[리눅스공통] tcpdump 패킷 필터 (SYN, SYN-ACK, ACK 별 필터 방법)

Posted by nkjok
2019. 8. 1. 14:42 OS&기타/Linux
반응형

tcpdump -nni any tcp[13]=0x02

- SYN 패킷만 필터

 

tcpdump -nni any tcp[13]=0x12

- SYN.ACK 패킷만 필터

 

tcpdump -nni any tcp[13]=0x10

- ACK 패킷만 필터

 

Flags

Flags

Numerically

Meaning

---- --S- 0000 0010

0x02

normal syn

---A --S- 0001 0010

0x12

normal syn-ack

---A ---- 0001 0000

0x10

normal ack

--UA P--- 0011 1000

0x38

psh-urg-ack.

---A -R-- 0001 0100

0x14

rst-ack

---- --SF 0000 0011

0x03

syn-fin scan

--U- P--F 0010 1001

0x29

urg-psh-fin

-Y-- ---- 0100 0000

0x40

anything >= 0x40

XY-- ---- 1100 0000

0xC0

both reserved bits set

XYUA PRSF 1111 1111

0xFF

FULL_XMAS scan

 

반응형