¹êÅç¤G¡Bºô¸ô¡]¨ó©w¡^¤ÀªR»ö
¹êÅç¥Øªº¡G
1.
»{ÃѺô¸ô¨ó©w¤ÀªR»öSnifferªº°ò¥»¾Þ§@¡A¥H¤ÎInternetªº±`¥Î¤u¨ãµ{¦¡¡C
2.
¸g¥Ñ¾Ç²ßEthernetºô¸ôªºì²z¡A»{ÃÑOSI¤C¼h¨ó©w¤¤¹êÅé¼h¤ÎData Link¼hªºì²z¤Î¾Þ§@¡C
3.
»{ÃѦbOSI¤C¼h¨ó©w¤¤ºô¸ô¼hªº¨ó©w¹B§@¡A¥]¬AIP¡]Internet Protocol¡^¡AARP¡]Address Resolution Protocol¡^¡A¥H¤ÎICMP¡]Internet Control Message Protocol¡^¡C
4.
¾Ç²ßping¡Barp¡Bnetstat¡Btracert¡Èµ¥µ¥ºô¸ô¬ÛÃöµ{¦¡«ü¥Oªº¨Ï¥Î¡C
5.
¹w³ø¡]¥´¦r¡B¤@¶¡^¡A½Ð»¡©úping¡Barp¡Bnetstat¡Btracert¦U«ü¥O¦³Ô£¥Î³~¡C
6.
¦P²Õ¦P¾Ç½Ð¥ý½T¹ê²z¸Ñ°Q½×¹L¹êÅ示®e¡A¤~¤£·|°µ¹êÅç®É¯í¯íµLÀYºü¡C
¹êÅç³]³Æ¡G
Ø
µwÅ鳡¤À¡G
1.
¨â¥xÓ¤H¹q¸£ (ªþºô¸ô¥d)¡C
2.
¤@¥x¥æ´«¦¡¶°½u¾¹¡C
3.
¤@Ó¤p«¬ªº¶°½u¾¹¡C
4.
¤@¥xsniffer (¤A¤Óºô¸ô¨ó©w¤ÀªR»ö)¡C
5.
Ethereal³nÅé¡C
¹êÅçì²z¡G
OSI±Nºô¸ô¤À¦¨¤C¼hªº¼Ò«¬¡]¹Ï1-1¡^¡A±q¤U¦Ó¤W¤À§O¬O¹êÅé¼h¡]Physical¡^¡A¸ê®ÆÃìµ²¼h¡]Data link¡^¡Aºô¸ô¼h¡]Network¡^¡A¶Ç¿é¼h¡]Transport¡^¡A·|ij¼h¡]Session¡^¡Aªí²{¼h¡]Presentation¡^¡A¥H¤ÎÀ³¥Î¼h¡]Application¡^¡C¥»¹êÅç¬O±´°Q³oÓ¼Ò«¬ªº³Ì§C¨â¼h¡A§Ú̱N¦b¤A¤Óºô¸ô¤W¡]Ethernet¡^¶i¦æ¹êÅç¡C
1.
¤A¤Óºô¸ô¡]Ethernet¡^
¤A¤Óºô¸ôªº¹êÅéÀô¹Ò¦³«Ü¦hºØ¡A¨ä¤¤³Ì±`¨£ªº¦³¡ã¨Ï¥ÎCoaxial Cable¡]Coax¡^©M¨Ï¥Î10/100 BaseT¨âºØ¡C¨Ï¥ÎCoax©Ò³s°_¨Óªº¹êÅéºô¸ô¡A¬O§eBusµ²ºcªº¡A¦Ó¨Ï¥Î10/100 BaseTªº¸Ü¡A¦]¬°¥²¶·³s¨ì¤@Ó¶°½u¾¹¡]Hub¡^¡A©Ò¥H¬O§e²{¬Pª¬µ²ºcªº¡C¶°½u¾¹©Ò´£¨Ñªº¥\¯à¬O§â¨C¤@Óportªºinput«Ê¥]output¨ì¨ä¥¦©Ò¦³ªºport¥h¡A©Ò¥Hµ¥©ó¬O¤@Ómulti-port repeater¡A¤]ºÙ¬°Dumb Hub¡C°£¤F±µ½u¤è¦¡¤£¦P¥~¡A³o¨âºØ¤èªk©Ò«Ø°_¨Óªº¹êÅéºô¸ô¦b¥\¯à¤W¨Ã¨S¦³¤°»ò¤£¦P¡A³£ÂkÄÝ©ó¤A¤Óºô¸ô¡]Ethernet¡^¡C
Application |
SNMP¡ADNS TELNET¡A
FTP |
Presentation |
|
Session |
|
Transport |
TCP¡AUDP |
Network |
IP¡AICMP |
Datalink |
ARP Ethernet |
Physical |
¹Ï1-1¡GOSI Reference Model
¤A¤Óºô¸ô¬O¤@ºØ¦@¨É´CÅé¡]shared medium¡^¡A©Ò¥H¥²¶·n¦³¤@Ó¤èªk¨Ó¨M©w¥Ñ½Ö¨Ó¨Ï¥Î¶Ç¿é´CÅé¡A¤]´N¬OMedium Access Control¡]MAC)¡C¤A¤Óºô¸ô¬O¨Ï¥ÎCSMA/CD¡]Carrier
Sense Multiple Access / Collision Detection¡^ªº¤èªk¨Ó°µMAC¡A¤]´N¬O¥ý¬Ý¬Ý¶Ç¿é´CÅ馳¨S¦³¤H¥¿¦b¥Î¡A¦pªG¨S¦³ªº¸Ü¡A´N¶}©l¶Ç°e«Ê¥]¡A¸U¤@¦³¨ä¥¦ªº¥D¾÷¤]è¦n¶}©l¶Ç°e«Ê¥]ªº¸Ü¡A´N·|³y¦¨¸I¼²¡]collision¡^¡A¨º»ò³o¨Ç¥¿¦b°eªº¥D¾÷¥þ³¡¥²¶·°±¤î¶Ç°e¡Aµ¥¤@¤U¦A¸Õ¸Õ¬Ý¡C©Ò¥H¦P®É¶¡¤º³Ì¦h¥u¦³¤@¥x¥i¥H¶Ç°e«Ê¥]¡C³o¨Ç¤À¨É¶Ç¿é´CÅ骺¥D¾÷¡A´NºÙ¬°¦b¦P¤@collision domain ¡]©ÎºÙ¬°segment¡^¤º¡C
³oºØ¦@¨É´CÅé¬[ºc¤§¤U¡Aºô¸ôªº®Ä¯à·|ÀHµÛ¥D¾÷¼Æ¥Øªº¼W¥[¦ÓÅÜ®t¡C¦]¬°·í
¾ô±µ¾¹©Ò¯à¤À¹jªº¬O¥u°e©¹³æ¤@¥Øªº¦aªº«Ê¥]¡]uni-cast packet¡^¡C¦pªG¬O¥Øªº¦a¬°ff:ff:ff:ff:ff:ffªº¼s¼½«Ê¥]¡]broadcast packet¡^¡A«h¾ô±µ¾¹·|±N¤§forward¦Ü¥t¤@Ósegment¡C³o¨Ç¥Î¾ô±µ¾¹©Ò³sµ²°_¨ÓªºEthernet segment¡AºÙ¬°¤@Óbroadcast domain¡C¦b¦P¤@Óbroadcast domain¸Ìªº¥D¾÷¡A³£¥i¥Hª½±µ¤¬³q¡C¤£¦Pbroadcast domain¸Ìªº¥D¾÷¡A´N¥²¶·¸g¥Ñrouter¤~¯à¤¬³q¡C
¥æ´«¦¡¶°½u¾¹¡]Switching Hub¡^¡A¦³¤HºÙ¬°fast multi-port bridge¡A¤]¬O¥Î¨Ó¤À¹jsegment¼W¥[ºô¸ô®Ä¯à¥Îªº¡C·í¥H¨C¤@Óport¬°³æ¦ì¨Ó§@switching®É¡A¦Ó±Nportª½±µ³s¨ì¤@¥x¥D¾÷®É¡A²z½×¤W¨º¥x¥D¾÷«K¿W¨É©Ò¦³ªºÀW¼e¡CSwitchingªºµ²ªG·|§â¥Øªº¦a¤£¬O³oÓportªºuni-cast«Ê¥]¹LÂo±¼¡A©Ò¥H¨CÓport¥u¬Ý±o¨ìÄÝ©ó³oÓportªº«Ê¥]¡A¦Ó¥B¦P®É¶¡¥i¥H¦³¦hÓport¥¦æ¦a¶Ç°e¡]parallelism¡^¡Aºô¸ôÁ`ÅéÀW¼e¦]¦Ó¼W¥[¡C
1.
IP¡]Internet Protocol¡^
IP¬OARPANETªººô¸ô¼h¨ó©w¡At³d°µrouting¡]«Ê¥]¸ô®|¿ï©w¤Î¶Ç°e¡^¡Afragmentation and
re-assembly¡]«Ê¥]¤À³Î¤Î«²Õ¡^¡C
0 |
4 |
8 |
|
16 |
|
|
31 |
|
Version |
IHL |
Type Of Service |
Total Length |
|||||
Identification |
Flags |
Fragment Offset |
||||||
Time To Live |
Protocol |
Header Checksum |
||||||
Source IP address |
||||||||
Destination IP address |
||||||||
Options (if any) |
||||||||
Data |
||||||||
¹Ï2-1¡GIP headerªº®æ¦¡¡]unit¡Gbit¡^
l
¹Ï2-1¤¤¦UÄæ¦ìªº¸ÑÄÀ¦p¤U:
Version |
IP version |
IHL |
Internet Header
Length, in 32bits |
Type of Service |
Reliability,
precedence, delay, and throughput |
Total Length |
Length of the
entire datagram, in Bytes |
Identification |
Uniquely
identifies each datagram |
Flags |
"Don't
Fragment" - don't fragment "More
Fragments" - more fragments are coming |
Fragment Offset
|
The position of
the fragment's data relative to the beginning of the data in the original
datagram |
Time To Live¡]TTL¡^ |
The number of
hops the datagram is allowed to remain "alive". Each gateway and router decrements it
by one. When it becomes zero, the
fragment is discarded. |
Protocol |
Identifies the
upper layer protocol |
Header Checksum |
Checksum for
the IP header |
Source Address |
The IP address
of the source of the datagram |
Destination
Address |
The IP address
of the destination of the datagram |
2.
ICMP¡]Internet Control Message Protocol¡^
ICMP¬O¥Î¨ÓÅýºô¸ô¤Wªº¾÷¾¹¥æ´«±±¨î°T®§¡A¥H³B²z¤@¨Çºô¸ôªº¯S®í©Î¿ù»~±¡ªp¡CICMP Message¦³³\¦hºØType¡A±`¨£ªº¦³:
l
±`¨£ªºICMP Message Types
ECHO REQUEST ECHO REPLY |
´ú¸Õ¥i§_³s¤W¬Y¥D¾÷¡]connectivity¡^¡C·í¥D¾÷¦¬¨ì¤@ÓECHO REQUESTªº«Ê¥]®É¡A´N·|¦^¤@ÓECHO REPLYªº«Ê¥]¡C |
REDIRECT |
¥Î¨Ó§ïÅÜroute¡A¦¬¨ìªº¥D¾÷¥i¥H¦brouting table¤¤¥[¤W¤@Ódynamicªºroute¡C |
SOURCE QUENCH |
¥Î¨Ó³qª¾¤@¥x¥D¾÷´î¤Ö°e¥Xªº«Ê¥]¶q¡C |
DESTINATION
UNREACHABLE |
·írouter§ä¤£¨ì¥Øªº¥D¾÷®É¡A©Î¦]¬°¨ä¥¦ì¦]¦Ó¨Ï«Ê¥]µLªk°e¦Ü²×ÂI®É¡A¥Î¨Ó³qª¾sourceªº«Ê¥]¡C |
TIME EXCEED |
¬O·í«Ê¥]ªºTTLÅܦ¨0¤F¦Ó©|¥¼©è¹F²×ÂI®É³qª¾sourceªº°T®§¡C |
¤@¯ë±`¥Îªºping´N¬O§Q¥ÎICMP
Echo Request¨Ó´ú¸Õºô¸ô¦³¨S¦³°ÝÃD¡C·í¤@¥xrouter¦¬¨ì¤@ÓTTL¡×1ªº«Ê¥]¡A¥i¬O¥Øªº¦aÁÙ¨S¨ìªº®ÉÔ¡A¥¦·|§â³oÓ«Ê¥]¥á¤F¡AµM«á°e¤@ÓTime Exceedªº«Ê¥]µ¹source¡AÅýsourceª¾¹D¥¦ªº«Ê¥]¦b¥b¸ô¤W³Q¥á±¼¤F¡A¥i¥H¦A°µ³B²z¡C¦pªG«Ê¥]¨ì¹F¤F¥Øªº¦a¡A«oµo²{¨S¦³processn¦¬³oÓ«Ê¥]ªº®ÉÔ¡A¥¦´N¦^¤@ÓDestination
Unreachableªº«Ê¥]µ¹source¡C½Ñ¦p¦¹Ãþªº¨ó©w¤è¦¡¡AICMP«K¥i¥H¥Î¨Ó³B²z¤@¨Ç°ÝÃD¡C
3.
ARP¡]Address Resolution Protocol¡^
¦bInternetºô¸ô¤¤¡Aºô¸ô¼hªºIP»Ýn¨Ï¥Î¤U¼hªº¹êÅéºô¸ô¡]¨Ò¦p¡G¤A¤Óºô¸ô¡^ªº¶Ç°eªA°È¨Ó±N¸ê®Æ«Ê¥]°e¨ì¥Øªº¦a¡C¦ý¬OIP¼h¥u·|ª¾¹D¥Øªº¦aªºIP¦ì§}¡A¦Ó¤£ª¾¹D¥Øªº¦aªºµwÅé¦ì§}¡A©Ò¥Hn¦³¤@ºØ¤èªk±qIP¦ì§}¨Ó§ä¥X¹ïÀ³ªº¹êÅé¦ì§}¡A¦Ó³o´N¬OARPªº¥\¯à¡C
¦b¤A¤Óºô¸ô¸Ì¡A«Ê¥]ªº¥Øªº¦ì§}¥i¥H¬O«üµ¹©Ò¦³¤H¡]¼s¼½¦ì§} ff:ff:ff:ff:ff:ff¡^¡A©Ò¥Hn§ä¥X¬Y¤@ÓIP¦ì§}©Ò¹ïÀ³ªº¤A¤Óºô¸ô¦ì§}¡A´N¥i¥H¥Ñ¨Ó·½ºÝ°e¥X¤@Ó¼s¼½«Ê¥]¡A¸Ì±¥]§t¤Fn§äªºIP¦ì§}©M¨Ó·½ºÝªº¤A¤Óºô¸ô¦ì§}¡A¨C¥x¥D¾÷³£·|¦¬¨ì¡C¦pªG³oÓIP¦ì§}ªº¥D¾÷¬Ý¨ì³oÓ«Ê¥]¡A¥¦´N·|¦^¤@Ó«Ê¥]µ¹¨Ó·½ºÝ¥D¾÷¡A¥]§t¤F¥¦ªº¤A¤Óºô¸ô¦ì§}¡CµM«á¨Ó·½ºÝ¥D¾÷´N¥i¥H§â³oÓµwÅé¦ì§}¦s¦bARP cache¤¤¡C¦P®É¥ØªººÝ¥D¾÷¤]·|°O¤U¨Ó·½ºÝ¥D¾÷ªºµwÅé¦ì§}¡A¦]¬°«Ü¥i¯à°¨¤W´N·|¥Î¨ì¤F¡C¹Ï4-1®i¥Ü¥XARP«Ê¥]ªº®æ¦¡¡C
0 |
2 |
4 |
7 |
||||
Hard Type |
Protocol Type |
Hard Size |
Prot Size |
operation |
|||
sender Ethernet address |
sender IP addr |
||||||
sender IP addr |
target Ethernet address |
||||||
target IP address |
¡@ |
||||||
¹Ï4-1¡GARP«Ê¥]ªº®æ¦¡
l
¹Ï4-1¤¤³¡¤ÀÄæ¦ìªº¸ÑÄÀ¦p¤U:
Hard Size = |
Hardware Address Length |
Prot Size = |
Protocol (IP) Address Length |
Operation = |
1 ARP request 2 ARP reply 3 RARP request 4 RARP reply |
¹êÅç¨BÆJ¡]Snifferªº³¡¤À¡A±N¥Î¹q¸£³nÅéethereal¨ú¥N¡^¡G
Fig. 1 ¹êÅç¤Gºô¸ô³sµ²¡]¬[ºc¤@¡^
Fig. 2 ¹êÅç¤Gºô¸ô³sµ²¡]¬[ºc¤G¡^
Ø
²Ä¤@³¡¤À
1.
³sµ²¹q¸£ºô¸ô¦p¬[ºc¤@¡A¥]¬APC¨â¥x¥H¤Îsniffer³£±µ©¹hub¡Ahub¦A³s©¹switching hub¡C
2.
³]©wsniffer¥uºI¨ú©Mpc1¨Ó©¹ªº«Ê¥]¡]sniffer¤W³]©w¥HPC1¤§IP¦ì§}»PEthernet¦ì§}¤À§O°µ¹êÅç¡^¡A¶}©lºI¨ú«Ê¥]¡A¨Ã§â¥H¤U¨C¤@Ó¨BÆJ©Ò§ì¨ìªº«Ê¥]¡]Y¦³ªº¸Ü¡^¤À§OÂkÃþ¦sÀÉ¡]½Ðª`·NÀɮצWºÙ¡^¡C
3.
¨Ï¥Îarp«ü¥O§R°£pc1¤W©Ò¦³ªº¹ï·Óªí¡C
4.
¨Ï¥Îpingµ{¦¡±qpc1³s©¹pc2¡A½Ð¸Õ¥Îdomain name¤ÎIP
address¨âºØ¤èªk¡C
5.
«§@¤@¦¸¨BÆJ4¡C
6.
«·s³sµ²¹q¸£ºô¸ô¦p¬[ºc¤G¡A¨Ã«ÂШBÆJ2-5¡C
Ø
²Ä¤G³¡¤À
1.
³sµ²¹q¸£ºô¸ô¦p¬[ºc¤@¡Apc1¡Apc2¡A¥H¤Îsniffer³£±µ©¹hub¡Ahub¦A³s©¹switching hub¡C
2.
³]©wsniffer¥uºI¨ú©Mpc1¨Ó©¹ªº«Ê¥]¡]sniffer¤W³]©w¥HPC1¤§IP¦ì§}»PEthernet¦ì§}¤À§O°µ¹êÅç¡^¡A¶}©lºI¨ú«Ê¥]¡A¨Ã§â¥H¤U¨C¤@Ó¨BÆJ©Ò§ì¨ìªº«Ê¥]¡]Y¦³ªº¸Ü¡^¤À§OÂkÃþ¦sÀÉ¡C
3.
¨Ï¥Îarp«ü¥O§R°£pc1¤W©Ò¦³ªº¹ï·Óªí¡C
4.
¦bpc1¤W°õ¦æ¥H¤U«ü¥O¨Ã°O¤Uµ²ªG¡]¿Ã¹õÅã¥Ü¤Î§ì¨ú«Ê¥]µ²ªG¡^¡C
> ftp
ftp.ntu.edu.tw
> ping
ftp.ntu.edu.tw
> arp -a
5.
¦bpc1¤W°õ¦æ¥H¤U«ü¥O¨Ã°O¤Uµ²ªG¡]¿Ã¹õÅã¥Ü¤Î§ì¨ú«Ê¥]µ²ªG¡^¡C
> netstat ¡Vr
¡]¤£¥Î§ì«Ê¥]¡^
> netstat ¡Ve
¡]¤£¥Î§ì«Ê¥]¡^
> netstat ¡Vs
¡]¤£¥Î§ì«Ê¥]¡^
> tracert www.yahoo.com
> ping -r 6 bbs.nsysu.edu.tw
> ping -i 1 bbs.nsysu.edu.tw
6.
¥Ñtracertªºµ²ªG¡Aping¨ä¤¤¨CÓhop¡A¨Ã°O¤URound Trip Time¡C
7.
°±¤îºI¨ú¡A§â§ì¨ìªº¸ê®Æ¦s¦¨Àɮס]½Ðª`·NÀɮצWºÙ¡^¡C
8.
§âÀɮצs¦Ü³nºÐ¨Ã¶i¤@¨B¤ÀªR¡C
¹êÅç°Q½×¡]½Ð©ó¹êÅç§¹¦¨«á¥ß§Y°Q½×§ä¸ê®Æ¡A¨Ã¾ã²z¯ó½Z¡]¥´¦rWordÀÉ¡^¡Aemailµ¹§U±Ð¡^¡G
Ø
²Ä¤@³¡¤À
1.
¥HFig. 1¡BFig.
2.
¦bSniffer¤W³]©w¥ÎIP address©M¥ÎMAC Address©Ò§ì¨ìªº«Ê¥]¼Æ¦³¦ó¤£¦P¡H¬°¤°»ò¡H¡]½Ð¥H²z½×»¡©ú¡^
3.
¦b¨BÆJ4©M5©Ò§ì¨ìªº«Ê¥]¦³¦ó¤£¦P¡H¬°¤°»ò¡H¡]½Ð¥H¹êÅç¨ú±o«Ê¥]»¡©ú¡^
4.
¥Hºô¸ô¤À¼hªºÆ[©À¸ÑÄÀ¬°¤°»ò¦b¤£¦Pbroadcast domainªº¾÷¾¹¤@©wn¸g¹Lrouter¤~¯à¤¬³q¡H
5.
¦bºI¨ú¨ìªº«Ê¥]¤¤ªºEthernet header¸Ì¦³destination Ethernet Address¡A¦ÓIP header¤¤¤]¦³¤@Ódestination IP Address¡C½Ð°Ý¡A³o¨âÓ¦ì§}¬O¤£¬O¦P¤@¥x¾÷¾¹¡H¬°¤°»ò¡H
6.
¥i¤£¥i¥H§Q¥Îsnifferª¾¹Dºô¸ô¤W¦³¨S¦³switching hubªº¦s¦b¡H
7.
±q¹êÅçµ²ªG¡A°Q½×n¦p¦ó§Q¥Îswitching hub¨Ó¼W¶iºô¸ô¦w¥þ¡C
Ø
²Ä¤G³¡¤À
1.
°õ¦æftp ftp.ntu.edu.twªº®ÉÔ¡A§ì¨ìªº«Ê¥]ªº¥ØªºIP¦ì§}¬°¦ó¡H¤S¥ØªºEthernet¦ì§}¬O¨º¸Ì¡]¥Îarp¬d¥X¨äIP
address/Domain Name¡^¡H¬O¤£¬Oftp.ntu.edu.twªº¡H¬°¤°»ò¡H
2.
°õ¦æping ftp.ntu.edu.twªº®ÉÔ¡A°e¥Xªº«Ê¥]¬O¨ººØICMP«Ê¥]¡H
3.
°õ¦æping -i 1
bbs.nsysu.edu.twªº®ÉÔ¡A¦¬¨ìªº«Ê¥]¬O¨ººØICMP«Ê¥]¡H
4.
½Ð°Ý¹êÅ礤¤§ARP request¤ÎARP replyªº«Ê¥]ªº¥Øªº¦a¦U¬°¨º¸Ì?
5.
¦b¨Ï¥Îarp -a©R¥O®É¡A·|°e¥XARP«Ê¥]¶Ü¡H
6.
¥Ñ¹êÅçµ²ªG¡A§ä¥X©¹www.yahoo.comªº«Ê¥]©Ò¸g¥Ñªº¸ô®|¡C¨Ã¥B§Q¥Î§ì¨ìªº«Ê¥]¡A»¡©útraceroute¬O¥Î¤°»ò¤èªk¨Ó§ä¸ô®|ªº¡C
7.
¥Ñ¹êÅçµ²ªG¡A»¡©ú©¹www.yahoo.comªº¨C¤@Óhop©Òªáªº®É¶¡¡A¨Ã¥Ñ¦¹§ä¥X³o±ø³q¸ôªº²~ÀV©Ò¦b¡C