¹êÅç¤G¡Bºô¸ô¡]¨ó©w¡^¤ÀªR»ö¡]PART III¡^
Ethereal§Ö³t¨Ï¥Î»¡©ú¡G
1. ¦w¸ËEthereal¤§«e¡A½Ð¦w¸ËWinPcap¡A¦A±µµÛ¦w¸ËEthereal¡C
2. ¶i¤JEthereal¥Dµ{¦¡«á¡A´N¥iª½±µÂI¿ïCapture->Start¡C
3. ¥X²{¦p¤W¹Ïªºµøµ¡¤§«á¡A
u
½Ð¥¿½T³]©w§Aªººô¸ô¥d¡]Interface¡^¡C
u
Count¥i³]©wn§ì´XÓ«Ê¥]¡A¹w³]Ȭ°0¡A¤]´N¬O²Å¦X±ø¥óªº«Ê¥]¥i¥H¤@ª½§ì¶i¨Ó¡C
u
Filter³¡¤À¬O«ÂI¡A¦b¦¹²¤¹L¡C
u
¨ä¥L¿ï¶µ«ö·Ó¹w³]ȧY¥i¡A¦³¿³½ìªº¦P¾Ç¥i¥H¿ïUpdate...¤ÎAutomatic...¡A¦ý³y¦¨·í¾÷®¤¤£t³d¡C
4. ¶}©l§ì«Ê¥]«á¡A·|¥X²{¤@Ó²Îp«Ê¥]ºØÃþ»P¼Æ¶qªº¤pµøµ¡¥i¨Ñ°Ñ¦Ò¡C¿ï¾ÜStop§Y¥i°±¤î§ì«Ê¥]¡C
5. ÂsÄý«Ê¥]¤º®e«án¦sÀÉ¡A½Ð¿ïFile->Print¡A¥X²{¦p¤Uµøµ¡¡C
u
Format¿ïPlain
Text§Y¥i¡A½Ð¤Å±Hpostscript¨Ó¡C
u
Print to:¿ï¾ÜFile¡A«hFile«ö¶s¥iÅý§A¿ï¾Ün¦s¦¨¤°»ò¦W¦rªºÀɮסA«Øij¦s¦¨°ÆÀɦW¬°.PRNªºÀɮסA¥H¤è«K¿ë»{¡C
u
±µ¤U¨Ó´Xӿﶵ½Ð¦Û¦æ¨M©w¡C°ò¥»¤W´N¬OnÅý§A·Q¬Ý¨ìªº¸ê°T³£¦³¦sÀÉ¡C
Capture Filter³]©w¡G
1.
ÂI¿ïCapture->Start¤§«á¡A«ö¤UFilter«ö¶s¡A¥i³]©w§A·Qnªºcapture
filter¡C
¡]¨Ò¦p¡Gn¥HMAC address 00¡G00¡G11¡G11¡G22¡G22¬°§ì«Ê¥]±ø¥ó¡^
u
FIlter name¡G¥ô·N¨ú¡A¦b¦¹³]¬°MAC_FILTER¡C
u
Filter string¡G½Ð¿é¤Jether
host 00¡G00¡G11¡G11¡G22¡G22
u
¦A«öNEW¤§«á¡A¥iÅý§AªºMAC_FILTER¥X²{¦b¤W¤èªº¦W³æ¤¤¡C
u
¦¹®ÉY¿ïSave¡A¬°Àx¦s§A©Ò¼gªºfilter¡A«h¤U¦¸«·s¶}±Ò¥»µ{¦¡®É¡A¥i«ÂШϥΡC
u
½T©w§Aªºfilter
string¥¿½T¤§«á¡A«öOK¸õ¥X¡A´N¥i¬Ý¨ìFilterÄæ¤w³]©w¡C
(¨Ò¦pn¥HIP address 11.22.33.44¥H¤ÎTELNET¬°«Ê¥]ªºfilter)
u
Filter string¡Gip host 11.22.33.44 and tcp port
23
2.
Filter name¿ï¾ÜµLªk¤@¦¸¿ï¨âÓ¡A©Ò¥Hn¨Ï¥Î¦h«±ø¥ó¡A½Ð¨Ï¥ÎÅÞ¿è²Å¸¹¡G
u
§_©w±ø¥ó¡] `!' ©Î `not' ¡^¡C
u
¥æ¶°±ø¥ó¡]
`&&' ©Î `and' ¡^¡C
u
Áp¶°±ø¥ó¡] `||' ©Î
`or' ¡^¡C
1.
¥t¥~ÁÙ¦³¤@°ï²Å¸¹¥i¥Î¡A¥]¬A=¡A>=¡A+¡A&¡A¡Èµ¥µ¥¡C¥»¹êÅ窺filter±ø¥ó¤ñ¸û²³æ¡A¬G½Ð¦³¿³½ì¬ã¨s»yªkªº¦P¾Ç¦Û¦æ°Ñ¦Òtcpdump¨Ï¥Î»¡©ú¡C
Display Filter³]©w¡G
1. Y¤£·Q³]©wCapture filter¡A«h©Ò¦³¥X²{¦b§Aºô¥d¤Wªº«Ê¥]¡A³£·|³Q§ì¶i¨Ó¡A¦¹®É¥i§Q¥ÎDisplay filter¶i¦æ¿z¿ï¡C
2. ¥Dµøµ¡¥ª¤U¤èªºFilter«ö¶s¡A´N¬O³]©wDisplay filterªº¦a¤è¡A¶i¤J¤§«á¿ï¾ÜAdd expression¡A§Y¦³¬Û·í©ö¾Þ§@ªº¬É±¥i¨Ï¥Î¡A¥B³¡¤À»PCapture
filter¤§³]©w¹p¦P¡A½Ð¦P¾Ç¦Û¦æ¾Þ§@¡C