发布时间:2011-03-23 17:21:22
1.监听所有非echo requests/replies的ICMP数据包 //ICMP ECHO(Type 8) 和ECHO Reply (Type 0)#tcpdump "icmp[0] != 8 and icmp[0] != 0"2.监听非本地网络的每次TCP会话开始和结束数据包#tcpdump 'tcp[13] & 3 != 0 and not src and dst net localnet'3.监听网关snup上长度大于576字节的IP数据包#tcpdump 'gatew.........【阅读全文】