• IP src and dst
    • ip.src==
    • ip.dst==
  • IPv6 RA message
    • icmpv6.type==134
  • IPv6 RS message
    • icmpv6.type==133
  • DHCP packet
    • udp.port eq67 || udp.port eq 68
    • bootp
    • dhcpv6
  • Samba service
    • smb
  • DHCP relay
    • bootp.hw.mac_addr == 00:90:00:00:06:01
  • http method
    • http.request.method==post
  • filter ipv6 packets
    • not.ip.version==6
  • ICMP v6
    • icmpv6.type=128 ping request
    • icmpv6.type=129 ping reply
  • IPv6 PMD
    • ipv6.fragment.offset(Fragmentation packets)
  • Filter unnecessary packets
    • !(arp or dns or icmp)
  • Troubleshoot tcp session
    • tcp.analysis.flags
    • tcp.flags == 0x0002           <=syn
    • tcp.flags == 0x0012           <=syn.ack
  • Search content key word
    • tcp contains facebook
    • udp contains facebook
創作者介紹
創作者 Cooldy's notebook 的頭像
cooldia

Cooldy's notebook

cooldia 發表在 痞客邦 留言(0) 人氣( 62 )