{"id":1112,"date":"2020-10-02T11:18:33","date_gmt":"2020-10-02T02:18:33","guid":{"rendered":"https:\/\/tippang.com\/?p=1112"},"modified":"2020-10-02T11:26:27","modified_gmt":"2020-10-02T02:26:27","slug":"%ec%99%80%ec%9d%b4%ec%96%b4%ec%83%a4%ed%81%ac-wireshark","status":"publish","type":"post","link":"https:\/\/tippang.com\/?p=1112","title":{"rendered":"\ub124\ud2b8\uc6cc\ud06c \ud328\ud0b7 \ubd84\uc11d \ud234 \uc640\uc774\uc5b4\uc0e4\ud06c (Wireshark)"},"content":{"rendered":"\r\n<p>\uc624\ud508 \uc18c\uc2a4 \ud328\ud0b7 \ubd84\uc11d \ud504\ub85c\uadf8\ub7a8\uc73c\ub85c &#8220;pcap&#8221;\uc744 \uc774\uc6a9\ud558\uc5ec \ud328\ud0b7 \ubd84\uc11d, \ubb34\ucc28\ubcc4 \ubaa8\ub4dc(promiscuous mode)\ub97c \uc9c0\uc6d0, In\/Out\/Broadcast\/Multicast Traffic, pcap \ub77c\uc774\ube0c\ub7ec\ub9ac \uc774\uc6a9\u00a0<br \/><!--more--><\/p>\r\n<p><strong>\uc124\uce58<\/strong><br \/>\ub2e4\uc6b4\ub85c\ub4dc \ub9c1\ud06c : <a href=\"https:\/\/www.wireshark.org\/download.html\" target=\"_blank\" rel=\"noreferrer noopener\">Go<\/a><\/p>\r\n\r\n\r\n\r\n\r\n\r\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/t1.daumcdn.net\/cfile\/tistory\/9977D3355B0C098A33\" alt=\"\" \/><\/figure>\r\n\r\n\r\n\r\n\r\n\r\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/t1.daumcdn.net\/cfile\/tistory\/998FAB375B0C09AF02\" alt=\"\" \/><\/figure>\r\n\r\n\r\n\r\n\r\n\r\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/t1.daumcdn.net\/cfile\/tistory\/99698E4A5B0C09D00B\" alt=\"\" \/><\/figure>\r\n\r\n\r\n\r\n<p><strong>\uc124\uc815<\/strong><\/p>\r\n\r\n\r\n\r\n<p>\uc790\ub3d9\uc73c\ub85c \uc640\uc774\uc5b4\uc0e4\ud06c\uac00 \uc774\ub354\ub137 \uc778\ud130\ud398\uc774\uc2a4\ub97c \ucc3e\uc74c<\/p>\r\n\r\n\r\n\r\n<p>\ud574\ub2f9 \ubd80\ubd84 \ud074\ub9ad\ud558\uba74 \uc67c\ucabd \uc0c1\ub2e8\uc5d0 \uc0c1\uc5b4\uc9c0\ub290\ub7ec\ubbf8 \ubaa8\uc591\uc774 \ud65c\uc131\ud654, \ud574\ub2f9 \uc774\ub354\ub137 \uc778\ud130\ud398\uc774\uc2a4\uc5d0\uc11c in\/out packet \ud655\uc778<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li>No.\u00a0: \ud328\ud0b7\uc744 \uc218\uc9d1\ud55c \uc21c\uc11c<\/li>\r\n<li>Time : \ud328\ud0b7\uc774 \uc218\uc9d1\ub41c \uc2dc\uac04<\/li>\r\n<li>Source : \ud328\ud0b7\uc744 \ubcf4\ub0b8 \uc8fc\uc18c<\/li>\r\n<li>Destination : \ud328\ud0b7 \ub3c4\ucc29 \uc8fc\uc18c<\/li>\r\n<li>Protocol : \ud504\ub85c\ud1a0\ucf5c \uc815\ubcf4<\/li>\r\n<li>Length : \ud328\ud0b7\uc758 \uae38\uc774<\/li>\r\n<li>Info : \ud328\ud0b7 \uc815\ubcf4<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p>\uc5d0\ub7ec \uc2dc red, black \ud328\ud0b7 \ud655\uc778, \ub370\uc774\ud130 \uc804\uc1a1 \uc2dc \ud328\ud0b7 \uc804\ub2ec \uc218 \ud655\uc778<\/p>\r\n\r\n\r\n\r\n<p>1.\u00a0\ud328\ud0b7 \uc218\uc9d1 \uc2dc \ud544\ud130 \uc801\uc6a9 (\uc131\ub2a5\uc5d0 \uc601\ud5a5\uc744 \ub07c\uce60 \uc218 \uc788\uc74c) \ucea1\ucc98\ud544\ud130<br \/>2. \ud328\ud0b7 \uc804\uccb4\ub97c \uc218\uc9d1,\u00a0\ucd94\ud6c4 \ud544\ud130 \ubc29\ubc95(<strong><u>\uad8c\uc7a5<\/u><\/strong>, \ub2e4\uc591\uc5f0\uc0b0 \uac00\ub2a5) \ub514\uc2a4\ud50c\ub808\uc774\ud544\ud130<\/p>\r\n\r\n\r\n\r\n<p>&#8220;Apply a display filter&#8221; \ud544\ud130 \uc801\uc6a9, Analyze &gt; Display Filters&#8230; \uc5d0\uc11c \uc801\uc6a9\uac00\ub2a5.<\/p>\r\n\r\n\r\n\r\n<p>\uc608 : &#8220;ip.addr == 192.1.1.1&#8221; \uc774\ub77c\uace0 \uc801\uc6a9\ud558\uba74 source\ub4e0 destination\uc774\ub4e0 \uc544\uc774\ud53c\uac00 \ud574\ub2f9 \uc544\uc774\ud53c\uc778 \ud328\ud0b7 \ud655\uc778 \uac00\ub2a5<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li>eth.addr == 00:3f:1e:00:00:23 \/\/\ucd9c\ubc1c\uc9c0\ub098 \ubaa9\uc801\uc9c0 MAC \uc8fc\uc18c\ub85c \uac80\uc0c9<\/li>\r\n<li>ip.addr == 192.168.0.2 \/\/ \ucd9c\ubc1c\uc9c0\ub098 \ubaa9\uc801\uc9c0 IP\uc8fc\uc18c\ub85c \uac80\uc0c9<\/li>\r\n<li>tcp.port == 3306 \/\/ TCP \ucd9c\ubc1c\uc9c0\ub098 \ubaa9\uc801\uc9c0 \ud3ec\ud2b8 \ubc88\ud638\ub85c \uac80\uc0c9<\/li>\r\n<li>ip.src != 10.1.2.3 \/\/ \ucd9c\ubc1c\uc9c0 IP\uc8fc\uc18c\uac00 \ud574\ub2f9 IP\uc8fc\uc18c\uac00 \uc544\ub2cc\uac83 \uac80\uc0c9<\/li>\r\n<li>eth.dst == 00:3f:1e:00:00:23 \/\/ \ubaa9\uc801\uc9c0 MAC\uc8fc\uc18c \uac80\uc0c9<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p>\uc138\uc158\ubcc4\ub85c \uc870\ub9bd : Stream, TCP \ud1b5\uc2e0 \ud328\ud0b7\ub4e4\uc744 \uc870\ub9bd<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/t1.daumcdn.net\/cfile\/tistory\/999773415B0C135934\" alt=\"\" \/><\/figure>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/t1.daumcdn.net\/cfile\/tistory\/99ADAE335B0C145C0D\" alt=\"\" \/><\/figure>\r\n\r\n\r\n\r\n<p>\ucd9c\ucc98:\u00a0<a href=\"https:\/\/jeong-pro.tistory.com\/155\" target=\"_blank\" rel=\"noopener\">https:\/\/jeong-pro.tistory.com\/155<\/a>\u00a0[\uae30\ubcf8\uae30\ub97c \uc313\ub294 \uc815\uc544\ub9c8\ucd94\uc5b4 \ucf54\ub529\ube14\ub85c\uadf8]<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>\uc624\ud508 \uc18c\uc2a4 \ud328\ud0b7 \ubd84\uc11d \ud504\ub85c\uadf8\ub7a8\uc73c\ub85c &#8220;pcap&#8221;\uc744 \uc774\uc6a9\ud558\uc5ec \ud328\ud0b7 \ubd84\uc11d, \ubb34\ucc28\ubcc4 \ubaa8\ub4dc(promiscuous mode)\ub97c \uc9c0\uc6d0, In\/Out\/Broadcast\/Multicast Traffic, pcap \ub77c\uc774\ube0c\ub7ec\ub9ac \uc774\uc6a9\u00a0<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,16],"tags":[],"class_list":["post-1112","post","type-post","status-publish","format-standard","hentry","category-tech","category--others"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/tippang.com\/index.php?rest_route=\/wp\/v2\/posts\/1112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tippang.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tippang.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tippang.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tippang.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1112"}],"version-history":[{"count":4,"href":"https:\/\/tippang.com\/index.php?rest_route=\/wp\/v2\/posts\/1112\/revisions"}],"predecessor-version":[{"id":1118,"href":"https:\/\/tippang.com\/index.php?rest_route=\/wp\/v2\/posts\/1112\/revisions\/1118"}],"wp:attachment":[{"href":"https:\/\/tippang.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tippang.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1112"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tippang.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}