资源描述:
《wiresharkdhcpdns抓包分析》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、DHCP&DNSANALYSISUsingWireSharkforDHCPcaptureandDNScapture0921282109B04asdfghjkl09212821DHCP&DNSANALYSISlTheconfigurationoftheWireSharkTheWireSharkinterfaceinLinuxisasabove.Thecaptureisdoneinthelab,inancaféhouseaswellasinthedorm.Theconnectiontocafeiswirelessconnection,inthelabthelaptopisa
2、llocatedtoapublicIPaddressandindorm,whereitiswiredconnection,thelaptopisallocatedtoaprivateIPaddress,whiletherouter’sIPis192.168.1.1.Whilewithwiredconnection,theinterfaceselectediseth0,withwirelessconnection,theinterfaceselectediseth2.asdfghjkl09212821DHCP&DNSANALYSISWhencapturingDHCPpack
3、et,theconfigurationofcaptureisasfollows:asdfghjkl09212821DHCP&DNSANALYSISWhencapturingDNSmessage,theconfigurationisasfollows:lTheprocedureofcaptureClickonthethirdbuttontoWhilecapturing,clickthethirdstartcapture.buttontostop.lDHCPanalysisAfterinputandincmd,,Releasethelinkandrebuildthelinku
4、singDHCPprotocol.asdfghjkl09212821DHCP&DNSANALYSISThefivemessagesthattheWiresharkpackedarerelease,discover,offer,requestandACK.Itcanbeinferredfromthepictureabovethatthesourceportnumberis68andthedestinationportnumberis67.AndthedestinationisaDHCPserveraswellasarouter.Theserver’sIPaddressis1
5、92.168.1.1(whichisaprivateIPaddressusedbyarouter)andthehost’sIPaddressis192.168.1.100(whichisalsoaprivateIPaddress).1.DiscovermessageTheclientbroadcastsmessagesonthephysicalsubnettodiscoveravailableDHCPservers.NetworkadministratorscanconfigurealocalroutertoforwardDHCPpacketstoaDHCPserverf
6、romadifferentsubnet.Thisclient-implementationcreatesaUserDatagramProtocol(UDP)packetwiththebroadcastdestinationof255.255.255.255orthespecificsubnetbroadcastaddress.asdfghjkl09212821DHCP&DNSANALYSISfieldvaluemeaning1.Messagetype01fromhosttoserver2.TransactionIDanintegerForclienttomatchresp
7、onse3.ClientIP0.0.0.0OnlyfieldiftheclientisBOUND,asdfghjkl09212821DHCP&DNSANALYSISaddressREVEW,orREBIND,soit’sall0.1.YourIPaddress0.0.0.0TheclientiswaitingtobeassignedforanIPaddress,sothisisall0.2.NextserverIPaddress0.0.0.0Theserver’sIPaddressisunknown.3.t=53DHCPtyp