Wiresharkã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ããã£ããã£ããã³åæããããã®éåžžã«ããç¥ãããããŒã«ã§ãããå®éã«ã¯æè²ãšãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®äž¡æ¹ã®æšæºã§ãã
Wiresharkã¯ãæ¢ç¥ã®ãããã³ã«ã®å€§éšåã§åäœããGTK +ã«åºã¥ãæ確ã§è«ççãªã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ãšåŒ·åãªãã£ã«ã¿ãŒã·ã¹ãã ãåããŠããŸãã
ã¯ãã¹ãã©ãããã©ãŒã ã§ãLinuxãSolarisãFreeBSDãNetBSDãOpenBSDãMac OS XããããŠãã¡ããWindowsãªã©ã®OSã§åäœããŸãã GNU GPL v2ã©ã€ã»ã³ã¹ã®äžã§é åžãããŸãã wireshark.orgã§ç¡æã§å ¥æã§ããŸãã
Windowsã·ã¹ãã ãžã®ã€ã³ã¹ããŒã«ã¯ç°¡åã§ã-次ã次ã次ã
å·çæç¹ã§ã®ææ°ããŒãžã§ã³ã¯1.10.3ã§ãããã¬ãã¥ãŒã«åå ããŸãã
ãªããã±ããã¢ãã©ã€ã¶ãŒãå¿ èŠãªã®ã§ããïŒ
ãããã¯ãŒã¯ã®ã¢ããªã±ãŒã·ã§ã³ãšãããã³ã«ã®ç 究ãè¡ãããããã¯ãŒã¯ã®åé¡ãçºèŠããéèŠãªããšã«ã¯ããããã®åé¡ã®åå ãçºèŠããããã
ã¹ããã¡ãŸãã¯ãã©ãã£ãã¯ã¢ãã©ã€ã¶ã®äœ¿çšãæ倧åããã«ã¯ãå°ãªããšããããã¯ãŒã¯ãšãããã¯ãŒã¯ãããã³ã«ã®åäœã«é¢ããäžè¬çãªç¥èãšç解ãå¿ èŠã§ããããšã¯æããã§ãã
ãŸããå€ãã®åœã§ã¯ãæ瀺çãªèš±å¯ãªãã«ã¹ãããã¡ãŒã䜿çšããããšã¯ç¯çœªã«çžåœããããšãæãåºããŠãã ããã
æ°Žæ³³ãå§ãã
ãã£ããã£ãéå§ããã«ã¯ããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãéžæããŠ[éå§]ãã¯ãªãã¯ããŸãã
ãã®åŸããã£ããã£ããã»ã¹ãéå§ãããå°çãããã±ããããªã¢ã«ã¿ã€ã ã§è¡šç€ºãããŸãã
ããã±ãŒãžã®ç¢ºèªããã³èª¿æ»ã®éçšã§ãåã®ããã±ãŒãžã«æ»ãå¿ èŠãããå ŽåããããŸãã ããã«ã¯2ã€ã®ãã¿ã³ããããŸãïŒã¹ã¯ãªãŒã³ã·ã§ãããåç §ïŒã
ãããŠããããã«ç¶ããã¿ã³ã䜿çšãããšããã®çªå·ãæå®ããŠããã±ãŒãžã«ãã°ãããžã£ã³ãã§ããŸãã
åãéãªãåã£ãŠäºãã«ã¯ããŒã«ããå Žåããã®ãããªåãå³ã¯ãªãã¯ããŠ[åã®ãµã€ãºå€æŽ ]ãéžæã§ããŸãã
çŸåšã®ç¶æ³ã«åãããŠãµã€ãºãèªåçã«èª¿æŽãããŸãã
ããã«ã ããã¹ãŠã®åã®ãµã€ãºãå€æŽããã¿ã³ãããããã¹ãŠã®åãæŽçããŸãã
ããšãã°ã [衚瀺]-[æéè¡šç€ºåœ¢åŒ ]ã¡ãã¥ãŒã䜿çšãããšããã£ããã£ã®éå§ããã§ã¯ãªãã以åã®ãã±ãããåä¿¡ããç¬éããã®æéãèšå®ã§ããŸãïŒ ä»¥åã®ãã£ããã£ãã±ãã以é ïŒã
åããã°ã©ã ã§æãéèŠãªãã®ïŒ ãã«ã-Wiresharkã«ã€ã㊠ïŒã¯ãäœæè ã®ããŒãžã§ã³ãšãªã¹ãã ãã§ãªãã ãã©ã«ããŒã¿ããå«ã¿ãŸãã ãã©ã«ããŒã¿ãã«ã¯ãæ§æã®ãããã£ã¬ã¯ããªã®å Žæã衚瀺ãããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã調ã¹ããšãããšãã°ãhttpãã±ãããéžæããŠãHTTPãTCPïŒãã©ã³ã¹ããŒãå±€ïŒã«ã«ãã»ã«åãããTCPãIPïŒãããã¯ãŒã¯å±€ïŒã«ã«ãã»ã«åãããIPãã€ãŒãµãããã«ã«ãã»ã«åãããããšãããããŸãïŒãã®åã«ã802.1Qããã©ãã·ã¥ããŸãïŒã
ãããŠæäžéšã«ã¯ããã¬ãŒã ã«ã€ããŠåéãããæ å ±ã®å°ããªæŠèŠã®ãããªãã®ããããŸãã
ãã£ã«ã¿ãŒã«ã€ããŠã¯åŸã»ã©èª¬æããŸããããã®æ®µéã§äžèŠãªããã±ãŒãžããã°ãããã£ã«ã¿ãŒã§é€å€ããå¿ èŠãããå Žåã¯ãããã±ãŒãžãå³ã¯ãªãã¯ããŠ[ ãã£ã«ã¿ãŒãšããŠé©çš-æªéžæ ]ã¡ãã¥ãŒãéžæãããšãå€æŽãããã«æå¹ã«ãªããŸãã
ä»ã®äœããåé€ããå¿ èŠãããå Žåã¯ã次ã«ãéžæãããŠããªãããéžæãããšãæ°ããã«ãŒã«ããã£ã«ã¿ãŒã«è¿œå ãããŸãã
ããªãåãé€ã
å€ãã®å ŽåãWiresharkã䜿çšããŠãããšãã«ã IPãã§ãã¯ãµã ãªãããŒããšã©ãŒãçºçããŸã-IPãã±ããããããŒãã§ãã¯ãµã ãšã©ãŒã
ææ°ã®ãããã¯ãŒã¯ã«ãŒãã¯éåžžã«ã¹ããŒãã§ããããããã§ãã¯ãµã ãèæ ®ããã®ã§ãTCP / IPã¹ã¿ãã¯ã¬ãã«ã§ããã°ã©ã ã§å®è¡ããã®ã¯é£ããå ŽåããããŸãã
ãŸããWiresharkã¯ãã±ããããããã¯ãŒã¯ã«å°éããåã«èªç¶ã«ååããŸãã
ãããŠããã®éé¡ãèšç®ãããããã±ãŒãžããããŒã«è¿œå ãããåã
ãããã£ãŠããã®åé¡ã解決ããã«ã¯2ã€ã®æ¹æ³ããããŸãããããã¯ãŒã¯ã«ãŒãèšå®ã§ãªãããŒãæ©èœãç¡å¹ã«ããããã¹ããã¡ãŒèšå®ã§æå®ããŠããã®å€ã«æ³šæãæããªãããã«ããŸãã
å€ãã®å Žåãäž»ã«åŠçé床ïŒéåžžã¯ããŒããŠã§ã¢ã§é«éïŒã«ãããããŒããŠã§ã¢æ©èœã¯ãœãããŠã§ã¢æ©èœãããåªããŠããå Žåãå€ããããã¹ããã¡ãŒèªäœã®èšå®ãå€æŽããããšããå§ãããŸãã
ãããè¡ãã«ã¯ãèšå®ïŒ[ ç·šé]-[èšå®] ïŒã«ç§»åãã[ãããã³ã«-IPv4]ã«ç§»åããŠã[ å¯èœã§ããã°IPv4ãã§ãã¯ãµã ãæ€èšŒãã]ãã©ã°ããªãã«ããŸãã
ãã©ãã£ãã¯ããã£ããã£ããåã«ãå®éã«ãã£ããã£ããå¿ èŠããããã®ã決å®ããå¿ èŠããããŸãã
ãã©ãã£ãã¯ã¢ãã©ã€ã¶ãŒãããã€ãã®å Žæã«é 眮ã§ããŸãã
- ãã¹ãäžã§ããŒã«ã«ã«;
- ã¹ã€ããã§ãã©ãã£ãã¯ãã©ãŒãªã³ã°ãæŽçããŸãã
- é¢å¿ã®ããå Žæã«çŽæ¥æ¥ç¶ããŸãã
- ãŸãã¯ARPãã€ãºãã³ã°ïŒãã©ãã£ãã¯ãååçã«ãªãã¹ã³ãããããããã«éæ³ïŒ
ã¹ããªãŒã ããã£ã«ã¿ãªã³ã°ãã
Wiresharkã«ã¯ããã£ããã£ïŒ ãã£ããã£ãã£ã«ã¿ ïŒãšè¡šç€ºïŒ ãã£ã¹ãã¬ã€ãã£ã«ã¿ ïŒã®2çš®é¡ã®ãã£ã«ã¿ãå«ãŸããŠããŸãã
ãŸãã ãã£ããã£ãã£ã«ã¿ãŒãæ€èšããŸãã
ååããæšæž¬ã§ããããã«ããã©ãã£ãã¯ãã£ããã£ã®æ®µéã§ããã£ã«ã¿ãªã³ã°ã«åœ¹ç«ã¡ãŸãã
ãã ãããã®å Žåãåœç¶ãå¿ èŠãªãã©ãã£ãã¯ã®äžéšãå®å šã«å€±ãå¯èœæ§ããããŸãã
ãã£ã«ã¿ãŒã¯ãå¿ èŠã«å¿ããŠè«çé¢æ°ïŒããã³ããŸãã¯ããã§ãªãïŒã§çµåã§ããçµã¿èŸŒã¿å€ã§æ§æãããåŒã§ãã
䜿çšããã«ã¯ã[ ãã£ãã㣠]ã¡ãã¥ãŒã[ ãªãã·ã§ã³ ]ã®é ã«ç§»åãã[ ãã£ããã£ãã£ã«ã¿]ãã£ãŒã«ãã«ãããšãã°ã ãã¹ã8.8.8.8 ïŒãŸãã¯ãããšãã°ã net 192.168.0.0./24 ïŒãšå ¥åããå¿ èŠããããŸãã
ãã¡ãããäºåã«äœæããããã£ã«ã¿ãŒãéžæããããšãã§ããŸãïŒCapture Filterãã¿ã³ããããæ åœããŸãïŒã
ãããã®ãªãã·ã§ã³ã§ããã€ã³ã¿ãŒãã§ã€ã¹ã®è¿ãã«ãã£ã«ã¿ãŒã衚瀺ãããŸããã¹ã¿ãŒããæŒãããšãã§ããŸãã
ããã§ã¯ã Display Filtersã«é²ã¿ãŸãããã
ãã§ã«ãã£ããã£ããããã©ãã£ãã¯ã®ã¿ããã£ã«ã¿ãªã³ã°ããŸãã
äœããã£ã«ã¿ãªã³ã°ã§ããŸããïŒ
-ã»ãšãã©ãã¹ãŠ-ãããã³ã«ãã¢ãã¬ã¹ããããã³ã«ã®ç¹å®ã®ãã£ãŒã«ãã
ãã£ã«ã¿ãŒã®äœæã«äœ¿çšã§ããæäœïŒ
ããŒã | äŸ¡å€ | 䜿çšäŸ |
---|---|---|
== | å¹³ç | ip.dst == 193.168.3.10 |
ïŒ= | çãããªã | udp.dstïŒ= 53 |
< | ããå°ãã | ip.ttl <24 |
> | ä»¥äž | frame.len> 10 |
<= | ããå°ãããçãã | frame.len <= 0x20 |
> = | ãã倧ãããçãã | tcp.analysis.bytes_in_flight> = 1000 |
äžèŽãã | æ£èŠè¡šçŸ | ãã¬ãŒã ã¯ã[Pp] [Aa] [Ss] [Ss]ããšäžèŽããŸã |
å«ã | å«ã | dns.resp.nameã«ã¯googleãå«ãŸããŠããŸã |
ãæ°ã¥ããããããŸããããè¡šãšããŠã¯ãäŸãšããŠããŸããŸãªè¡šçŸããããéåžžã«ç解ããããããã°ãã°èªåèªèº«ã§è©±ããŠããŸããã
ããšãã°ãip.dstã¯IPãããã³ã«ãã£ãŒã«ãã§ãã
ãã®ãã£ãŒã«ãã衚瀺ããã«ã¯ãããã±ãŒãžãèŠãã ãã§ããŠã£ã³ããŠã®äžéšã«ãã®å€ã衚瀺ãããä»»æã®ãã£ã«ã¿ãŒã«é©çšã§ããŸãã
ããšãã°ãTTLå€ããã§ãã¯ããããã£ã«ã¿ãŒãäœæããæ¹æ³ã«èå³ããããŸãã
ãããè¡ãã«ã¯ãL3ããŒããéãã察å¿ãããã£ãŒã«ãã«ç«ã£ãŠãã ããã
ãããŠããã£ã«ã¿ãäœæããã«ã¯ãip.ttlåŒã䜿çšããå¿ èŠãããããšãããããŸãã
ãã£ã«ã¿ãŒã®å ¥åãéå§ãããšããã€ã³ãã®åŸã«å¯èœãªå€ã®ãªã¹ããèªåçã«è¡šç€ºãããŸãã
ãã£ã«ã¿ãŒãé©çšããã«ã¯ãåã«EnterããŒãæŒããã[é©çš]ãã¿ã³ãã¯ãªãã¯ããŸãã
ãã£ã«ã¿å ¥åãã£ãŒã«ãèªäœã¯ãå ¥åå 容ã«å¿ããŠè²ãå€ããããšãã§ããŸãã
ç·ã¯ãã¹ãŠãæ£åžžã§ããããšã瀺ããŸãã èµ€-ãšã©ãŒãçºçããé»è²-ãã£ã«ã¿ãŒãèšè¿°ããããã®ä»ã®ãªãã·ã§ã³ããããããäºæããªãçµæãåŸãããŸããïŒããšãã°ã ip.dstïŒ= 8.8.8.8ãŸãã¯ïŒIp.dst == 8.8.8.8ãèšè¿°ã§ããŸãã2çªç®ã®ãªãã·ã§ã³ãããæãŸããïŒã
[ä¿å]ãã¿ã³ãã¯ãªãã¯ããŠãå°æ¥äœ¿çšããããã«ãã£ã«ã¿ãŒãä¿åããä»»æã®ååãå ¥åããŸãã
[OK]ãã¿ã³ãã¯ãªãã¯ãããšããã£ã«ã¿ãŒãããã«ã«ãã¿ã³ãšããŠè¡šç€ºãããŸãã
ãããŠãè¿ãã®[Expression ...]ãã¿ã³ãã¯ãªãã¯ãããšãããªã匷åãªåŒã³ã³ã¹ãã©ã¯ã¿ãŒãéããŸããããã«ãããã»ãšãã©ãããã¯ãŒã¯ãããã³ã«ãåŠç¿ã§ããŸãã ãµããŒãããããããã³ã«ã®æ°ã¯åžžã«å¢å ããŠããŸãã
åè¿°ã®ããã«ãä»»æã®ããã±ãŒãžãéžæããã³ã³ããã¹ãã¡ãã¥ãŒã§[ ãã£ã«ã¿ãŒãšããŠé©çš ]ãéžæãããµãã¡ãã¥ãŒã§ã¢ãŒããéžæãŸãã¯éžæããŸãããããã£ãŠã éžæãããã£ã«ã¿ãŒã®ã¿ã衚瀺ãããã£ã«ã¿ãŒãããã«è¡šç€ºãããŸãã
ãããã£ãŠãç»é¢ã«è¡šç€ºãããã®ãšããªããã®ãæè»ã«éžæã§ããŸãã
ããã¯ãç¹å®ã®IPã¢ãã¬ã¹ãTTLãããŒããDNSå¿çãªã©ã§ãã
ããã«ããã®ãããªã¯ã€ãã¯ãã£ã«ã¿ãŒã«ã¯ããã£ã«ã¿ãŒãšããŠæºåãããšãã£ã«ã¿ãŒãšããŠé©çšããã®2ã€ã®ãªãã·ã§ã³ããããŸãã
ååã瀺ãããã«ãæåã®ã±ãŒã¹ã§ã¯è¡šç€ºãã£ã«ã¿ãŒã®å ¥åãã£ãŒã«ãã«ã®ã¿è¡šç€ºãããŸãããé©çšãããŸããïŒããšãã°ããã®æ¹æ³ã§è€æ°ã®ãã£ã«ã¿ãŒãè¿œå ããããã«å®æããçµæãé©çšããå Žåã«äŸ¿å©ã§ãïŒã -ããã«é©çšããŸãã
ããŒã«ä»£æ°ã§ããªãã¿ã®è«çæŒç®ã䜿çšããŠããã£ã«ã¿ãŒãçµã¿åãããããšãã§ããŸãã
(dns) && (http)
è«ççããã³
(dns) || (http)
(dns) || (http)
ããã¯è«ççã§ãã
ãããã£ãŠã次ã®ãããªå€§ããè€éãªãã£ã«ã¿ãŒãäœæã§ããŸãã
(tcp.flags.syn==1) && (ip.src == 172.16.10.2) && (ip.dst == 172.16.10.1)
ããã§ã¯ãç¹å®ã®éä¿¡è ãšåä¿¡è ã®ã¢ãã¬ã¹ãæã€TCP SYNã»ã°ã¡ã³ãã®ã¿ãéžæãããŠããããšãããããŸãã 倧ããªãã£ã«ã¿ãŒãã³ã³ãã€ã«ããå Žåããã£ã«ã¿ãŒã¯æ¬è³ªçã«è«çåŒã§ãããtrueã®å Žåãããã±ãŒãžã¯ç»é¢ã«è¡šç€ºãããŸãïŒfalseã®å Žå-noïŒã
ããæ·±ãæœã
ããªãäžè¬çãªç¶æ³ã§ããããã¯ãŒã¯ã®åäœãé ããšããèŠæ ãããå Žåãããã«ã¯å€ãã®çç±ããããŸãã
äœãåå ã§ããããææ¡ãã2ã€ã®æ¹æ³ãèããŠã¿ãŸãããã
1ã€ã¯ã TCPãã«ã¿åãè¿œå ããããšã§ãã
ããã±ãŒãžãéãã ãã®TCPãã¬ãŒã ãã£ãŒã«ãã§åã®ãã¬ãŒã ããã®æéãèŠã€ããå³ã¯ãªãã¯ããŠ[ åãšããŠé©çš ]ãéžæããŸãã æ°ããåã衚瀺ãããŸãã
ãã®äžã§ãå³ã¯ãªãã¯ããŠãœãŒãã¢ãŒããéžæã§ããŸãïŒäŸïŒ éé ã§ãœãŒãïŒ ã
ãããŠããã«2çªç®ã®æ¹æ³ãæ€èšããŠãã ããã
æ¯èŒçæè¿ïŒããŒãžã§ã³1.10.0ïŒãtcp.time_deltaãã£ã«ã¿ãŒãç»å ŽããŸãããå®éã«ã¯ãæåŸã®ãªã¯ãšã¹ãããã®æéãèæ ®ããŠããŸãã
ã¯ã©ã€ã¢ã³ãã10ããªç§åŸã«èŠæ±ãè¡ããå¿çãåä¿¡ããã¯ã©ã€ã¢ã³ãããã¹ãŠã®åäœãé ããšèšã£ãå Žåãã¯ã©ã€ã¢ã³ãã«åé¡ãããå¯èœæ§ããããŸãã
ã¯ã©ã€ã¢ã³ãã2ã3ç§åŸã«èŠæ±ãè¡ããå¿çãåãåã£ãå Žåãããããåé¡ã¯ãããã¯ãŒã¯ã«ãããŸãã
ããã«æ·±ã
TCPãã±ããïŒãŸãã¯æ£ç¢ºã«èšããšã»ã°ã¡ã³ãïŒãèŠããšãéåžžã¯ãŒãããå§ãŸãStream indexãèŠãããšãã§ããŸãã
ãã£ãŒã«ãèªäœã¯tcp.streamãšåŒã°ããŸãã
ãããå³ã¯ãªãã¯ããŠãã£ã«ã¿ãŒãäœæã§ããŸãã
ãã®ããã«ããŠãç®çã®ååç©ããã£ã«ã¿ãªã³ã°ã§ããŸãã
å¥ã®æ¹æ³ã¯ãããã±ãŒãžèªäœãå³ã¯ãªãã¯ãã äŒè©±ãã£ã«ã¿ãŒãéžæããŠãããããl2 l3 l4ã¬ãã«ã®ãã£ã«ã¿ãŒãäœæããããšã§ãã
ãã®çµæã2ã€ã®ãã¹ãã®çžäºäœçšãåã³è¡šç€ºãããŸãã
3çªç®ã®ãªãã·ã§ã³ã¯ãæãèå³æ·±ãæ©èœã®1ã€ã§ãïŒ TCPã¹ããªãŒã ã«åŸãïŒ ã
å床䜿çšããã«ã¯ããã±ãããå³ã¯ãªãã¯ããŠ[ TCPã¹ããªãŒã ã«åŸã ]ãéžæããŸãã 2ã€ã®ããŒãéã®äº€æå šäœãæ確ã«ç€ºããããŠã£ã³ããŠã衚瀺ãããŸãã
[ çµ±èš-äŒè©± ]ã¡ãã¥ãŒã«ç§»åããããã¯ããŒã¯ãéžæãããšããã®ãããªãäŒè©±ãããã³ããŸããŸãªã»ãã·ã§ã³ã®çµ±èšã衚瀺ã§ããŸããããšãã°ã転éãããããŒã¿æ°ãªã©ãç°ãªãåã§äžŠã¹æ¿ããããšãã§ããŸãã
ãã®ãŠã£ã³ããŠã§ãã³ã³ããã¹ãã¡ãã¥ãŒãå³ã¯ãªãã¯ããŠããã£ã«ã¿ãŒãšããŠå床é©çšã§ããŸãã
æéãçµã€ã«ã€ããŠãçµéšãæ¥ã
ããŸããŸãªãã©ãã£ãã¯ã®ãã£ããã£ã«æéãè²»ãããåŸãå·Šäžé ã«ããçš®ã®çç¶ã®ãã¿ã³ã«æ°ä»ãããšããããŸãããããã§ãè²ãå€ããããšããããŸãã
ãã®ãã¿ã³ãã¯ãªãã¯ãããšã ãšãã¹ããŒãæ å ±ãŠã£ã³ããŠãéããŸãã
[ åæ-ãšãã¹ããŒãæ å ± ]ã¡ãã¥ãŒã«ç§»åããŠããåãçµæãåŸãããŸãã
ãã®ãŠã£ã³ããŠã«ã¯ãèŠã€ãã£ãããã±ãŒãžã«é¢ããæ å ±ãå«ãŸãããšã©ãŒãèŠåãã¡ã¢ããã£ããã®ã°ã«ãŒãã«åããããŸãã
ãããã®ã°ã«ãŒãã®ã«ã©ãŒãªã³ã°ã¯æ¬¡ã®ãšããã§ãã
ãšã©ãŒ-èµ€
èŠå-é»è²
ã¡ã¢-éç·ïŒã·ã¢ã³ïŒ
ãã£ãã-ã°ã¬ãŒ
Wiresharkã«ã¯åŒ·åãªã¢ãã©ã€ã¶ãŒãå«ãŸããŠããããããã¯ãŒã¯ã§çºçããå€æ°ã®åé¡ãèªåçã«æ€åºã§ããŸãã
ãæ°ã¥ããããããŸããããæåéããã£ã«ã¿ãŒãšãšãã¹ããŒãæ å ±ã䜿çšã§ãããã¹ãŠã®å Žæã¯äŸå€ã§ã¯ãããŸããã
ãã®ãããªãã£ã«ã¿ãŒãäœæããã«ã¯ã expert.severityã³ã³ã¹ãã©ã¯ãã䜿çšããå¿ èŠããããŸãã
ããšãã°ã expert.severity == error ã
ãããã©ãã£ãã¯ïŒ
Wiresharkã䜿çšããŠãããŠã³ããŒãããããã®ã確èªã§ããŸããïŒ
ã¯ããã§ããŸãã ãããŠä»ãç§ãã¡ã¯ãããèŠãã§ãããã
ãŸããHTTPãã©ãã£ãã¯ãååŸããŸãããã
HTTPããã±ãŒãžïŒ ãããã³ã«èšå®ïŒãå³ã¯ãªãã¯ããŠãWebãã©ãã£ãã¯ããã®ãã¡ã€ã«ã®æœåºã«çŽæ¥åœ±é¿ããå€ãã®ãªãã·ã§ã³ãèŠãŠã¿ãŸãããã
çŸåšã®ãã³ãããäœãæœåºã§ãããã確èªããã«ã¯ã [ãã¡ã€ã«]-[ãªããžã§ã¯ãã®ãšã¯ã¹ããŒã ] -[HTTP ]ã¡ãã¥ãŒã«ç§»åããŸãã
ãã£ããã£ããããã¹ãŠã®httpãªããžã§ã¯ãïŒããã¹ããã¡ã€ã«ãåçãªã©ïŒã瀺ããŠã£ã³ããŠã衚瀺ãããŸãã ãã®ãªã¹ããããã¡ã€ã«ãååŸããã«ã¯ããã¡ã€ã«ãéžæããŠ[ååãä»ããŠä¿å]ãã¯ãªãã¯ããŸãã
ã芧ã®ãšãããå³é¢ã¯åé¡ãªãåé€ãããŸããã
åæ§ã«ãã¹ããªãŒãã³ã°ãããª/ãªãŒãã£ãªãæœåºã§ããŸãã
ããããWiresharkã®å¯èœæ§ã¯ããã ãã§ã¯ãããŸããïŒ
圌ã¯ãFTPãããã³ã«ãããã¡ã€ã«ããã«ããæ¹æ³ãç¥ã£ãŠããŸãã
ãããè¡ãã«ã¯ãããªãã¿ã®Follow TCP Streamã䜿çšã§ããŸãã
ãã®çµæãFTPãä»ãã亀æã®ã¿ã衚瀺ãããŸãããã®å ŽåãRETRè¡ãèŠã€ããå¿ èŠããããå®éã«ã¯ãã¡ã€ã«è»¢éãæå³ããŸãã
次ã«ãããã«äžã«ç§»åãããã¡ã€ã«ïŒFTP-DATAïŒã§ããã±ãŒãžãçŽæ¥èŠã€ããå床TCPã¹ããªãŒã ã«åŸããéžæãããã¡ã€ã«ã®å 容ã確èªããŠã[ååãä»ããŠä¿å]ãã¯ãªãã¯ããŠä¿åããŸãã
VoIP
Wiresharkã«ã¯ããã®æè¡ã§åäœããããã€ãã®çµã¿èŸŒã¿æ©èœããããŸãã
SIPãSDPãRTSPãH.323ãRTCPãSRTPãªã©ãå€ãã®é³å£°ãããã³ã«ããµããŒãããŠããŸãã
ãããŠããã¡ãããããã«èãããã«é³å£°ãã©ãã£ãã¯ãååããŠä¿åããããšãã§ããŸãã
ãã®æ©èœã¯ãVoice over IPãããã¯ãŒã¯ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«æé©ã§ãã
[ çµ±èš-ãããŒã°ã©ã ]ã¡ãã¥ãŒã«ã¯ããã±ãã亀æå šäœãã©ã®ããã«è¡ãããããèŠèŠçã«è¡šç€ºãããŸãã
äžè¬ã«ã ãã¬ãã©ããŒã¡ãã¥ãŒå šäœã¯ãé³å£°ãã©ãã£ãã¯ãåŠçããããã«äºçŽãããŠããŸãã
ããšãã°ã Telephony-RTP-Show All Streamsã¯ãRTPã§çºçããããšãç¹ã«ãžãã¿ãŒïŒé³å£°ã§ããããæãéèŠãªãã©ã¡ãŒã¿ãŒïŒã詳现ã«è¡šç€ºããåé¡ã®ååšãããã«ç€ºããŸãã
[åæ]ãã¿ã³ãã¯ãªãã¯ãããšã RTPã¹ããªãŒã åæãŠã£ã³ããŠãéãããšãã§ããŸããããã§ã¹ããªãŒã ãéžæãããšããã¬ãŒã€ãŒãã¿ã³ã䜿çšããŠåçããããšãã§ããŸãã
ãŸãããã¬ãŒã€ãŒãŠã£ã³ããŠãéããŸãããã®ãŠã£ã³ããŠã§ã¯ããŸãé©åãªãžãã¿ãŒå€ãèšå®ãããã³ãŒããã¿ã³ã䜿çšããå¿ èŠããããŸãã
ã¹ãã¯ãã«ã¢ãã©ã€ã¶ãŒã«äŒŒããã®ã衚瀺ãããç®çã®äŒè©±ãããŒã¯ã§ããŸãããã®åŸã[åç]ãã¿ã³ãã¢ã¯ãã£ãã«ãªããŸãã
é³å£°é話ãèãå¥ã®æ¹æ³ããããŸã-ãã¬ãã©ããŒã¡ãã¥ãŒã«ç§»åã§ããŸã-VoIPé話 ã
ãŠã£ã³ããŠãéããåŒã³åºãã®ãªã¹ãã衚瀺ãããŸããããã§åã³ãã¬ãŒã€ãŒãã¿ã³ãæŒãããã©ã°ã䜿çšããŠå¿ èŠãªäŒè©±ããã£ã³ã»ã«ããåçãæŒããŸãã
蚱容ã§ããé³è³ªãå®çŸããã«ã¯ããžãã¿ãããã¡ãã£ãŒã«ãã®å€ãå€æŽããŠåçããå¿ èŠããããŸãã
äœè«
ãã°ããåã«ã CloudShark.orgãšãããµã€ããç»å ŽããŸããã
ããã¯åãWiresharkã¹ããã¡ãŒã§ããããªã³ã©ã€ã³ãµãŒãã¹ãšããŠå®è£ ãããŠããŸãã ãã®å©ããåããŠãããã¯ãŒã¯ãã©ãã£ãã¯ããã£ããã£ããããšã¯äžå¯èœã§ããããšã¯æããã§ããããã©ãã£ãã¯ãã³ãåæãå®è¡ããããšã¯éåžžã«å¯èœã§ãã ãã©ãŒã ãä»ããŠåæã®ããã«PCAPãã¡ã€ã«ãã¢ããããŒãããããšã«ããããããã³ã«ã«å¿ããŠãã¹ãŠã®ããŒã¿ãç解å¯èœãªãã£ãŒã«ãã«åå²ããããã±ããã®æ確ãªã·ãŒã±ã³ã¹ãååŸã§ããŸãã äžè¬ã«ãåãWiresharkã§ãããå°ã軜éã§ãã©ã®ãã©ãŠã¶ããã§ãã¢ã¯ã»ã¹ã§ããŸãã
æçµæ±ºæŠ
æåŸã«ãããŒãã¹ãã£ã³ãã©ã®ããã«èŠããããæ€èšããŸãã
ãã³ããèŠããšãæåã«ARPèŠæ±ããããã¹ãã£ã³ãçŽæ¥éå§ãããããšãããããŸãã ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ã¯192.168.10.11ã§ãã¹ãã£ã³ã¯ã¢ãã¬ã¹192.168.10.101ããè¡ãããŸã
ããã¯ãSYNãã±ãããæå®ãããããŒãç¯å²ã«éããããšãã®ããããSYNã¹ãã£ã³ã§ãã ã»ãšãã©ã®ããŒããéããããŠãããããã«ãŒã¿ãŒã¯RSTãACKãã±ããã§å¿çããŸãã
å°ãäžã«ã¹ã¯ããŒã«ãããšãtelnetãéããŠããããšãããããŸãïŒtcp 23ïŒã
ããã¯ãã«ãŒã¿ãŒãSYNãACKãã±ããã§å¿çãããšããäºå®ã«ãã£ãŠç€ºãããŸãã
ãšããã§ãã¹ããã¡ãŒã§ããŒãããã£ã«ã¿ãŒããã«ã¯ãtcp.srcportãtcp.dstportãããã³tcp.portã®åœ¢åŒã®æ§æã䜿çšã§ããŸãã UDPã®å Žåããã¹ãŠåãã§ã-udp.srcportãudp.dstportãudp.portã
ãŸãšã
æé©ãªãã±ããã¢ãã©ã€ã¶ãŒã®æ©èœã®æãåºæ¬çãªéšåã調ã¹ãŸããã
ãããããç§ã¯ã§ããéãå€ãã®æ©èœã«è§ŠããéèŠãªãã®ãèŠéããªãããã«ãããã£ããããããé¢åã§ããã
ãããã¬ãŒããã³éã¢ã»ã³ãã©ãŒãšããŠã®ãã±ããã¢ãã©ã€ã¶ãŒã¯ããããã¯ãŒã¯ããã³ãããã¯ãŒã¯ãããã³ã«ã®æå°ã®è©³çŽ°ã瀺ãããšãå€æããŸããã
Wiresharkã䜿çšããå¿ èŠãªç¥èïŒlinkmeup.ruãµã€ãã§æå°èŠæš¡ã®ãããã¯ãŒã¯ã·ãªãŒãºã調ã¹ãããšã§åéã§ããŸãïŒãååŸãããšããããã¯ãŒã¯ã§çºçããããŸããŸãªåé¡ãéåžžã«å¹æçã«èŠã€ããŠèšºæã§ããŸãã
å·çããã»ã¹ã§ã¯ã wiki.wireshark.orgã®è³æã䜿çšããŸãã
ãã©ãã£ãã¯ãã³ãã¯ããŸããŸãªãœãŒã¹ããååŸãããŸãããã»ãšãã©ã®å Žåã packetlife.netããååŸãããŸãã