找回密码
 注册
查看: 3906|回复: 1

tcpdump抓包抓某个地址host,并写入文件时以时间命令

[复制链接]

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
发表于 2019-3-28 17:00:48 | 显示全部楼层 |阅读模式
购买主题 本主题需向作者支付 5 金钱 才能浏览

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
 楼主| 发表于 2022-12-14 09:48:06 | 显示全部楼层
[root@xa-radb-01 ~]# tcpdump  -i br0 host 192.168.0.232 -vv -nn! e2 I- ]& R+ h2 c. v5 z% J8 ^& O
dropped privs to tcpdump$ Y5 ^! V2 e* C8 s
tcpdump: listening on br0, link-type EN10MB (Ethernet), capture size 262144 bytes. x9 B6 I( ?4 o# G  d  [, @2 n, |
09:43:25.469439 IP (tos 0x0, ttl 64, id 60063, offset 0, flags [DF], proto ICMP (1), length 84)
$ }" [3 D, r- f( K" @    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11076, seq 1, length 64
% C/ {+ U+ q! L: u. G6 ?7 Q* j09:43:28.617495 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.0.41 tell 192.168.0.232, length 287 p, h$ X- F; @5 i
09:43:28.617529 ARP, Ethernet (len 6), IPv4 (len 4), Reply 192.168.0.41 is-at e8:61:1f:3e:ea:0f, length 28
: a' t" Z  A) J: x- T" R3 R09:43:28.617630 IP (tos 0x0, ttl 64, id 1210, offset 0, flags [DF], proto ICMP (1), length 84)+ u# W- C  \  R9 g1 C
    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 1, length 64
/ _2 ]8 t" X' p) Z* s09:43:28.617657 IP (tos 0x0, ttl 64, id 35091, offset 0, flags [none], proto ICMP (1), length 84)5 H$ G/ @  R' ]% g/ z9 i
    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 1, length 64
# q1 Y9 b9 n6 B* h/ S$ n09:43:29.619053 IP (tos 0x0, ttl 64, id 1479, offset 0, flags [DF], proto ICMP (1), length 84)
; X, Z" ~+ J0 j* W- P* E5 G% {1 ]    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 2, length 64  S, ^$ `7 X' o/ l$ Y/ ~6 f
09:43:29.619067 IP (tos 0x0, ttl 64, id 35130, offset 0, flags [none], proto ICMP (1), length 84)* G1 k) E% B& G- C* k3 q" `
    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 2, length 64+ _5 M# K+ ]3 `! L; H& Q) ?
09:43:30.620547 IP (tos 0x0, ttl 64, id 1534, offset 0, flags [DF], proto ICMP (1), length 84)) Z3 k7 Z2 |! g" v6 k7 d4 Y( L" _& T* V
    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 3, length 64
( b% R1 V9 y+ u, T% B* ?09:43:30.620566 IP (tos 0x0, ttl 64, id 35321, offset 0, flags [none], proto ICMP (1), length 84)
2 n, F$ N1 n$ p  |% z" T& J+ v    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 3, length 645 D& p4 p& O; ^0 S) P; s
09:43:31.621869 IP (tos 0x0, ttl 64, id 1857, offset 0, flags [DF], proto ICMP (1), length 84)0 f0 _* [- S. t: g7 g6 ~  M% K$ v
    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 4, length 645 D! D( z5 D2 T. t1 g6 K
09:43:31.621890 IP (tos 0x0, ttl 64, id 35473, offset 0, flags [none], proto ICMP (1), length 84)9 Y3 v# e1 z+ L# e' @2 d2 A
    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 4, length 641 [% ?" u4 U2 ^- `: p: n+ D
09:43:33.536520 IP (tos 0x0, ttl 64, id 62363, offset 0, flags [DF], proto ICMP (1), length 84). e. Q9 R+ y9 |. e; f1 Q, x$ Q8 @
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 1, length 64  v* U7 b9 L- l) Z
09:43:33.819142 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.0.232 tell 192.168.0.41, length 28
; I/ Q+ T. T6 g! {  w! G6 z09:43:33.819270 ARP, Ethernet (len 6), IPv4 (len 4), Reply 192.168.0.232 is-at 52:54:00:3a:43:52, length 28. h- b$ ?" E8 K6 l% c. ~
09:43:34.536049 IP (tos 0x0, ttl 64, id 62471, offset 0, flags [DF], proto ICMP (1), length 84)3 N; N+ l# t. K1 m$ l
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 2, length 64
% w+ }$ z% ?# i# V7 \5 B8 W4 e% u09:43:35.536039 IP (tos 0x0, ttl 64, id 63261, offset 0, flags [DF], proto ICMP (1), length 84)
3 o* N6 r( p' P( d    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 3, length 64* E5 w2 P, t; d, [# y3 B' l  ]
09:43:36.536014 IP (tos 0x0, ttl 64, id 63451, offset 0, flags [DF], proto ICMP (1), length 84), i+ C) L' {4 v$ E2 q6 J
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 4, length 64; d, U) m8 ~' {' I- W' ?3 B
09:43:37.536025 IP (tos 0x0, ttl 64, id 64171, offset 0, flags [DF], proto ICMP (1), length 84)' J, c, c2 n6 V: j! S9 J
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 5, length 645 R# A3 R: |! M, o) r! y! D
09:43:38.535994 IP (tos 0x0, ttl 64, id 64546, offset 0, flags [DF], proto ICMP (1), length 84)
0 e. e: W5 q* a, g: V4 P    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 6, length 64" v7 M! e' t- b& G
09:43:39.535993 IP (tos 0x0, ttl 64, id 65261, offset 0, flags [DF], proto ICMP (1), length 84)1 k1 r" f6 A& B% N9 S
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 7, length 64
: f5 o; x5 I* ?' M8 A. u9 R09:43:40.535978 IP (tos 0x0, ttl 64, id 590, offset 0, flags [DF], proto ICMP (1), length 84)
7 N+ R1 Z/ r+ v& d. I    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 8, length 64
3 ]& D* J% P2 G9 q4 Y, W, O09:43:47.885238 IP (tos 0x0, ttl 64, id 6499, offset 0, flags [DF], proto ICMP (1), length 84)
$ [3 _. t9 q: D0 r3 O7 k$ m    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 1, length 64% H% P% y+ M3 ~- m& K
09:43:48.884913 IP (tos 0x0, ttl 64, id 6872, offset 0, flags [DF], proto ICMP (1), length 84)
8 R  ~! N+ [: f; K# [; h    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 2, length 64
1 ^+ w! N4 B/ Q  M& E, U09:43:49.884924 IP (tos 0x0, ttl 64, id 6895, offset 0, flags [DF], proto ICMP (1), length 84)0 i8 t, [/ H3 T' s: O5 V
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 3, length 64& I" d& t5 s4 w  r: E. D5 P
09:43:50.884893 IP (tos 0x0, ttl 64, id 7013, offset 0, flags [DF], proto ICMP (1), length 84)& o$ [$ D) s$ `, g, N- k1 @
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 4, length 64
; o3 \1 Z( _9 g; m09:44:52.844611 IP (tos 0x0, ttl 62, id 43536, offset 0, flags [DF], proto TCP (6), length 60): c  m! [+ w& t1 E  p
您需要登录后才可以回帖 登录 | 注册

本版积分规则

返回首页|Archiver|手机版|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )

GMT+8, 2026-6-12 00:01 , Processed in 0.069663 second(s), 25 queries .

Powered by Discuz! X5.0

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表