:FF:FF:FF:FF:FF') / ARP (op=1,hwsrc='00:0c:29:e2:bb:15',hwdst='00:00:00:00:00:00',psrc='192.168.80.250',pdst='192.168.80.251',))

Begin emission:

* Finished to send 1 packets.

Received 1 packets, got 1 answers, remaining 0 packets

1) > print (arp1)

()

Generate received response and unreceived response tuples

2) View the data type of arp1:

Print (type (arp1))

Is a tuple

3) use the tuple method to print only the received message:

Print (arp1 [0])

4) display arp1 [0] data type:

Print (type (arp1 [0]))

5) check the processing method of the 'scapy.plist.SndRcvList data type (check https://fossies.org/dox/scapy-2.3.3/ on the Internet) use the method of res

6) generate packets that are sent and received in response packets, and list the packet res methods

Print (arp1 [0] .res) * first pair of sending and sending packets

[,)]

7) propose packet collection data

Print (arp1 [0] .res [0] [1])

8) View arp1 [0] .res [0] [1] data type:

Print (type (arp1 [0] .res [0] [1]))

9) check the processing method of the scapy.layers.l2.Ether data type (check https://fossies.org/dox/scapy-2.3.3/ on the Internet)

Static Public Attributes

String name = "Ethernet"

List fields_desc

The method of

10) use the fields method (generate the corresponding dictionary) to extract the packet receiving data:

Print (arp1 [0] .res [0] [1] .fields)

{'src':' 001FD 03mm, 'dst':' 00VOCLAR 0cVOCRAPHY 29CVOCLARO 29RAPHY 2BBREX 15, 'type': 2054}

11) use show method to read packet receiving data:

Print (arp1 [0] .res [0] [1] .show ())

# [Ethernet] #

Dst= 00:0c:29:e2:bb:15

Src= 00:0c:29:21:fd:03

Type= 0x806

# [ARP] #

Hwtype= 0x1

Ptype= 0x800

Hwlen= 6

Plen= 4

Op= is-at

Hwsrc= 00:0c:29:21:fd:03

Psrc= 192.168.80.251

Hwdst= 00:0c:29:e2:bb:15

Pdst= 192.168.80.250

# [Padding] #

Load='\ X00\ x00\ x00

12) use show method to read ARP in packet receiving data:

Print (arp1 [0] .res [0] [1] [1] .show ())

# [ARP] #

Hwtype= 0x1

Ptype= 0x800

Hwlen= 6

Plen= 4

Op= is-at

Hwsrc= 00:0c:29:21:fd:03

Psrc= 192.168.80.251

Hwdst= 00:0c:29:e2:bb:15

Pdst= 192.168.80.250

# [Padding] #

Load='\ X00\ x00\ x00

13) generate the desired print result:

Print ('ip:' + arp1 [0] .res [0] [1] [1] .fields [' psrc'] + 'mac:' + arp1 [0] .res [0] [1] [1] .fields [' hwsrc'])

Ip:192.168.80.251 mac:00:0c:29:21:fd:03

14) data structure:

Tags: Data method type processing dictionary message data structure structure result process Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno macOS Apple Huawei OPPO Reno Shulou Information