易陆发现互联网技术论坛

 找回密码
 开始注册
查看: 3904|回复: 1
收起左侧

tcpdump抓包抓某个地址host,并写入文件时以时间命令

[复制链接]
发表于 2019-3-28 17:00:48 | 显示全部楼层 |阅读模式
购买主题 本主题需向作者支付 5 金钱 才能浏览
 楼主| 发表于 2022-12-14 09:48:06 | 显示全部楼层
[root@xa-radb-01 ~]# tcpdump  -i br0 host 192.168.0.232 -vv -nn
' N5 F4 l- l6 [  a8 Edropped privs to tcpdump
2 H2 v! w8 L- e- l6 D6 [( jtcpdump: listening on br0, link-type EN10MB (Ethernet), capture size 262144 bytes" o4 a, U% k+ R6 U# ?
09:43:25.469439 IP (tos 0x0, ttl 64, id 60063, offset 0, flags [DF], proto ICMP (1), length 84)5 |, `5 b: C6 ^0 q" b' V3 Z
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11076, seq 1, length 64
  ^- l4 D' }- M( ^8 `: N09:43:28.617495 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.0.41 tell 192.168.0.232, length 28
9 U: M; T' T" b. j: C09:43:28.617529 ARP, Ethernet (len 6), IPv4 (len 4), Reply 192.168.0.41 is-at e8:61:1f:3e:ea:0f, length 289 ^+ ^$ l+ `( S8 x  i* o$ C
09:43:28.617630 IP (tos 0x0, ttl 64, id 1210, offset 0, flags [DF], proto ICMP (1), length 84)
% A; s" Q- I. E  z    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 1, length 640 |. y1 f: x' m# T# O6 h
09:43:28.617657 IP (tos 0x0, ttl 64, id 35091, offset 0, flags [none], proto ICMP (1), length 84)8 A7 y, P2 J9 V5 P. \
    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 1, length 64
; _* Z6 s* b" n3 O% h  \" B4 ?' S2 Z09:43:29.619053 IP (tos 0x0, ttl 64, id 1479, offset 0, flags [DF], proto ICMP (1), length 84)
5 P9 E' \# c% {8 X( t* A' f& I3 r    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 2, length 64
3 g0 N: Q+ b) ^0 b) o6 V6 s09:43:29.619067 IP (tos 0x0, ttl 64, id 35130, offset 0, flags [none], proto ICMP (1), length 84)
" _0 i4 o1 f8 n5 s) D    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 2, length 649 G& i; X/ p' N
09:43:30.620547 IP (tos 0x0, ttl 64, id 1534, offset 0, flags [DF], proto ICMP (1), length 84)
: Z: Q1 K' a/ P    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 3, length 64
" Z9 Q5 `1 Z& ?; V3 ]- W  Q09:43:30.620566 IP (tos 0x0, ttl 64, id 35321, offset 0, flags [none], proto ICMP (1), length 84)
7 h6 E% F0 |9 ]) e  D$ V    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 3, length 64
  u' t9 g9 y8 O$ @' b- ^$ N09:43:31.621869 IP (tos 0x0, ttl 64, id 1857, offset 0, flags [DF], proto ICMP (1), length 84)7 R# Y% f1 Y6 \  P; T$ B! R9 v
    192.168.0.232 > 192.168.0.41: ICMP echo request, id 11077, seq 4, length 64  p+ g$ a4 A; K+ J' g) I# C0 `
09:43:31.621890 IP (tos 0x0, ttl 64, id 35473, offset 0, flags [none], proto ICMP (1), length 84)
8 j7 ^' \( f4 R5 s1 i" F( m* T- A    192.168.0.41 > 192.168.0.232: ICMP echo reply, id 11077, seq 4, length 646 o% b, I' p8 S; [/ _
09:43:33.536520 IP (tos 0x0, ttl 64, id 62363, offset 0, flags [DF], proto ICMP (1), length 84)
9 V9 \# v8 R- ~0 v, O4 t    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 1, length 64
/ X) V  Z; E) f& G# V3 N1 L7 h7 X* d09:43:33.819142 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.0.232 tell 192.168.0.41, length 28$ }: }$ m% b" h, d; V! j# P+ e- z  q
09:43:33.819270 ARP, Ethernet (len 6), IPv4 (len 4), Reply 192.168.0.232 is-at 52:54:00:3a:43:52, length 285 H8 N9 p7 t. U/ l3 d
09:43:34.536049 IP (tos 0x0, ttl 64, id 62471, offset 0, flags [DF], proto ICMP (1), length 84)
( F6 v6 _* H3 Z- a- m: o8 ^3 H    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 2, length 64- P7 h0 l8 ^% z1 e( W9 Z) S
09:43:35.536039 IP (tos 0x0, ttl 64, id 63261, offset 0, flags [DF], proto ICMP (1), length 84)
6 `* ?& q2 s3 t# [: A& u% L    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 3, length 64% L) v5 |1 b8 r: x0 |8 i
09:43:36.536014 IP (tos 0x0, ttl 64, id 63451, offset 0, flags [DF], proto ICMP (1), length 84)
7 T: o6 t8 U* g7 p. A    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 4, length 641 \/ e+ i, w+ t* o  T. ~+ g
09:43:37.536025 IP (tos 0x0, ttl 64, id 64171, offset 0, flags [DF], proto ICMP (1), length 84)
' h1 W' b3 |5 g. R1 J    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 5, length 64: j* e. l) N" b8 i# N! @
09:43:38.535994 IP (tos 0x0, ttl 64, id 64546, offset 0, flags [DF], proto ICMP (1), length 84)5 Y, W: w2 \8 }0 u8 M; f
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 6, length 64/ e5 L% P5 K8 t. T
09:43:39.535993 IP (tos 0x0, ttl 64, id 65261, offset 0, flags [DF], proto ICMP (1), length 84)
6 \( |! N( {7 `, g    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 7, length 64
) Z' _  Y  r5 Y* v: \4 s09:43:40.535978 IP (tos 0x0, ttl 64, id 590, offset 0, flags [DF], proto ICMP (1), length 84)" ]- t8 w& U, t1 |* N* X5 B2 Y
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11078, seq 8, length 64
+ r& x2 K- l9 E+ Q# G09:43:47.885238 IP (tos 0x0, ttl 64, id 6499, offset 0, flags [DF], proto ICMP (1), length 84)
' d) }* F2 J$ e, E! J) `( H1 e& P    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 1, length 647 D9 R& g4 V# _: i
09:43:48.884913 IP (tos 0x0, ttl 64, id 6872, offset 0, flags [DF], proto ICMP (1), length 84)
2 |7 w* Q, ~* v. j# n* h5 |# [+ C    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 2, length 64
9 G# J2 A) K: h/ k! g09:43:49.884924 IP (tos 0x0, ttl 64, id 6895, offset 0, flags [DF], proto ICMP (1), length 84)4 F+ v- _) U* z
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 3, length 645 C6 u# l  n5 n: r( U" l
09:43:50.884893 IP (tos 0x0, ttl 64, id 7013, offset 0, flags [DF], proto ICMP (1), length 84): O6 x& W7 U) c2 H2 K2 d
    192.168.0.232 > 192.168.0.1: ICMP echo request, id 11080, seq 4, length 64: _1 a$ m% I( i. V4 t
09:44:52.844611 IP (tos 0x0, ttl 62, id 43536, offset 0, flags [DF], proto TCP (6), length 60)
2 q$ N9 ]7 L! j) ~. q
您需要登录后才可以回帖 登录 | 开始注册

本版积分规则

关闭

站长推荐上一条 /4 下一条

北京云银创陇科技有限公司以云计算运维,代码开发

QQ|返回首页|Archiver|小黑屋|易陆发现技术论坛 点击这里给我发消息

GMT+8, 2026-4-8 10:41 , Processed in 0.094068 second(s), 25 queries .

Powered by Discuz! X3.4 Licensed

© 2012-2025 Discuz! Team.

快速回复 返回顶部 返回列表