????10:59:46????????????????

????728425?????????

????arp?????????????? ARP ????

????who-has 192.168.1.1 tell 192.168.1.110????? 110 ???? 1 ?? MAC ???

?????? ???????“9.185.10.57”???????????????????

tcpdump host 9.185.10.57

?????? ?????????“9.185.10.57”??????“9.185.10.58”??“9.185.10.59”???????????

tcpdump host 9.185.10.57 and >(9.185.10.58 or 9.185.10.59)

?????? ???????“9.185.10.57”???????“9.186.10.58”?????????????????????IP?????

tcpdump ip host 9.185.10.57 and ! 9.185.10.58

?????? ???????“9.185.10.57”?????????FTP???????21???????

tcpdump tcp port 21 host 9.185.10.57

?????? ????????????????DoS????????????????????????????ICMP?????????????д?????ping?????????

tcpdump icmp -n -i eth0

?????? Ethereal

?????? ????????

????***????? libpcap ????????****

# cp ethereal-0.9.9.tar.bz2 /usr/local/src/
# cd /usr/local/src/
# bzip2 -d ethereal-0.9.9.tar.bz2
# tar xvf ethereal-0.9.9.tar
# cd ethereal-0.9.9
# ./configure
# make
# make install

?????? ??????????

????????? 2 ????

?????? ??? "filter":??????????????????????????????????磺

????Filter name:Rocky

????Filter string: host 124.127.185.106