记录tcp首部
IPT='/sbin/iptables'
$IPT -I INPUT 1 -p tcp --dport 22 -j LOG --log-tcp-options --log-tcp-sequence
$nc -v 192.168.1.103 22
日志如下:
Dec 30 16:50:09 localhost kernel: IN=eth0 OUT= MAC=00:0c:29:06:9a:01:00:0c:29:b9:73:7b:08:00 SRC=192.168.1.124 DST=192.168.1.103 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=24369 DF PROTO=TCP SPT=32773 DPT=22 SEQ=2836907495 ACK=4171508168 WINDOW=1460 RES=0x00 ACK FIN URGP=0 OPT (0101080A008BA3E500E1E49D)
下面是udp 首部记录
阅读(2446) | 评论(0) | 转发(0) |