如何分析网络数据包? - V2EX
请不要在回答技术问题时复制粘贴 AI 生成的内容
zengcity

如何分析网络数据包?

  •  
  •   zengcity Sep 12, 2019 5640 views
    This topic created in 2438 days ago, the information mentioned may be changed or developed.
    iOS 下学习抓包分析,已经用 NetworkExtension 捕获到包。
    比如这样的:
    45 00 00 40 00 00 40 00 40 06 bb ec 0a 08 00 02 65
    怎么分析这些网络包呢?有没有什么轮子呢?
    29 replies    2022-03-03 13:42:13 +08:00
    CallMeReznov
        1
    CallMeReznov  
       Sep 12, 2019
    wireshark 了解一下
    Chenamy2017
        2
    Chenamy2017  
       Sep 12, 2019
    wireshark + 1
    roryzh
        3
    roryzh  
       Sep 12, 2019
    wireshark
    samwalt
        4
    samwalt  
       Sep 12, 2019
    @zengcity 先确定下是什么协议
    tuding
        5
    tuding  
       Sep 12, 2019 via Android
    omni 也可以了解下
    tuding
        6
    tuding  
       Sep 12, 2019 via Android
    omnipeek
    wangkai0351
        7
    wangkai0351  
       Sep 12, 2019
    应用层的二进制分析??
    nnnToTnnn
        8
    nnnToTnnn  
       Sep 12, 2019
    wireshark
    GreyYang
        9
    GreyYang  
       Sep 12, 2019 via Android
    wireshark
    momo1999
        10
    momo1999  
       Sep 12, 2019
    ida 了解一下
    VDimos
        11
    VDimos  
       Sep 12, 2019 via Android
    wirrshark,上至 http,下至 IP 都能抓,建议配合 osi 模型一起看
    wangkai0351
        12
    wangkai0351  
       Sep 12, 2019
    @VDimos 拼写错误警告
    zengcity
        13
    zengcity  
    OP
       Sep 12, 2019
    @wangkai0351 看上去,比应用层高一些,是网络层的包。
    zengcity
        14
    zengcity  
    OP
       Sep 12, 2019
    @samwalt 网络层的包。
    wangkai0351
        15
    wangkai0351  
       Sep 12, 2019   1
    @zengcity 给你一个机会重新组织一下语言,应用层和网络层谁比谁高
    hkitdog
        16
    hkitdog  
       Sep 12, 2019 via iPhone
    WPE
    hkitdog
        17
    hkitdog  
       Sep 12, 2019 via iPhone
    要解密,百度 WPE
    zhoudaiyu
        18
    zhoudaiyu  
    PRO
       Sep 12, 2019 via iPhone
    问问大家 服务器上咋抓包?纯命令行环境
    luozic
        19
    luozic  
       Sep 12, 2019 via iPhone
    wireshark
    sinotw
        20
    sinotw  
       Sep 12, 2019
    @zhoudaiyu tcpdump,抓的包可以拿下来用 wireshark 分析
    hcymk2
        21
    hcymk2  
       Sep 12, 2019 via Android
    tshark
    salmon5
        22
    salmon5  
       Sep 12, 2019
    @zhoudaiyu tcpdump,tshark,一般 tcpdump 就可以了
    zhoudaiyu
        23
    zhoudaiyu  
    PRO
       Sep 13, 2019 via iPhone
    @sinotw
    @salmon5
    学到了,多谢!
    samwalt
        24
    samwalt  
       Sep 13, 2019
    @zengcity 是不是私有二进制协议?
    zengcity
        25
    zengcity  
    OP
       Sep 15, 2019
    @wangkai0351 看上去,比应用层低一些,是网络层的包。
    zengcity
        26
    zengcity  
    OP
       Sep 15, 2019
    @samwalt 不是私有二进制的。就普通数据包。
    zengcity
        27
    zengcity  
    OP
       Sep 15, 2019
    https://gist.github.com/zengcity/ed710ff963ce7038d4c3d43d545d6ea6

    像 NEKit 这样的解包,先看 NEKit 吧。
    samwalt
        28
    samwalt  
       Sep 17, 2019
    @zengcity 分析出数据包的结构没?
    unnamedhao
        29
    unnamedhao  
       Mar 3, 2022
    拿到的是 IP 包,可以考虑用 lwip 这个库解析
    https://savannah.nongnu.org/projects/lwip/
    About     Help     Advertise     Blog     API     FAQ     Solana     3043 Online   Highest 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 65ms UTC 08:50 PVG 16:50 LAX 01:50 JFK 04:50
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86