当前位置: 代码迷 >> 综合 >> tcpdump icmp分析
  详细解决方案

tcpdump icmp分析

热度:17   发布时间:2024-02-09 22:50:18.0

src 192.168.2.9

dst 192.168.2.131

ping 192.168.2.131 -c 1

icmp 协议类型

08--请求

00--响应

 

root@2233:jessica$tcpdump -i any -nn -vvvv -XX icmp
tcpdump: listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
13:15:21.778383 IP (tos 0x0, ttl 64, id 23124, offset 0, flags [DF], proto ICMP (1), length 84)
192.168.2.9 > 192.168.2.131: ICMP echo request, id 2951, seq 1, length 64
0x0000:  0004 0001 0006 0050 563c 1ad0 0000 0800  .......PV<......
0x0010:  4500 0054 5a54 4000 4001 5a78 c0a8 0209  E..TZT@.@.Zx....
0x0020:  c0a8 0283 0800 e435 0b87 0001 291f d56f  .......5....)..o
0x0030:  0000 0000 3fe0 0b00 0000 0000 1011 1213  ....?...........
0x0040:  1415 1617 1819 1a1b 1c1d 1e1f 2021 2223  .............!"#
0x0050:  2425 2627 2829 2a2b 2c2d 2e2f 3031 3233  $%&'()*+,-./0123
0x0060:  3435 3637 0000 0000 0000 0000 0000 0000  4567............
0x0070:  0000 0000                                ....


13:15:21.778983 IP (tos 0x0, ttl 64, id 63274, offset 0, flags [none], proto ICMP (1), length 84)
192.168.2.131 > 192.168.2.9: ICMP echo reply, id 2951, seq 1, length 64
0x0000:  0000 0001 0006 000c 294d d956 0000 0800  ........)M.V....
0x0010:  4500 0054 f72a 0000 4001 fda1 c0a8 0283  E..T.*..@.......
0x0020:  c0a8 0209 0000 ec35 0b87 0001 291f d56f  .......5....)..o
0x0030:  0000 0000 3fe0 0b00 0000 0000 1011 1213  ....?...........
0x0040:  1415 1617 1819 1a1b 1c1d 1e1f 2021 2223  .............!"#
0x0050:  2425 2627 2829 2a2b 2c2d 2e2f 3031 3233  $%&'()*+,-./0123
0x0060:  3435 3637 0000 0000 0000 0000 0000 0000  4567............
0x0070:  0000 0000                                ....