找回密码
 注册
查看: 3904|回复: 1

tcpdump抓包抓某个地址host,并写入文件时以时间命令

[复制链接]

0

主题

0

回帖

9

积分

管理员

积分
9
QQ
发表于 2019-3-28 17:00:48 | 显示全部楼层 |阅读模式
购买主题 本主题需向作者支付 5 金钱 才能浏览

0

主题

0

回帖

9

积分

管理员

积分
9
QQ
 楼主| 发表于 2022-12-14 09:48:06 | 显示全部楼层
[root@xa-radb-01 ~]# tcpdump  -i br0 host 192.168.0.232 -vv -nn; F2 f' n/ C& Z! S- m& {4 A
dropped privs to tcpdump5 v& y9 Q# Z0 X; D' h" C# n+ b* y
tcpdump: listening on br0, link-type EN10MB (Ethernet), capture size 262144 bytes: }! ^9 D" W3 Z5 h
09:43:25.469439 IP (tos 0x0, ttl 64, id 60063, offset 0, flags [DF], proto ICMP (1), length 84)
, l4 e' m, I( d) v; z  x    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11076, seq 1, length 64
3 ~, J6 |& M/ R- w& K! Z  E09:43:28.617495 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.0.41 tell 192.168.0.232, length 28
, u4 K8 {9 {7 i! k: p" ~09:43:28.617529 ARP, Ethernet (len 6), IPv4 (len 4), Reply 192.168.0.41 is-at e8:61:1f:3e:ea:0f, length 28! c* H' k  S6 d; l8 a1 o5 o
09:43:28.617630 IP (tos 0x0, ttl 64, id 1210, offset 0, flags [DF], proto ICMP (1), length 84)
! T8 U- }# g/ o; {5 _, |4 F3 A4 W    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 1, length 64
5 y. _/ q6 \1 L8 t2 u& a: l& p; W09:43:28.617657 IP (tos 0x0, ttl 64, id 35091, offset 0, flags [none], proto ICMP (1), length 84)
* m3 J/ @  V; l& }    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 1, length 64% c+ c1 A) L% g# V9 V  c
09:43:29.619053 IP (tos 0x0, ttl 64, id 1479, offset 0, flags [DF], proto ICMP (1), length 84); Y! S& ]7 v3 L* V2 o  M# h5 [
    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 2, length 64. X8 h- i. B9 ?/ d' F2 A8 o
09:43:29.619067 IP (tos 0x0, ttl 64, id 35130, offset 0, flags [none], proto ICMP (1), length 84)
1 c# ~4 D  U+ V; x$ M    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 2, length 64
3 o6 j4 w" h# J% E3 f09:43:30.620547 IP (tos 0x0, ttl 64, id 1534, offset 0, flags [DF], proto ICMP (1), length 84)
0 X( N$ }: `8 g    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 3, length 641 A3 Y) u. K2 O- E
09:43:30.620566 IP (tos 0x0, ttl 64, id 35321, offset 0, flags [none], proto ICMP (1), length 84)# Z, l  P: i- T
    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 3, length 64; k2 |8 w0 ~9 i& o( u3 ~
09:43:31.621869 IP (tos 0x0, ttl 64, id 1857, offset 0, flags [DF], proto ICMP (1), length 84)
  B4 S% M- _; p. f# F    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 4, length 64
+ y/ q) y1 O% f- \09:43:31.621890 IP (tos 0x0, ttl 64, id 35473, offset 0, flags [none], proto ICMP (1), length 84)9 A( [1 h0 B9 q/ E" b
    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 4, length 640 c5 `. ]( q/ j7 S
09:43:33.536520 IP (tos 0x0, ttl 64, id 62363, offset 0, flags [DF], proto ICMP (1), length 84)
# n% f9 p7 g' C8 s: Q    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 1, length 64
3 c" b4 M& q" L8 c: p  q6 D09:43:33.819142 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.0.232 tell 192.168.0.41, length 28
* c/ g1 S4 K1 H  C  ~- s3 {09:43:33.819270 ARP, Ethernet (len 6), IPv4 (len 4), Reply 192.168.0.232 is-at 52:54:00:3a:43:52, length 28# |& y6 D' V) U+ d) D# N
09:43:34.536049 IP (tos 0x0, ttl 64, id 62471, offset 0, flags [DF], proto ICMP (1), length 84)! Y% m0 a0 B" c! s! \$ r' \$ f
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 2, length 64
2 i4 h) r) A" a+ b" ]4 `+ u09:43:35.536039 IP (tos 0x0, ttl 64, id 63261, offset 0, flags [DF], proto ICMP (1), length 84)/ Y- J7 f3 O( |# W) X' u" q
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 3, length 64
0 S9 O% {. s! G5 K* m: v0 G09:43:36.536014 IP (tos 0x0, ttl 64, id 63451, offset 0, flags [DF], proto ICMP (1), length 84)
# E7 ^6 S7 p: E5 k9 }# |    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 4, length 64* O1 N. g. O+ {( r3 s
09:43:37.536025 IP (tos 0x0, ttl 64, id 64171, offset 0, flags [DF], proto ICMP (1), length 84)
* ?! \, I1 R0 a! B9 M& F" \    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 5, length 645 \( |! g; F* D/ |4 R2 R5 m6 _
09:43:38.535994 IP (tos 0x0, ttl 64, id 64546, offset 0, flags [DF], proto ICMP (1), length 84)
8 T- C" R8 G( d    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 6, length 64
+ p' W* W" N9 G09:43:39.535993 IP (tos 0x0, ttl 64, id 65261, offset 0, flags [DF], proto ICMP (1), length 84)
8 _5 E8 x7 f/ q- G! T    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 7, length 64
) V4 k! @4 f& g09:43:40.535978 IP (tos 0x0, ttl 64, id 590, offset 0, flags [DF], proto ICMP (1), length 84)/ e% I! d& @3 C" X* V
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 8, length 64
2 M7 W  @, w0 Y3 c09:43:47.885238 IP (tos 0x0, ttl 64, id 6499, offset 0, flags [DF], proto ICMP (1), length 84)
: h/ z1 G/ s( O* O) H' w. j: }    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 1, length 64
( K  s% p% }% G09:43:48.884913 IP (tos 0x0, ttl 64, id 6872, offset 0, flags [DF], proto ICMP (1), length 84)
9 H3 A: p5 j+ F& n    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 2, length 64/ P/ A/ Q, k. N9 p
09:43:49.884924 IP (tos 0x0, ttl 64, id 6895, offset 0, flags [DF], proto ICMP (1), length 84)
0 k" F7 U4 D; v* e    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 3, length 64- p2 L$ u, A# L& P
09:43:50.884893 IP (tos 0x0, ttl 64, id 7013, offset 0, flags [DF], proto ICMP (1), length 84)( \* t/ p4 T3 m# W4 A! a5 t
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 4, length 64
" z' ~) \* n9 L; t- ^09:44:52.844611 IP (tos 0x0, ttl 62, id 43536, offset 0, flags [DF], proto TCP (6), length 60)
0 a, z1 y( l( {( K0 V+ n: f
您需要登录后才可以回帖 登录 | 注册

本版积分规则

返回首页|Archiver|手机版|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )

GMT+8, 2026-6-11 22:59 , Processed in 0.027273 second(s), 25 queries .

Powered by Discuz! X5.0

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表