WireSharp语法过滤器

WireSharp语法过滤器

介绍语法
不管端口是来源还是目标tcp.port eq 80
过滤来源是某个ipip.src eq 192.168.60.122
过滤目标ipip.dst eq 192.168.1.107
不区分是源还是目标ip.dst eq 192.168.1.107
tcp的目标端口tcp.dstport == 80
端口范围过滤tcp.port >= 1 and tcp.port <= 80
过滤目标maceth.dst == A0:00:00:04:C5:84
过滤来源maceth.src eq A0:00:00:04:C5:84
等于eq
大于gt
大于等于ge
不等ne
包长过滤udp.length == 26
tcp包长度tcp.len >= 7
数据包长度frame.len == 119
http请求方式http.request.method == “GET”
http的urihttp.request.uri == “/img/logo-edu.gif”
get包http.request.method == “GET” && http contains "User-Agent: "
post包http.request.method == “POST” && http contains "User-Agent: "
响应包http contains “HTTP/1.1 200 OK” && http contains "Content-Type: "
posted @ 2022-04-03 23:08  飞航之梦  阅读(23)  评论(0)    收藏  举报