Linux基础学习之利用tcpdump抓包实例代码
<p><span><strong>简介</strong></span></p>
<p>
很多时候我们的系统部署在Linux系统上面,在一些情况下定位问题就需要查看各个系统之间发送数据报文是否正常,下面我就简单讲解一下如何使用tcpdump抓包</p>
<p>
网络数据包截获分析工具。支持针对网络层、协议、主机、网络或端口的过滤。并提供and、or、not等逻辑语句帮助去除无用的信息。</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_419166">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump - dump traffic on a network</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<span><strong>tcpdump的命令格式</strong></span></p>
<p>
tcpdump的参数众多,通过man tcpdump可以查看tcpdump的详细说明,这边只列一些自己常用的参数:</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_595427">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump [-i 网卡] -nnAX </code><code class="bash string">'表达式'</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>各参数说明如下:</strong></p>
<ul>
<li>
-i:interface 监听的网卡。</li>
<li>
-nn:表示以ip和port的方式显示来源主机和目的主机,而不是用主机名和服务。</li>
<li>
-A:以ascii的方式显示数据包,抓取web数据时很有用。</li>
<li>
-X:数据包将会以16进制和ascii的方式显示。</li>
<li>
表达式:表达式有很多种,常见的有:host 主机;port 端口;src host 发包主机;dst host 收包主机。多个条件可以用and、or组合,取反可以使用!,更多的使用可以查看man 7 pcap-filter。</li>
</ul>
<p>
<span><strong>例子</strong></span></p>
<p>
<strong>不指定任何参数</strong></p>
<p>
监听第一块网卡上经过的数据包。主机上可能有不止一块网卡,所以经常需要指定网卡。</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_389964">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>监听特定网卡</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_507152">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump -i en0</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>监听特定主机</strong></p>
<p>
例子:监听本机跟主机182.254.38.55之间往来的通信包。</p>
<p>
备注:出、入的包都会被监听。</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_964028">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump host 182.254.38.55</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>特定来源、目标地址的通信</strong></p>
<p>
特定来源</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_521380">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump src host </code><code class="bash functions">hostname</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
特定目标地址</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_166657">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump dst host </code><code class="bash functions">hostname</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
如果不指定src跟dst,那么来源 或者目标 是hostname的通信都会被监听</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_851821">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump host </code><code class="bash functions">hostname</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>特定端口</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_49509">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump port 3000</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>监听TCP/UDP</strong></p>
<p>
服务器上不同服务分别用了TCP、UDP作为传输层,假如只想监听TCP的数据包</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_407964">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump tcp</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>来源主机+端口+TCP</strong></p>
<p>
监听来自主机123.207.116.169在端口22上的TCP数据包</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_361387">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump tcp port 22 and src host 123.207.116.169</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
监听特定主机之间的通信</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_105161">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump ip host 210.27.48.1 and 210.27.48.2</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
210.27.48.1除了和210.27.48.2之外的主机之间的通信</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_612840">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump ip host 210.27.48.1 and ! 210.27.48.2</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>稍微详细点的例子</strong></p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_692262">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump tcp -i eth1 -t -s 0 -c 100 and dst port ! 22 and src net 192.168.1.0</code><code class="bash plain">/24</code> <code class="bash plain">-w .</code><code class="bash plain">/target</code><code class="bash plain">.cap</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
(1)tcp: ip icmp arp rarp 和 tcp、udp、icmp这些选项等都要放到第一个参数的位置,用来过滤数据报的类型</p>
<p>
(2)-i eth1 : 只抓经过接口eth1的包</p>
<p>
(3)-t : 不显示时间戳</p>
<p>
(4)-s 0 : 抓取数据包时默认抓取长度为68字节。加上-S 0 后可以抓到完整的数据包</p>
<p>
(5)-c 100 : 只抓取100个数据包</p>
<p>
(6)dst port ! 22 : 不抓取目标端口是22的数据包</p>
<p>
(7)src net 192.168.1.0/24 : 数据包的源网络地址为192.168.1.0/24</p>
<p>
(8)-w ./target.cap : 保存成cap文件,方便用ethereal(即wireshark)分析</p>
<p>
<strong>抓http包</strong></p>
<p>
TODO</p>
<p>
<strong>限制抓包的数量</strong></p>
<p>
如下,抓到1000个包后,自动退出</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_192299">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump -c 1000</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<strong>保存到本地</strong></p>
<p>
备注:tcpdump默认会将输出写到缓冲区,只有缓冲区内容达到一定的大小,或者tcpdump退出时,才会将输出写到本地磁盘</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_128574">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump -n -vvv -c 1000 -w </code><code class="bash plain">/tmp/tcpdump_save</code><code class="bash plain">.cap</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
也可以加上-U强制立即写到本地磁盘(一般不建议,性能相对较差)</p>
<p>
<span><strong>实战例子</strong></span></p>
<p>
先看下面一个比较常见的部署方式,在服务器上部署了nodejs server,监听3000端口。nginx反向代理监听80端口,并将请求转发给nodejs server(127.0.0.1:3000)。</p>
<p>
浏览器 -> nginx反向代理 -> nodejs server</p>
<p>
问题:假设用户(183.14.132.117)访问浏览器,发现请求没有返回,该怎么排查呢?</p>
<p>
步骤一:查看请求是否到达nodejs server -> 可通过日志查看。</p>
<p>
步骤二:查看nginx是否将请求转发给nodejs server。</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_484058">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump port 8383</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
这时你会发现没有任何输出,即使nodejs server已经收到了请求。因为nginx转发到的地址是127.0.0.1,用的不是默认的interface,此时需要显示指定interface</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_475717">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump port 8383 -i lo</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
备注:配置nginx,让nginx带上请求侧的host,不然nodejs server无法获取 src host,也就是说,下面的监听是无效的,因为此时对于nodejs server来说,src host 都是 127.0.0.1</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_87810">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump port 8383 -i lo and src host 183.14.132.117</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
步骤三:查看请求是否达到服务器</p>
<div class="jb51code">
<div>
<div class="syntaxhighlighterbash" id="highlighter_182946">
<div class="toolbar">
<span>?</span>
</div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr>
<td class="gutter">
<div class="line number1 index0 alt2">
1</div>
</td>
<td class="code">
<div class="container">
<div class="line number1 index0 alt2">
<code class="bash plain">tcpdump -n tcp port 8383 -i lo and src host 183.14.132.117</code>
</div>
</div>
</td>
</tr></tbody></table>
</div>
</div>
<div class="codetool" id="codetool">
<div class="code_n">
<textarea></textarea>
</div>
</div>
</div>
<p>
<span><strong>总结</strong></span></p>
<p>
以上就是这篇文章的全部内容了,希望本文的内容对大家的学习或者工作具有一定的参考学习价值,如果有疑问大家可以留言交流,谢谢大家对的支持。</p>
<p>
原文链接:https://segmentfault.com/a/1190000012593192</p>
頁:
[1]