·抓包tcp
tcpdump -i eth0 -s 0 -w file.pcapawk
·讀取抓包文件file
tcpdump -r file.pcapim
·ASCII讀取抓包文件sort
tcpdump -A -r file.pcapimg
·16進制讀取文件文件
tcpdump -x -r file.pcap
·篩選
tcpdump -n -r file.pcap | awk'{print $3}' | sort -u
tcpdump -n src host 192.168.1.103 -r file.pcap
tcpdump -n dst host 192.168.1.103 -r file.pcap
tcpdump -n port 80 -r file.pcap