{"id":409,"date":"2015-03-14T03:43:10","date_gmt":"2015-03-14T00:13:10","guid":{"rendered":"http:\/\/www.chpert.net\/?p=409"},"modified":"2019-05-29T23:40:15","modified_gmt":"2019-05-29T19:10:15","slug":"%d9%85%d9%82%d8%af%d9%85%d9%87%e2%80%8c%d8%a7%db%8c-%d8%a8%d8%b1-tcpdump","status":"publish","type":"post","link":"http:\/\/pahlevanzadeh.net\/?p=409","title":{"rendered":"\u0645\u0642\u062f\u0645\u0647\u200c\u0627\u06cc \u0628\u0631 tcpdump"},"content":{"rendered":"<p>\u0647\u0645\u06cc\u0634\u0647 \u0628\u0631\u0627\u06cc \u0628\u0639\u0636\u06cc \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0633\u0624\u0627\u0644\u0627\u062a\u06cc \u0645\u0637\u0631\u062d \u0627\u0633\u062a \u06a9\u0647 \u0627\u0632 \u06a9\u062f\u0627\u0645 \u0628\u0631\u0646\u0627\u0645\u0647 \u0628\u0631\u0627\u06cc log \u06af\u06cc\u0631\u06cc \u0634\u0628\u06a9\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u0645\u0627\u06cc\u0646\u062f. \u062a\u0627 \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u0627\u06cc\u0646 \u062e\u0648\u0627\u0633\u062a\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0645\u0634\u062e\u0635 \u0646\u0628\u0627\u0634\u062f \u0627\u06cc\u0646 \u0633\u0624\u0627\u0644 \u0628\u062f\u0648\u0646 \u062c\u0648\u0627\u0628 \u0628\u0627\u0642\u06cc \u0645\u06cc\u200c\u0645\u0627\u0646\u062f.<br \/>\n\u062e\u0648\u0628 \u0645\u0633\u0644\u0645\u0627\u064b \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u0632\u06cc\u0627\u062f\u06cc \u0628\u0627 \u06a9\u0627\u0631\u0628\u0631\u062f\u200c\u0647\u0627\u06cc \u0632\u06cc\u0627\u062f\u06cc \u0647\u0633\u062a\u0646\u062f \u0627\u0646\u0648\u0627\u0639 monitoring \u0634\u0628\u06a9\u0647 \u0631\u0627 \u062f\u0627\u0631\u06cc\u0645 \u06a9\u0647 \u0647\u0631\u06cc\u06a9 \u0628\u0646\u0627 \u0628\u0647 \u0631\u0633\u062a\u0647 \u062e\u0648\u062f \u0645\u0648\u0631\u062f \u0628\u062d\u062b \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u062f \u0648 \u0628\u0627\u0632 \u062f\u0631 \u0628\u062d\u062b <a href=\"http:\/\/www.pahlevanzadeh.net\/wp-content\/uploads\/2015\/03\/tcpdump.png\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.pahlevanzadeh.net\/wp-content\/uploads\/2015\/03\/tcpdump-300x115.png\" alt=\"tcpdump\" width=\"300\" height=\"115\" class=\"alignleft size-medium wp-image-266\" srcset=\"http:\/\/pahlevanzadeh.net\/wp-content\/uploads\/2015\/03\/tcpdump-300x115.png 300w, http:\/\/pahlevanzadeh.net\/wp-content\/uploads\/2015\/03\/tcpdump.png 450w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a>sniffing \u062a\u0642\u0633\u06cc\u0645\u200c\u0628\u0646\u062f\u06cc \u0647\u0627\u06cc \u0645\u062a\u0641\u0627\u0648\u062a\u06cc \u0647\u0645\u0627\u0646\u0646\u062f log \u06af\u06cc\u0631\u06cc \u062d\u062c\u0645 \u0627\u0637\u0627\u0644\u0627\u0639\u0627\u062a \u0634\u0628\u06a9\u0647\u060c capture \u06a9\u0631\u062f\u0646 \u062f\u0627\u062f\u0647\u200c\u0647\u0627\u060c \u0627\u0628\u0632\u0627\u0631\u06cc \u0628\u0631\u0627\u06cc \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0633\u0627\u0632\u06cc \u0648 \u063a\u06cc\u0631\u0647 \u0645\u0648\u062c\u0648\u062f\u0646\u062f \u06a9\u0647 \u0647\u0645\u0632\u0645\u0627\u0646 \u0628\u0627 \u0632\u0645\u0627\u0646 \u0648 \u067e\u0631\u0648\u062a\u06a9\u0644\u200c\u0647\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f.<br \/>\n\u0627\u0645\u0627 \u0686\u0631\u0627 tcpdump \u061f \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0628\u062e\u0648\u0627\u0647\u062f \u062f\u0631 \u0645\u0648\u0631\u062f packet \u0647\u0627 \u062a\u062d\u0642\u06cc\u0642\u200c \u06a9\u0646\u062f \u0628\u0627\u06cc\u062f \u0622\u0646\u200c\u0647\u0627 capture \u06a9\u0631\u062f\u0647 \u0648 \u062d\u0627\u0644 \u06cc\u0627 \u0627\u0632 \u0622\u0646\u200c\u0647\u0627 log \u06af\u0631\u0641\u062a\u0647 \u0648 \u0627\u06cc\u0646 log \u0645\u0647\u0645 \u0627\u0633\u062a \u0648 \u06cc\u0627 \u06a9\u0627\u0631 \u0628\u0627 \u06cc\u06a9 grep \u062d\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0633\u0624\u0627\u0644\u06cc \u06a9\u0647 \u0645\u0637\u0631\u062d \u0645\u06cc\u200c\u0634\u0648\u062f \u0627\u06cc\u0646 \u0627\u0633\u062a \u06a9\u0647 wireshark \u0646\u06cc\u0632 \u0647\u0645\u06cc\u0646 \u06a9\u0627\u0631 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0631\u0627 \u0627\u0632 \u0622\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u0634\u0648\u062f\u061f \u0645\u0633\u0644\u0645\u0627\u064b \u06cc\u06a9 \u06a9\u0627\u0631\u0628\u0631 \u0634\u0628\u06a9\u0647 \u0647\u0645\u0632\u0645\u0627\u0646 \u0628\u0631 \u0631\u0648\u06cc \u0686\u0646\u062f\u06cc\u0646 \u0633\u0631\u0648\u0631 \u0628\u0627\u06cc\u062f \u0628\u0631\u0648\u062f \u06a9\u0647 \u0647\u06cc\u0686 \u06a9\u0646\u0633\u0648\u0644 \u06af\u0631\u0627\u0641\u06cc\u06a9\u06cc \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f \u0648 \u0628\u0642\u06cc\u0647 \u0642\u0636\u06cc\u0627&#8230; \u0627\u0645\u0627 \u0627\u06af\u0631 \u062f\u0631 \u0645\u0648\u0631\u062f \u06a9\u0627\u0631\u0628\u0631\u062f wireshark \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u062f \u0628\u067e\u0631\u0633\u06cc\u062f \u062f\u0631 \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0633\u0627\u0632\u06cc \u0628\u0647 \u0634\u062f\u062a \u06a9\u0627\u0631\u0628\u0631\u062f \u062f\u0627\u0631\u062f.<br \/>\n<!--more--><\/p>\n<p style=\"font-size: 18px;\"><strong>\u06f1. \u062e\u0648\u062f \u0628\u0631\u0646\u0627\u0645\u0647 tcpdump<\/strong><\/p>\n<p>\u06a9\u0627\u0631 \u0628\u0627 \u0628\u0627 tcpdump \u0628\u0647 \u062f\u0648 \u0628\u062e\u0634 \u062e\u0648\u062f \u0628\u0631\u0646\u0627\u0645\u0647 \u0622\u0646 \u0648 \u0628\u062e\u0634 filter \u0646\u0648\u06cc\u0633\u06cc \u0628\u0631\u0627\u06cc \u0622\u0646 \u062a\u0642\u0633\u06cc\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0628\u0647 \u0637\u0648\u0631\u06cc \u06a9\u0647 \u062d\u062a\u06cc manual page \u0647\u0627\u06cc \u0622\u0646\u0627\u0646 \u0645\u062a\u0641\u0627\u0648\u062a \u0645\u06cc\u200c\u0628\u0627\u0634\u062f. \u0628\u0631\u0627\u06cc \u062e\u0648\u062f \u0622\u0646 \u0628\u0627\u06cc\u062f <em>(8)tcpdump<\/em> \u0631\u0627 \u0645\u0637\u0627\u0644\u0639\u0647 \u06a9\u0631\u062f \u0648 \u0628\u0631\u0627\u06cc filter \u0646\u0648\u06cc\u0633\u06cc \u062f\u0631 tcpdump \u0628\u0627\u06cc\u062f <em>(7)pcap-filter<\/em> \u0631\u0627 \u0645\u0637\u0627\u0644\u0639\u0647 \u06a9\u0631\u062f.<br \/>\n\u0627\u06cc\u0646 \u0628\u0631\u0646\u0627\u0645\u0647 \u062c\u0632\u0648 \u067e\u0631\u0648\u0698\u0647 pcap \u0645\u06cc\u200c\u0628\u0627\u0634\u062f \u06a9\u0647 \u06cc\u06a9 library \u0642\u0648\u06cc \u0628\u0631\u0627\u06cc capture \u06a9\u0631\u062f\u0646 packet \u0647\u0627 \u0645\u06cc\u200c\u0628\u0627\u0634\u062f.<br \/>\n\u0628\u0647\u062a\u0631 \u0627\u0633\u062a \u06cc\u06a9 \u0645\u0631\u0648\u0631 \u06a9\u0644\u06cc \u0628\u0631 \u0631\u0648\u06cc option \u0647\u0627\u06cc \u0627\u0635\u0644\u06cc \u0622\u0646 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u0645 \u062a\u0627 \u0628\u0647 \u0627\u0635\u0644 \u0642\u0636\u06cc\u0647 \u06cc\u0639\u0646\u06cc \u0646\u0648\u0634\u062a\u0646 \u0641\u06cc\u0644\u062a\u0631 \u0628\u067e\u0631\u062f\u0627\u0632\u06cc\u0645.<br \/>\n\u0647\u0645\u0647 \u0686\u06cc\u0632 \u0628\u0627 \u062a\u0639\u06cc\u06cc\u0646 interface \u0645\u0631\u0628\u0648\u0637\u0647 \u0634\u0631\u0648\u0639 \u0645\u06cc\u200c\u0634\u0648\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n21:55:38.963133 IP dev32.1900 > 239.255.255.250.1900: UDP, length 94\r\n21:55:39.512530 IP debian.47888 > google-public-dns-a.google.com.domain: 33222+ PTR? 250.255.255.239.in-addr.arpa. (46)\r\n21:55:39.516780 IP dev32.1900 > 239.255.255.250.1900: UDP, length 94\r\n21:55:39.774315 IP google-public-dns-a.google.com.domain > debian.47888: 33222 NXDomain 0\/1\/0 (103)\r\n21:55:40.175894 IP dev32.1900 > 239.255.255.250.1900: UDP, length 94\r\n^C\r\n5 packets captured\r\n7 packets received by filter\r\n0 packets dropped by kernel\r\n<\/pre>\n<p>\u0628\u0644\u0647\u060c \u062f\u0631 \u0628\u0627\u0644\u0627 \u0628\u0647 tcpdump \u06af\u0641\u062a\u06cc\u0645 \u0628\u0647 eth0 \u06af\u0648\u0634 \u0641\u0631\u0627 \u062f\u0647\u062f.<br \/>\n\u0627\u0645\u0627 \u0628\u06cc\u0627\u06cc\u06cc\u062f \u06a9\u0645\u06cc \u0641\u0631\u0645\u062a \u062e\u0631\u0648\u062c\u06cc \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u0645:<br \/>\n\u0639\u0645\u0644\u06af\u0631 < \u0628\u06cc\u0646 \u062f\u0648 host \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u0646\u062f \u0648 \u0646\u0634\u0627\u0646\u06af\u0631 \u0648\u0631\u0648\u062f\u06cc \u062e\u0631\u0648\u062c\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0645\u06cc\u200c\u0628\u0627\u0634\u0646\u062f \u0628\u0647 \u062e\u0637 \u0632\u06cc\u0631 \u0646\u06af\u0627\u0647 \u06a9\u0646\u06cc\u062f:\n\n\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">21:55:39.774315 IP google-public-dns-a.google.com.domain > debian.47888: 33222 NXDomain 0\/1\/0 (103)<\/pre>\n<p>hostname \u0633\u06cc\u0633\u062a\u0645 \u0634\u062e\u0635\u06cc \u0645\u0646 debian \u0645\u06cc\u200c\u0628\u0627\u0634\u062f packet \u0627\u0632 \u0633\u06cc\u0633\u062a\u0645  google-public-dns-a.google.com \u0628\u0647 \u0633\u06cc\u0633\u062a\u0645 \u0645\u0646 \u0627\u0646\u062a\u0642\u0627\u0644 \u067e\u06cc\u062f\u0627 \u06a9\u0631\u062f\u0647 \u0627\u0633\u062a. \u0647\u0645\u0627\u0646\u0637\u0648\u0631 \u06a9\u0647 \u0627\u0632 \u0646\u0627\u0645\u0634 \u067e\u06cc\u062f\u0627\u0633\u062a resolve \u06a9\u0631\u062f\u0646 \u0628\u0648\u062f\u0647 \u06cc\u06a9 NXDomain \u0628\u0648\u062f\u0647 \u0627\u0633\u062a. \u0628\u0647 \u0632\u0648\u062f\u06cc \u0686\u0634\u0645\u062a\u0627\u0646 \u0628\u0627 \u0628\u0642\u06cc\u0647 \u0645\u0642\u0627\u062f\u06cc\u0631 \u0622\u0634\u0646\u0627 \u0645\u06cc\u200c\u0634\u0648\u062f.<br \/>\n<strong>option \u0647\u0627\u06cc \u062e\u0627\u0646\u0648\u0627\u062f\u0647 v- :<\/strong><br \/>\nv- \u0647\u0645\u0627\u0646\u0637\u0648\u0631 \u06a9\u0647 \u0627\u0632 \u0646\u0627\u0645\u0634 \u067e\u06cc\u062f\u0627\u0633\u062a verbose mode \u0627\u0633\u062a. \u0627\u06cc\u0646 verbose mode \u0628\u0631\u0627\u06cc \u0641\u0631\u0645\u062a \u062e\u0631\u0648\u062c\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<br \/>\nvv-  \u0628\u0633\u062a\u0647\u200c\u200c\u0647\u0627 \u0631\u0627 \u0628\u0627\u0632 \u0645\u06cc\u200c\u06a9\u0646\u062f.  \u0648 \u0641\u06cc\u0644\u062f\u0647\u0627\u06cc \u0628\u06cc\u0634\u062a\u0631\u06cc \u0631\u0627 \u0628\u0647 \u0646\u0645\u0627\u06cc\u0634 \u0645\u06cc\u200c\u06af\u0630\u0627\u0631\u062f.<br \/>\nvvv- \u0628\u0647 \u0635\u0648\u0631\u062a \u06a9\u0627\u0645\u0644 \u06af\u0632\u06cc\u0646\u0647\u200c\u0647\u0627 \u0631\u0627 \u0646\u0645\u0627\u06cc\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f.<br \/>\n<strong>\u0646\u06a9\u062a\u0647:<\/strong> \u0627\u06cc\u0646\u062c\u0627 \u0645\u062b\u0627\u0644 \u0646\u0645\u06cc\u0627\u0648\u0631\u06cc\u0645 \u0686\u0648\u0646 \u0641\u0631\u0636 \u0628\u0631 \u0627\u06cc\u0646 \u0627\u0633\u062a \u06a9\u0647 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0634\u0645\u0627 \u0631\u0627 \u0646\u0645\u06cc\u200c\u062f\u0627\u0646\u06cc\u0645\u060c \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u06af\u0627\u0647\u06cc \u0628\u0631\u0627\u06cc \u0634\u062e\u0635\u06cc \u0628\u0627\u06cc\u062f \u06cc\u06a9 log \u0628\u06af\u06cc\u0631\u06cc\u062f \u0648 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0633\u0646\u062f \u0628\u0631\u0627\u06cc\u0634 \u0628\u0641\u0631\u0633\u062a\u06cc\u062f \u06a9\u0647 \u0628\u0647\u062a\u0631 \u0627\u0633\u062a log \u0634\u0645\u0627 \u06a9\u0627\u0645\u0644 \u0628\u0627\u0634\u062f. \u0627\u0645\u0627 \u0646\u0647 \u06af\u0627\u0647\u06cc \u0646\u06cc\u0627\u0632 \u0627\u0633\u062a \u0627\u0632 tcpdump \u0641\u0642\u0637 \u06cc\u06a9 grep \u06af\u0631\u0641\u062a\u0647 \u06a9\u0647 \u0628\u0627\u0632 \u0628\u0633\u062a\u0647 \u0628\u0647 \u0627\u06cc\u0646 \u06a9\u0647 \u0627\u0632 \u0686\u0647 \u0686\u06cc\u0632\u06cc \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u062f grep \u0628\u06af\u06cc\u0631\u06cc\u062f \u0628\u0647 \u0622\u0646 \u0628\u0627\u06cc\u062f \u06af\u0632\u06cc\u0646\u0647 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f \u0686\u0648\u0646 \u06a9\u0627\u0631 \u062e\u0648\u062f \u0631\u0627 \u0633\u062e\u062a \u06a9\u0631\u062f\u0647\u200c\u0627\u06cc\u062f. \u067e\u0633 \u0634\u0645\u0627 \u0628\u0627\u06cc\u062f \u062e\u0648\u062f \u0646\u06cc\u0627\u0632\u0633\u0646\u062c\u06cc \u06a9\u0646\u06cc\u062f \u062a\u0627 \u0628\u0647 \u0646\u062a\u06cc\u062c\u0647 \u0628\u0647\u062a\u0631\u06cc \u0628\u0631\u0633\u06cc\u062f.<br \/>\n\u067e\u0633 \u062e\u0648\u0627\u0647\u0634\u06cc \u06a9\u0647 \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f \u0646\u06a9\u062a\u0647 \u0628\u0627\u0644\u0627 \u0631\u0627 \u062f\u0631 \u062a\u0645\u0627\u0645 \u0645\u062b\u0627\u0644\u200c\u0647\u0627 \u0631\u0639\u0627\u06cc\u062a \u0641\u0631\u0645\u0627\u06cc\u06cc\u062f.<br \/>\n<strong>\u0627\u0645\u0627 \u0686\u0646\u062f \u0645\u062b\u0627\u0644 \u0633\u0627\u062f\u0647:<\/strong><br \/>\n\u0647\u0645\u0627\u0646\u0646\u062f \u0633\u0627\u06cc\u0631 \u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0645\u062b\u0644 netstat \u0634\u0645\u0627 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f hostname \u0647\u0627 \u0631\u0627 \u0646\u062f\u06cc\u062f \u06af\u0631\u0641\u062a\u0647 \u0648 \u0627\u0632 \u0641\u0631\u0645\u062a IP \u0622\u0646\u200c\u0647\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u0645\u0627\u06cc\u06cc\u062f \u0647\u0645\u0627\u0646\u0646\u062f \u0632\u06cc\u0631 :<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump  -i eth0 -n\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n03:07:30.191457 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 328\r\n03:07:30.300709 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 328\r\n03:07:30.408663 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 337\r\n03:07:30.518178 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 337\r\n03:07:30.627724 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 392\r\n03:07:30.737305 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 392\r\n03:07:30.804819 IP 74.125.195.189.443 > 192.168.1.4.43132: Flags [P.], seq 2104755659:2104755718, ack 652043965, win 1653, options [nop,nop,TS val 166742941 ecr 4375072], length 59\r\n03:07:30.804895 IP 192.168.1.4.43132 > 74.125.195.189.443: Flags [.], ack 59, win 940, options [nop,nop,TS val 4381302 ecr 166742941], length 0\r\n03:07:30.847981 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 402\r\n03:07:30.956411 IP 192.168.1.1.32865 > 239.255.255.250.1900: UDP, length 402\r\n^C\r\n10 packets captured\r\n10 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p>tcpdump \u06cc\u06a9 option \u062f\u0627\u0631\u062f \u06a9\u0647 \u0628\u0647 \u0645\u0627 \u06a9\u0645\u06a9 \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u062a\u0639\u062f\u0627\u062f \u0628\u0633\u062a\u0647 \u0631\u0627 \u0645\u0634\u062e\u0635 \u06a9\u0646\u06cc\u0645 \u0627\u0644\u0628\u062a\u0647 \u0628\u062f\u0631\u062f \u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0645\u06cc\u200c\u062e\u0648\u0631\u062f\u060c \u062f\u0631 \u062f\u0646\u06cc\u0627\u06cc \u0648\u0627\u0642\u0639\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f \u06a9\u0645\u06cc \u062f\u0627\u0631\u062f \u0648\u0644\u06cc \u0628\u0647 \u062f\u0631\u062f \u0622\u0645\u0627\u0631 \u062f\u0631 \u0633\u0627\u0639\u062a \u0645\u06cc\u200c\u062e\u0648\u0631\u062f.<br \/>\n\u0628\u06cc\u0627\u06cc\u06cc\u062f \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u0646\u0645\u0627\u06cc\u06cc\u0645:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c2 -A -vvv\r\ntcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n03:11:49.131499 IP (tos 0x0, ttl 4, id 0, offset 0, flags [DF], proto UDP (17), length 356)\r\n    192.168.1.1.32865 > 239.255.255.250.1900: [udp sum ok] UDP, length 328\r\nE..d..@..............a.l.P..NOTIFY * HTTP\/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=100\r\nLOCATION: http:\/\/192.168.1.1:49152\/description.xml\r\nNT: upnp:rootdevice\r\nNTS: ssdp:alive\r\nSERVER: Linux\/2.6.22.15, UPnP\/1.0, Portable SDK for UPnP devices\/1.3.1\r\nX-User-Agent: redsonic\r\nUSN: uuid:bc329e00-1dd8-11b2-8601-0026755d2a2e::upnp:rootdevice\r\n\r\n\r\n03:11:49.239209 IP (tos 0x0, ttl 4, id 0, offset 0, flags [DF], proto UDP (17), length 356)\r\n    192.168.1.1.32865 > 239.255.255.250.1900: [udp sum ok] UDP, length 328\r\nE..d..@..............a.l.P..NOTIFY * HTTP\/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=100\r\nLOCATION: http:\/\/192.168.1.1:49152\/description.xml\r\nNT: upnp:rootdevice\r\nNTS: ssdp:alive\r\nSERVER: Linux\/2.6.22.15, UPnP\/1.0, Portable SDK for UPnP devices\/1.3.1\r\nX-User-Agent: redsonic\r\nUSN: uuid:bc329e00-1dd8-11b2-8601-0026755d2a2e::upnp:rootdevice\r\n\r\n\r\n2 packets captured\r\n4 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p><strong>\u062a\u062d\u0644\u06cc\u0644 \u067e\u0627\u0631\u0627\u0645\u062a\u0631\u200c\u0647\u0627\u06cc tcpdump:<\/strong> \u062f\u0631 \u0627\u0628\u062a\u062f\u0627 \u0628\u0647 \u0622\u0646 interface \u0631\u0627 \u0645\u0639\u0631\u0641\u06cc \u06a9\u0631\u062f\u06cc\u0645 \u0648 \u06af\u0641\u062a\u06cc\u0645 \u0647\u0645\u0647 \u0686\u06cc \u0631\u0627 \u0628\u0647\u0647 \u0635\u0648\u0631\u062a numeric \u0628\u0631\u06af\u0631\u062f\u0627\u0646. \u0633\u067e\u0633 \u0628\u0627  c2- \u0628\u0647 \u0622\u0646 \u06af\u0641\u062a\u06cc\u0645 \u062f\u0648 \u0628\u0633\u062a\u0647 \u0631\u0627 capture \u06a9\u0646. \u067e\u0627\u0631\u0627\u0645\u062a\u0631 A- \u0645\u06cc\u200c\u06af\u0648\u06cc\u062f \u0647\u0631 \u0646\u0648\u0639 \u0628\u0633\u062a\u0647\u200c\u0627\u06cc \u0631\u0627 capture \u06a9\u0646\u062f \u06a9\u0647 \u0627\u06cc\u0646 \u0627\u0635\u0644\u0627\u064b \u062e\u0648\u0628 \u0646\u06cc\u0633\u062a \u0648 \u062f\u0631 \u062c\u0644\u0648\u062a\u0631 \u0628\u0627 \u0622\u0646 \u0628\u0631\u062e\u0648\u0631\u062f \u0627\u0633\u0627\u0633\u06cc \u0645\u06cc\u200c\u0634\u0648\u062f. \u0648 \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0628\u0647 \u0635\u0648\u0631\u062a full \u0628\u0633\u062a\u0647 \u0648 option\u0647\u0627\u06cc \u0622\u0646 \u0631\u0627 \u0627\u0632 tcpdump \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06a9\u0631\u062f\u06cc\u0645.<\/p>\n<p><strong>\u062a\u062d\u0644\u06cc\u0644 \u0628\u0633\u062a\u0647\u200c\u0647\u0627:<\/strong> \u06a9\u0627\u0641\u06cc\u0633\u062a \u06a9\u0645\u06cc \u0628\u0627 \u0686\u0634\u0645 \u0628\u0647 \u0622\u0646 \u062f\u0648 \u0628\u0633\u062a\u0647 \u06a9\u0647 \u0628\u0627 blank line \u0627\u0632 \u0647\u0645 \u062c\u062f\u0627 \u0634\u062f\u0647\u200c\u0627\u0646\u062f \u062f\u0642\u062a \u06a9\u0646\u06cc\u0645. \u062f\u0648 \u0628\u0633\u062a\u0647 \u0627\u0632 \u0646\u0648\u0639 UDP \u06a9\u0647 \u0628\u0627 \u0637\u0648\u0644 \u06f3\u06f5\u06f6 \u0645\u06cc\u200c\u0628\u0627\u0634\u0646\u062f \u0648 TTL \u0628\u0631\u0627\u0628\u0631 \u06f4. \u0627\u0644\u0628\u062a\u0647 \u062c\u0632\u06cc\u06cc\u0627\u062a \u062e\u06cc\u0644\u06cc \u0628\u06cc\u0634\u062a\u0631 \u0642\u0627\u0628\u0644 \u0631\u0648\u06cc\u062a\u200c \u0647\u0633\u062a\u0646\u062f. \u0647\u0645\u0627\u0646\u0637\u0648\u0631 \u06a9\u0647 \u0642\u0628\u0644\u0627\u064b \u06af\u0641\u062a\u0647 \u0634\u062f vvv- \u062e\u06cc\u0644\u06cc \u0627\u0632 \u0628\u0633\u062a\u0647\u200c\u0647\u0627 \u0631\u0627 \u0628\u0627\u0632\u0646\u0645\u0648\u062f\u0647 \u0648 \u0627\u06cc\u0646 \u06f2 \u0628\u0633\u062a\u0647 \u0627\u0632 \u0646\u0648\u0639 Cache \u0645\u06cc\u200c\u0628\u0627\u0634\u0646\u062f \u0628\u0647 \u0637\u0648\u0631\u06cc \u06a9\u0647X-User-Agent \u0622\u0646\u200c\u0647\u0627 \u0647\u0645 \u0645\u0634\u062e\u0635 \u0627\u0633\u062a.<br \/>\n\u0628\u0647 \u0633\u0627\u062f\u06af\u06cc \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u06af\u0632\u06cc\u0646\u0647 server \u0631\u0627 \u062f\u0631 \u0622\u0646 grep \u06a9\u0631\u062f\u0647 \u0648 \u0646\u062a\u06cc\u062c\u0647 \u0632\u06cc\u0631 \u0631\u0627 \u062d\u0627\u0635\u0644 \u06a9\u0631\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c2 -A -vvv |grep -i server \r\ntcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n2 packets captured\r\n8 packets received by filter\r\n0 packets dropped by kernel\r\nSERVER: Linux\/2.6.22.15, UPnP\/1.0, Portable SDK for UPnP devices\/1.3.1\r\nSERVER: Linux\/2.6.22.15, UPnP\/1.0, Portable SDK for UPnP devices\/1.3.1<\/pre>\n<p><strong>\u0646\u06a9\u062a\u0647:<\/strong> \u062f\u0644 \u0628\u0647 \u0627\u06cc\u0646 grep \u06a9\u0631\u062f\u0646 \u062e\u0648\u0634 \u0646\u06a9\u0646\u06cc\u0645 \u0648 \u0628\u0647 \u0645\u062b\u0627\u0644\u200c\u0647\u0627\u06cc \u062c\u0644\u0648\u062a\u0631 \u06a9\u0647 \u0628\u0631\u0633\u06cc\u0645 \u0645\u06cc\u200c\u0641\u0647\u0645\u06cc\u0645 \u06a9\u0647 \u0647\u0631 \u0686\u0642\u062f\u0631 \u062c\u0644\u0648\u062a\u0631 \u0628\u0631\u0648\u06cc\u0645 \u0641\u0647\u0645\u0645\u0627\u0646 \u0631\u0627 \u0628\u0627\u06cc\u062f \u0627\u0632 \u0634\u0628\u06a9\u0647 \u0628\u06cc\u0634\u062a\u0631 \u06a9\u0646\u06cc\u0645.<br \/>\n\u0622\u06cc\u0627 \u0628\u0633\u062a\u0647 \u0628\u0627 vvv- \u0628\u0627\u0632 \u0634\u062f\u061f \u0628\u0644\u0647 \u0627\u0645\u0627 \u0647\u0646\u0648\u0632 \u0627\u0628\u0632\u0627\u0631 \u0634\u0645\u0627 \u06a9\u0645\u06cc \u0646\u0627\u0642\u0635 \u0627\u0633\u062a. \u0642\u0628\u0644\u0627\u064b xx- \u06a9\u0648\u0686\u06a9 \u0628\u0648\u062f \u06a9\u0647 \u0628\u0647 \u0635\u0648\u0631\u062a hex   \u0647\u062f\u0631\u0647\u0627\u06cc\u06cc \u0631\u0627 \u0628\u0627\u0632 \u0645\u06cc\u200c\u0646\u0645\u0648\u062f \u0627\u0645\u0627 deprecate \u0634\u062f. \u0628\u0647 \u062f\u0648 \u062f\u0644\u06cc\u0644: <\/p>\n<ul>\n<li style=\"margin-right: 30px;\">\n<p>\n \u067e\u0631\u0648\u062a\u06a9\u0644\u200c\u0647\u0627\u06cc \u062c\u062f\u06cc\u062f \u0631\u0627 \u062d\u0645\u0627\u06cc\u062a \u0646\u0645\u06cc\u200c\u06a9\u0646\u062f.<\/p>\n<\/li>\n<li style=\"margin-right: 30px;\">\n<p>\n \u0628\u0647 \u0635\u0648\u0631\u062a ASCII \u067e\u0631\u06cc\u0646\u062a \u0646\u0645\u06cc\u200c\u06a9\u0646\u062f.<\/p>\n<\/li>\n<\/ul>\n<p>\u0647\u0645\u0627\u0646 xx- \u0631\u0627 \u0627\u06af\u0631 \u0628\u0647 \u0635\u0648\u0631\u062a upercase \u06cc\u0639\u0646\u06cc XX- \u0628\u0647 \u06a9\u0627\u0631 \u0628\u0628\u0631\u06cc\u0645 \u0647\u0645\u0647 \u0686\u06cc \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc\u200c\u06a9\u0646\u062f.\u0628\u0647 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631 \u0646\u06af\u0627\u0647 \u06a9\u0646\u06cc\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c1 -A -vvv -xx\r\ntcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n03:57:01.757946 IP (tos 0x88, ttl 39, id 37674, offset 0, flags [none], proto TCP (6), length 111)\r\n    74.125.195.189.443 > 192.168.1.4.43132: Flags [P.], cksum 0xf122 (correct), seq 2104786500:2104786559, ack 652173423, win 1653, options [nop,nop,TS val 169713897 ecr 5118382], length 59\r\n\t0x0000:  1803 7360 b44e 0026 755d 2a2e 0800 4588\r\n\t0x0010:  006f 932a 0000 2706 2ff0 4a7d c3bd c0a8\r\n\t0x0020:  0104 01bb a87c 7d74 7e44 26df 606f 8018\r\n\t0x0030:  0675 f122 0000 0101 080a 0a1d a0e9 004e\r\n\t0x0040:  19ae 1703 0300 3600 0000 0000 0003 399c\r\n\t0x0050:  f906 ed6e 12d0 6d67 f7d6 59a7 8996 0faa\r\n\t0x0060:  98cb 05a4 feb2 0175 4821 eca2 bb83 bd32\r\n\t0x0070:  dd5d c36e 8314 d4ed f235 4c93 5e\r\n1 packet captured\r\n2 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p>\u062d\u0627\u0644\u0627 \u0647\u0645\u0627\u0646 \u0631\u0627 \u0628\u0627 upercase \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u062f\u0647\u06cc\u0645:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c1 -A -vvv -XX\r\ntcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n03:57:52.310213 IP (tos 0x0, ttl 64, id 47728, offset 0, flags [DF], proto UDP (17), length 61)\r\n    192.168.1.4.34498 > 8.8.8.8.53: [udp sum ok] 36690+ A? play.google.com. (33)\r\n\t0x0000:  0026 755d 2a2e 1803 7360 b44e 0800 4500     .&u]*...s`.N..E.\r\n\t0x0010:  003d ba70 4000 4011 ae83 c0a8 0104 0808      .=.p@.@.........\r\n\t0x0020:  0808 86c2 0035 0029 74b0 8f52 0100 0001     .....5.)t..R....\r\n\t0x0030:  0000 0000 0000 0470 6c61 7906 676f 6f67      .......play.goog\r\n\t0x0040:  6c65 0363 6f6d 0000 0100 01              le.com.....\r\n1 packet captured\r\n5 packets received by filter\r\n0 packets dropped by kernel\r\nroot@debian:\/home\/mohsen# <\/pre>\n<p>\u062f\u0648\u0645\u06cc \u0628\u0631\u0627\u06cc grep \u0639\u0627\u0644\u06cc \u0627\u0633\u062a. \u0628\u0627 \u062a\u062c\u0631\u0628\u0647 \u06a9\u0627\u0631\u06cc \u0628\u0647 \u06cc\u0627\u062f \u062f\u0627\u0631\u0645 \u0647\u0645\u06a9\u0627\u0631\u0645 \u0628\u0627 \u0647\u0645\u06cc\u0646 vvv- \u0648 XX- \u062d\u0645\u0644\u0647 \u06a9\u0646\u0646\u062f\u0647 \u0628\u0647 \u0633\u0627\u06cc\u062a \u0631\u0627 \u062a\u0648\u0627\u0646\u0633\u062a \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u0628\u0647 \u06a9\u062f\u0627\u0645 \u0633\u0627\u06cc\u062a \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u062f \u062d\u0645\u0644\u0647 \u06a9\u0646\u062f. \u062a\u0646\u0647\u0627 \u0628\u0627 grep&#8230;&#8230;!!!! \u0627\u0644\u0628\u062a\u0647 \u0641\u06cc\u0644\u062a\u0631\u0647\u0627\u06cc\u06cc \u0647\u0645 \u0646\u0648\u0634\u062a \u06a9\u0647 \u062f\u0631 \u062c\u0644\u0648\u062a\u0631 \u062a\u0648\u0636\u06cc\u062d \u0645\u06cc\u200c\u062f\u0647\u0645.<br \/>\n\u0631\u06a9\u0648\u0631\u062f \u062f\u0631 \u0641\u0627\u06cc\u0644 :<br \/>\n\u0628\u0644\u0647 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0634\u0645\u0627 \u0628\u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0644 capture \u0631\u0627 \u062f\u0631 \u0641\u0627\u06cc\u0644 \u0628\u0646\u0648\u06cc\u0633\u06cc\u062f \u0627\u06cc\u0646 \u06f2 \u0631\u0627\u0647 \u062f\u0627\u0631\u062f:<\/p>\n<ul>\n<li style=\"margin-right: 30px;\">\n<p>\n\u0634\u0645\u0627 \u06a9\u0644 \u062f\u0633\u062a\u0648\u0631 tcpdump \u0631\u0627 \u0628\u0627 \u06cc\u06a9 IO\/Redirection \u062f\u0631 \u06cc\u06a9 \u0641\u0627\u06cc\u0644 \u0630\u062e\u06cc\u0631\u0647 \u0646\u0645\u0627\u06cc\u06cc\u062f.<\/p>\n<\/li>\n<li style=\"margin-right: 30px;\">\n<p>\n\u0628\u0627 w- \u062f\u0631 \u06cc\u06a9 \u0641\u0627\u06cc\u0644 \u06cc\u0646\u0648\u0633\u06cc\u062f:<\/p>\n<\/li>\n<\/ul>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c1 -A -vvv -XX -w `date +%Y_%m_%d.pcap`\r\ntcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n1 packet captured\r\n5 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p>\u06a9\u0647 \u0641\u0627\u06cc\u0644 \u0631\u0648\u0628\u0631\u0648  \u0630\u062e\u06cc\u0631\u0647 \u0645\u06cc\u200c\u0634\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">2015_03_14.pcap<\/pre>\n<p><strong>\u0646\u06a9\u062a\u0647:<\/strong> \u067e\u0633\u0648\u0646\u062f \u0627\u06cc\u0646\u06af\u0648\u0646\u0647 \u0641\u0627\u06cc\u0644\u200c\u0647\u0627 pcap \u0645\u06cc\u200c\u0628\u0627\u0634\u062f.<br \/>\n<strong>\u0646\u06a9\u062a\u0647:<\/strong> \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0628\u062e\u0648\u0627\u0647\u06cc\u062f \u06af\u0632\u06cc\u0646\u0647 \u0632\u0645\u0627\u0646 \u0631\u0627 \u0627\u0632 \u062e\u0631\u0648\u062c\u06cc \u062d\u0630\u0641 \u0646\u0645\u0627\u06cc\u06cc\u062f \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 \u062e\u0627\u0646\u0648\u0627\u062f\u0647 t- \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u0645\u0627\u06cc\u06cc\u062f. \u0627\u0645\u0627 \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f \u0628\u0631\u0627\u06cc \u06af\u0631\u0641\u062a\u0646 log \u0628\u0631\u0627\u06cc \u06a9\u0633\u06cc \u06cc\u0627 \u062c\u0627\u06cc\u06cc \u06a9\u0647 \u0645\u0633\u062a\u0646\u062f \u0627\u0633\u062a \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u0646\u062f\u0647\u06cc\u062f.<br \/>\n\u062d\u0627\u0644 \u06a9\u0647 \u06af\u0648\u0634\u0647\u200c\u200c\u0627\u06cc \u0627\u0632 option \u0647\u0627\u06cc tcpdump \u0631\u0627 \u0641\u0631\u0627\u06af\u0631\u0641\u062a\u06cc\u062f \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 filter \u0646\u0648\u0634\u062a\u0646 \u0631\u0627 \u0641\u0631\u0627\u06af\u0631\u0641\u062a.<\/p>\n<p style=\"font-size: 18px;\"><strong>\u06f2. \u0646\u0648\u0634\u062a\u0646 filter<\/strong><\/p>\n<p>\u0628\u0631\u0627\u06cc \u0627\u0648\u0644 \u06a9\u0627\u0631 filter \u0646\u0648\u06cc\u0633\u06cc \u0628\u0627\u06cc\u062f \u06f4 \u0639\u0645\u0644\u06af\u0631 \u0627\u0635\u0644\u06cc \u0634\u0631\u0637\u06cc \u0622\u0646 \u0631\u0627 \u062f\u0627\u0646\u0633\u062a:<\/p>\n<ul>\n<li style=\"margin-right: 30px;\">\n<p>\n and \u06cc\u0627 \u0647\u0645\u0627\u0646 &#038;&#038;<\/p>\n<\/li>\n<li style=\"margin-right: 30px;\">\n<p>\n not \u06cc\u0627 \u0647\u0645\u0627\u0646 !<\/p>\n<\/li>\n<li style=\"margin-right: 30px;\">\n<p>\n or \u06cc\u0627 \u0647\u0645\u0627\u0646 ||<\/p>\n<\/li>\n<li style=\"margin-right: 30px;\">\n<p>\n \u0639\u0645\u0644\u06af\u0631 \u062a\u0633\u0627\u0648\u06cc \u06cc\u0627 \u0647\u0645\u0627\u0646 ==<\/p>\n<\/li>\n<\/ul>\n<p>\u062f\u0631 \u062c\u0644\u0648\u062a\u0631 \u0628\u0639\u0636\u06cc \u0627\u0632 \u0639\u0645\u0644\u06af\u0631\u200c\u0647\u0627\u06cc \u067e\u06cc\u0634\u0631\u0641\u062a\u0647\u200c\u062a\u0631 \u0631\u0627 \u0646\u06cc\u0632 \u062a\u0648\u0636\u06cc\u062d \u062e\u0648\u0627\u0647\u06cc\u0645 \u062f\u0627\u062f. (\u0627\u0644\u0628\u062a\u0647 \u062f\u0631 \u0645\u062b\u0627\u0644)<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c2 'dst port 80 or 443'\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n05:02:55.093879 IP 192.168.1.4.58878 > 10.10.34.34.443: Flags [S], seq 2334601873, win 29200, options [mss 1460,sackOK,TS val 6112375 ecr 0,nop,wscale 7], length 0\r\n05:02:56.633867 IP 192.168.1.4.48764 > 74.125.195.100.443: Flags [P.], seq 3792460615:3792460656, ack 1332089255, win 397, options [nop,nop,TS val 6112759 ecr 3204520238], length 41\r\n2 packets captured\r\n4 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p>\u0647\u0645\u0627\u0646\u0637\u0648\u0631 \u06a9\u0647 \u062f\u0631 \u0641\u0631\u0645\u0627\u0646 \u0628\u0627\u0644\u0627 \u062f\u06cc\u062f\u06cc\u062f \u0645\u0633\u06cc\u0631 \u0628\u0633\u062a\u0647\u200c\u0647\u0627 \u0631\u0627 \u0628\u0647 \u0628\u06cc\u0631\u0648\u0646 \u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0647 \u0648 \u067e\u0648\u0631\u062a\u200c\u0647\u0627 \u0631\u0627 \u0628\u0647 \u067e\u0648\u0631\u062a SSL \u0648\u0628 \u0648 \u067e\u0648\u0631\u062a \u0639\u0627\u062f\u06cc \u0648\u0628 \u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u06cc\u0645. \u0627\u06cc\u0646 \u0628\u062f\u0627\u0646 \u0645\u0639\u0646\u0627\u0633\u062a \u06a9\u0647 \u0647\u0631\u0686\u0647 request \u0648\u0628 \u062f\u0627\u0634\u062a\u06cc\u0645 capture \u0645\u06cc\u200c\u0634\u0648\u062f.<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 -n -c2 'dst port 995 or 465'\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n05:28:27.850431 IP 192.168.1.4.58666 > 198.23.143.231.995: Flags [S], seq 3003232596, win 29200, options [mss 1460,sackOK,TS val 6495564 ecr 0,nop,wscale 7], length 0\r\n05:28:28.175118 IP 192.168.1.4.58666 > 198.23.143.231.995: Flags [.], ack 1659429373, win 229, options [nop,nop,TS val 6495645 ecr 3266956330], length 0\r\n2 packets captured\r\n3 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p>\u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0628\u0627\u0644\u0627 \u0628\u0647 \u067e\u0648\u0631\u062a\u200c\u0647\u0627\u06cc \u0645\u0642\u0635\u062f pops \u0648 smpts \u0631\u0627 capture \u06a9\u0631\u062f\u06cc\u0645.<br \/>\n\u0627\u06cc\u0646 \u0686\u0646\u06cc\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0647\u0645 \u0627\u0632 \u0639\u0645\u0644\u06af\u0631 and \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f \u0648 \u0647\u0645 \u0645\u062d\u062f\u0648\u062f \u0628\u0647 \u06cc\u06a9 host \u0634\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0  -c2 'src port 443 or 80 ' and host google.com\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n05:37:39.889315 IP wj-in-f139.1e100.net.http > debian.35368: Flags [.], ack 3030103160, win 341, options [nop,nop,TS val 1627400588 ecr 6631017], length 0\r\n05:37:39.905789 IP wj-in-f139.1e100.net.http > debian.35369: Flags [.], ack 3973516011, win 341, options [nop,nop,TS val 3679981984 ecr 6631021], length 0\r\n2 packets captured\r\n7 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p><strong>\u0646\u06a9\u062a\u0647:<\/strong> host \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f IP \u0628\u0627\u0634\u062f.<br \/>\n\u0628\u0627 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 src host \u0631\u0627 \u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u06cc\u0645 \u0628\u0647 \u06cc\u06a9\u06cc \u0627\u0632 \u06a9\u0644\u0627\u06cc\u062a\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u0648 \u0628\u0627 \u062f\u0648 \u067e\u0631\u0648\u062a\u06a9\u0644 arp \u0648 \u06cc\u0627 icmp \u0622\u0646 \u0631\u0627 and \u06a9\u0631\u062f\u06cc\u0645 \u0648 \u0627\u0632 \u0647\u0645\u06cc\u0646 \u0645\u0627\u0634\u06cc\u0646 \u0622\u0646 \u0631\u0627 ping \u06a9\u0631\u062f\u06cc\u0645 \u0648 \u062c\u0648\u0627\u0628 \u06af\u0631\u0641\u062a\u06cc\u0645:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0  -c2 'src host 192.168.1.1 and ( arp or icmp )'\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n05:52:33.558905 IP 192.168.1.1 > debian: ICMP echo reply, id 9862, seq 19, length 64\r\n05:52:34.560079 IP 192.168.1.1 > debian: ICMP echo reply, id 9862, seq 20, length 64\r\n2 packets captured\r\n3 packets received by filter\r\n0 packets dropped by kernel<\/pre>\n<p>\u0641\u0631\u0645\u0627\u0646 \u0632\u06cc\u0631 \u0627\u0632 \u0639\u0645\u0644\u06af\u0631 =! \u0627\u0633\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f\u0647 \u0628\u0648\u062f \u0648 \u062f\u0631 \u062e\u0648\u062f <em>(8)tcpdump <\/em> \u0648\u0644\u06cc \u062d\u06cc\u0641\u0645 \u0627\u0648\u0645\u062f \u06a9\u0647 \u0628\u0631\u0627\u062a\u0648\u0646 \u0646\u06af\u0630\u0627\u0631\u0645 \u0627\u06cc\u0646 \u062a\u0645\u0627\u0645  type \u0647\u0627\u06cc icmp \u0631\u0648 \u067e\u0631\u06cc\u0646\u062a \u0645\u06cc\u200c\u06af\u0631\u0647 \u0628\u0647 \u062c\u0632 ping \u0648 pong \u062f\u0631\u200c\u0648\u0627\u0642\u0639 type \u0647\u0627\u06cc echo \u0648 echo reply:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -i eth0 'icmp[icmptype] != icmp-echo and icmp[icmptype] != icmp-echoreply'<\/pre>\n<p>\u0628\u0631\u0627\u06cc \u0627\u06cc\u0646\u06a9\u0647 \u062f\u0631 \u062e\u0631\u0648\u062c\u06cc \u0686\u06cc\u0632\u06cc \u0628\u0628\u06cc\u0646\u06cc\u062f\u060c \u062f\u0631 \u0647\u0645\u06cc\u0646 host \u0628\u0627\u06cc\u062f icmp \u0631\u0627 \u0628\u0627 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0628\u0633\u062a:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# iptables -A INPUT -p icmp -j REJECT<\/pre>\n<p>\u0633\u067e\u0633 \u0628\u0647 \u06cc\u06a9 host \u062f\u06cc\u06af\u0631 \u0631\u0641\u062a\u0647 \u0648 \u0633\u0639\u06cc \u06a9\u0646\u06cc\u0645 \u0628\u0647 \u0627\u06cc\u0646 host \u062f\u0633\u062a\u0631\u0633\u06cc \u067e\u06cc\u062f\u0627 \u06a9\u0646\u06cc\u0645 \u0648 \u067e\u06cc\u063a\u0627\u0645 \u0632\u06cc\u0631 \u0631\u0627 \u062f\u0631 \u0647\u0645\u06cc\u0646 host \u0645\u06cc\u200c\u0628\u06cc\u0646\u06cc\u0645:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -A -i eth0 'icmp[icmptype] != icmp-echo and icmp[icmptype] != icmp-echoreply'\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n06:09:44.546077 IP debian > 192.168.1.8: ICMP debian protocol 1 port 5965 unreachable, length 92\r\nE..p;~..@...................E..T.>..@..............M....U........\t\r\n..................... !\"#$%&'()*+,-.\/01234567\r\n06:09:45.603283 IP debian > 192.168.1.8: ICMP debian protocol 1 port 13870 unreachable, length 92\r\nE..p<v..@...................E..T.B..@..\r\n..........6.....U........\t\r\n..................... !\"#$%&#038;'()*+,-.\/01234567<\/pre>\n<p><strong>\u0646\u06a9\u062a\u0647:<\/strong> \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u0627\u0632 src \u0648 \u06cc\u0627 dst \u0628\u0631\u0627\u06cc host \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u0634\u0648\u062f \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0628\u06cc\u0646 \u062f\u0648 host \u0628\u0627\u06cc\u062f capture \u0634\u0648\u062f \u0628\u0647 \u0645\u062b\u0627\u0644 \u0632\u06cc\u0631 \u062f\u0642\u062a \u0634\u0648\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">root@debian:\/home\/mohsen# tcpdump -A -i eth0  host 192.168.1.1 and host 192.168.1.8\r\ntcpdump: verbose output suppressed, use -v or -vv for full protocol decode\r\nlistening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes\r\n06:20:45.792313 IP 192.168.1.8 > 192.168.1.1: ICMP echo request, id 3845, seq 0, length 64\r\nE..T....@.............BW....U..;...Z.\t\r\n..................... !\"#$%&'()*+,-.\/01234567\r\n06:20:45.792328 IP 192.168.1.8 > 192.168.1.1: ICMP echo request, id 3845, seq 0, length 64\r\nE..T....@.............BW....U..;...Z.\t\r\n..................... !\"#$%&'()*+,-.\/01234567<\/pre>\n<p>\u0645\u0627\u0634\u06cc\u0646\u06cc \u06a9\u0647 \u0628\u0631 \u0631\u0648\u06cc \u0622\u0646 tcpdump \u06af\u0631\u0641\u062a\u06cc\u0645 IP \u0622\u0646 4 \u0645\u06cc\u200c\u0628\u0627\u0634\u062f \u0648 \u062f\u0631\u200c\u0648\u0627\u0642\u0639 \u0645\u0627 \u0627\u06cc\u0646\u062c\u0627 sniff \u06a9\u0631\u062f\u06cc\u0645.<\/p>\n<p>\u0628\u0631\u0627\u06cc \u062a\u0633\u062a \u06a9\u0631\u062f\u0646 handshaking \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0627\u0632 filter \u0647\u0627\u06cc \u0632\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f:<\/p>\n<pre class=\"theme:dark-terminal font:liberation-mono font-size:14 nums:false line-height:20 toolbar:2 scroll:true lang:sh decode:true plain:false\">ACK packets:\r\n\u2018tcp[13] & 16\u00a0!= 0\u2018 \r\nPSH packets:\r\n\u2018tcp[13] & 8\u00a0!= 0\u2018 \r\nRST packets:\r\n\u2018tcp[13] & 4\u00a0!= 0\u2018 \r\nSYN packets:\r\n\u2018tcp[13] & 2\u00a0!= 0\u2032 \r\nFIN packets:\r\n\u2018tcp[13] & 1\u00a0!= 0\u2018 \r\nSYN-ACK packets:\r\n\u2018tcp[13] = 18\u2018 \r\n<\/pre>\n<p><em>tcpdump \u0628\u0632\u0631\u06af\u062a\u0631 \u0627\u0632 \u0622\u0646 \u0627\u0633\u062a \u06a9\u0647 \u0628\u062e\u0648\u0627\u0647\u0645 \u062f\u0631 tutorial \u0633\u0627\u062f\u0647 \u062a\u0645\u0627\u0645 \u0639\u0645\u0644\u06af\u0631\u0647\u0627\u06cc \u0622\u0646 \u0631\u0627 \u0628\u06af\u0648\u06cc\u0645 \u0648 \u06cc\u0627 filter \u0647\u0627\u06cc \u0622\u0646 \u0631\u0627 \u0627\u0634\u0627\u0631\u0647 \u06a9\u0646\u0645. \u0647\u0631 \u06af\u0648\u0646\u0647 filter \u0622\u0646 \u0628\u0647 \u06cc\u06a9 \u06af\u0648\u0646\u0647 error \u0628\u0631 \u0645\u06cc\u200c\u062e\u0648\u0631\u062f \u06a9\u0647 \u0627\u06cc\u0646 \u062e\u0648\u062f \u062a\u062c\u0631\u0628\u0647\u200c\u0627\u06cc\u0633\u062a \u0628\u0631\u0627\u06cc \u06cc\u06a9 sysadmin. \u0627\u0645\u0627 \u0627\u0645\u06cc\u062f\u0648\u0627\u0631\u0645 \u062a\u0648\u0627\u0646\u0633\u062a\u0647 \u0628\u0627\u0634\u0645 \u0634\u0645\u0627 \u0631\u0627 \u0628\u0627 \u0622\u0646 \u0622\u0634\u0646\u0627 \u06a9\u0631\u067e\u062f\u0647 \u0628\u0627\u0634\u0645.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u0647\u0645\u06cc\u0634\u0647 \u0628\u0631\u0627\u06cc \u0628\u0639\u0636\u06cc \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0633\u0624\u0627\u0644\u0627\u062a\u06cc \u0645\u0637\u0631\u062d \u0627\u0633\u062a \u06a9\u0647 \u0627\u0632 \u06a9\u062f\u0627\u0645 \u0628\u0631\u0646\u0627\u0645\u0647 \u0628\u0631\u0627\u06cc log \u06af\u06cc\u0631\u06cc \u0634\u0628\u06a9\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u0645\u0627\u06cc\u0646\u062f. \u062a\u0627 \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u0627\u06cc\u0646 \u062e\u0648\u0627\u0633\u062a\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0645\u0634\u062e\u0635 \u0646\u0628\u0627\u0634\u062f \u0627\u06cc\u0646 \u0633\u0624\u0627\u0644 \u0628\u062f\u0648\u0646 \u062c\u0648\u0627\u0628 \u0628\u0627\u0642\u06cc \u0645\u06cc\u200c\u0645\u0627\u0646\u062f. \u062e\u0648\u0628 \u0645\u0633\u0644\u0645\u0627\u064b \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u0632\u06cc\u0627\u062f\u06cc \u0628\u0627 \u06a9\u0627\u0631\u0628\u0631\u062f\u200c\u0647\u0627\u06cc \u0632\u06cc\u0627\u062f\u06cc \u0647\u0633\u062a\u0646\u062f \u0627\u0646\u0648\u0627\u0639 monitoring \u0634\u0628\u06a9\u0647 \u0631\u0627 \u062f\u0627\u0631\u06cc\u0645 \u06a9\u0647 \u0647\u0631\u06cc\u06a9 \u0628\u0646\u0627 \u0628\u0647 \u0631\u0633\u062a\u0647 \u062e\u0648\u062f \u0645\u0648\u0631\u062f \u0628\u062d\u062b \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u062f &hellip; <a href=\"http:\/\/pahlevanzadeh.net\/?p=409\" class=\"more-link\">\u0627\u062f\u0627\u0645\u0647 \u062e\u0648\u0627\u0646\u062f\u0646 <span class=\"screen-reader-text\">\u0645\u0642\u062f\u0645\u0647\u200c\u0627\u06cc \u0628\u0631 tcpdump<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,2,111,67,109],"tags":[138,7,137,136,55,52],"_links":{"self":[{"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=\/wp\/v2\/posts\/409"}],"collection":[{"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=409"}],"version-history":[{"count":7,"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=\/wp\/v2\/posts\/409\/revisions"}],"predecessor-version":[{"id":904,"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=\/wp\/v2\/posts\/409\/revisions\/904"}],"wp:attachment":[{"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=409"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/pahlevanzadeh.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}