<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Complexity is the enemy of Security &#187; tcpdump</title>
	<atom:link href="http://blog.lifeoverip.net/tag/tcpdump/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.lifeoverip.net</link>
	<description>Life (Over) IP,</description>
	<lastBuildDate>Wed, 08 Sep 2010 11:00:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Tcpdump ile Trafik Analizi</title>
		<link>http://blog.lifeoverip.net/2010/04/14/tcpdump-ile-trafik-analizi/</link>
		<comments>http://blog.lifeoverip.net/2010/04/14/tcpdump-ile-trafik-analizi/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 11:16:57 +0000</pubDate>
		<dc:creator>Huzeyfe ONAL</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Network Tools]]></category>
		<category><![CDATA[Sniffer]]></category>
		<category><![CDATA[tcpdump]]></category>

		<guid isPermaLink="false">http://blog.lifeoverip.net/?p=2216</guid>
		<description><![CDATA[İlk sürümünü 2006 yılında hazırladığım &#8220;Tcpdump ile Trafik Analizi&#8221; konulu belgenin yeni sürümü http://www.guvenlikegitimleri.com/calismalar/tcpdump1.pdf adresine eklenmiştir. Yeni sürümde  içeriği genişleterek üç bölüm haline getirdik. Diğer bölümleri de zaman buldukca internete aktaracağım. Share and Enjoy: Related posts:Sifreli Trafik analizi icin IDS Tasarimi Kaydedilmis trafik uzerinde anonimlestirme Thsark ile TCP/IP Paket Analizi


Related posts:<ol><li><a href='http://blog.lifeoverip.net/2007/06/21/sifreli-trafigi-analiz-icin-ids-tasarimi/' rel='bookmark' title='Permanent Link: Sifreli Trafik analizi icin IDS Tasarimi'>Sifreli Trafik analizi icin IDS Tasarimi</a></li>
<li><a href='http://blog.lifeoverip.net/2007/10/15/kaydedilmis-trafik-uzerinde-anonimlestirme/' rel='bookmark' title='Permanent Link: Kaydedilmis trafik uzerinde anonimlestirme'>Kaydedilmis trafik uzerinde anonimlestirme</a></li>
<li><a href='http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/' rel='bookmark' title='Permanent Link: Thsark ile TCP/IP Paket Analizi'>Thsark ile TCP/IP Paket Analizi</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>İlk sürümünü 2006 yılında hazırladığım &#8220;Tcpdump ile Trafik Analizi&#8221; konulu belgenin yeni sürümü <a href="http://www.guvenlikegitimleri.com/calismalar/tcpdump1.pdf">http://www.guvenlikegitimleri.com/calismalar/tcpdump1.pdf</a> adresine eklenmiştir. Yeni sürümde  içeriği genişleterek üç bölüm haline getirdik. Diğer bölümleri de zaman buldukca internete aktaracağım.</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;partner=sociable" title="Print"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;title=Tcpdump%20ile%20Trafik%20Analizi&amp;bodytext=%C4%B0lk%20s%C3%BCr%C3%BCm%C3%BCn%C3%BC%202006%20y%C4%B1l%C4%B1nda%20haz%C4%B1rlad%C4%B1%C4%9F%C4%B1m%20%22Tcpdump%20ile%20Trafik%20Analizi%22%20konulu%20belgenin%20yeni%20s%C3%BCr%C3%BCm%C3%BC%20http%3A%2F%2Fwww.guvenlikegitimleri.com%2Fcalismalar%2Ftcpdump1.pdf%C2%A0adresine%20eklenmi%C5%9Ftir.%20Yeni%20s%C3%BCr%C3%BCmde%C2%A0%20i%C3%A7eri%C4%9Fi%20geni%C5%9Fleterek%C2%A0%C3%BC%C3%A7%20b%C3%B6l%C3%BCm%20hal" title="Digg"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F" title="Sphinn"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/sphinn.png" title="Sphinn" alt="Sphinn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;title=Tcpdump%20ile%20Trafik%20Analizi&amp;notes=%C4%B0lk%20s%C3%BCr%C3%BCm%C3%BCn%C3%BC%202006%20y%C4%B1l%C4%B1nda%20haz%C4%B1rlad%C4%B1%C4%9F%C4%B1m%20%22Tcpdump%20ile%20Trafik%20Analizi%22%20konulu%20belgenin%20yeni%20s%C3%BCr%C3%BCm%C3%BC%20http%3A%2F%2Fwww.guvenlikegitimleri.com%2Fcalismalar%2Ftcpdump1.pdf%C2%A0adresine%20eklenmi%C5%9Ftir.%20Yeni%20s%C3%BCr%C3%BCmde%C2%A0%20i%C3%A7eri%C4%9Fi%20geni%C5%9Fleterek%C2%A0%C3%BC%C3%A7%20b%C3%B6l%C3%BCm%20hal" title="del.icio.us"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;t=Tcpdump%20ile%20Trafik%20Analizi" title="Facebook"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;title=Tcpdump%20ile%20Trafik%20Analizi" title="Mixx"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;title=Tcpdump%20ile%20Trafik%20Analizi&amp;annotation=%C4%B0lk%20s%C3%BCr%C3%BCm%C3%BCn%C3%BC%202006%20y%C4%B1l%C4%B1nda%20haz%C4%B1rlad%C4%B1%C4%9F%C4%B1m%20%22Tcpdump%20ile%20Trafik%20Analizi%22%20konulu%20belgenin%20yeni%20s%C3%BCr%C3%BCm%C3%BC%20http%3A%2F%2Fwww.guvenlikegitimleri.com%2Fcalismalar%2Ftcpdump1.pdf%C2%A0adresine%20eklenmi%C5%9Ftir.%20Yeni%20s%C3%BCr%C3%BCmde%C2%A0%20i%C3%A7eri%C4%9Fi%20geni%C5%9Fleterek%C2%A0%C3%BC%C3%A7%20b%C3%B6l%C3%BCm%20hal" title="Google Bookmarks"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F&amp;title=Tcpdump%20ile%20Trafik%20Analizi" title="StumbleUpon"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F" title="Technorati"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Tcpdump%20ile%20Trafik%20Analizi%20-%20http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F04%2F14%2Ftcpdump-ile-trafik-analizi%2F" title="Twitter"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>

<p>Related posts:<ol><li><a href='http://blog.lifeoverip.net/2007/06/21/sifreli-trafigi-analiz-icin-ids-tasarimi/' rel='bookmark' title='Permanent Link: Sifreli Trafik analizi icin IDS Tasarimi'>Sifreli Trafik analizi icin IDS Tasarimi</a></li>
<li><a href='http://blog.lifeoverip.net/2007/10/15/kaydedilmis-trafik-uzerinde-anonimlestirme/' rel='bookmark' title='Permanent Link: Kaydedilmis trafik uzerinde anonimlestirme'>Kaydedilmis trafik uzerinde anonimlestirme</a></li>
<li><a href='http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/' rel='bookmark' title='Permanent Link: Thsark ile TCP/IP Paket Analizi'>Thsark ile TCP/IP Paket Analizi</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.lifeoverip.net/2010/04/14/tcpdump-ile-trafik-analizi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DDOS analizinde tcpdump kullanımı</title>
		<link>http://blog.lifeoverip.net/2010/03/23/ddos-analizinde-tcpdump-kullanimi/</link>
		<comments>http://blog.lifeoverip.net/2010/03/23/ddos-analizinde-tcpdump-kullanimi/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 20:28:34 +0000</pubDate>
		<dc:creator>Huzeyfe ONAL</dc:creator>
				<category><![CDATA[Misc]]></category>
		<category><![CDATA[ddos analiz]]></category>
		<category><![CDATA[tcpdump]]></category>

		<guid isPermaLink="false">http://blog.lifeoverip.net/?p=2136</guid>
		<description><![CDATA[Bu aralar nedense DOS saldırılarında ciddi bir artış var. 2010 yılında daha önceki hayatımda karşılaşmadığım kadar DOS/DDOS olayıyla karşılaştım. Bunların çoğu ciddi(50-100 Mb ile yapılan) saldırılar olmasa da hedef sistemleri aşağı indirmeyi başarmış saldırılar.  Yaşanan saldırı sonrası genelde analiz kısmı bana kaldığı için ben de oturup analiz aşamasında ne yaptığımı kısa kısa anlatayım dedim. Analiz kısmında [...]


Related posts:<ol><li><a href='http://blog.lifeoverip.net/2007/04/30/tcpdump-ile-pasif-isletim-sistemi-saptama/' rel='bookmark' title='Permanent Link: tcpdump ile pasif isletim sistemi saptama'>tcpdump ile pasif isletim sistemi saptama</a></li>
<li><a href='http://blog.lifeoverip.net/2009/01/06/tcpdump-tshark-ile-cdp-paketleri/' rel='bookmark' title='Permanent Link: tcpdump &amp; tshark ile CDP paketleri'>tcpdump &amp; tshark ile CDP paketleri</a></li>
<li><a href='http://blog.lifeoverip.net/2008/01/10/tcpdumpi-saldiri-tespit-sistemi-olarak-kullanma/' rel='bookmark' title='Permanent Link: tcpdump&#8217;i saldiri tespit sistemi olarak kullanma'>tcpdump&#8217;i saldiri tespit sistemi olarak kullanma</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Bu aralar nedense DOS saldırılarında ciddi bir artış var. 2010 yılında daha önceki hayatımda karşılaşmadığım kadar DOS/DDOS olayıyla karşılaştım. Bunların çoğu ciddi(50-100 Mb ile yapılan) saldırılar olmasa da hedef sistemleri aşağı indirmeyi başarmış saldırılar.  Yaşanan saldırı sonrası genelde analiz kısmı bana kaldığı için ben de oturup analiz aşamasında ne yaptığımı kısa kısa anlatayım dedim.</p>
<p>Analiz kısmında genellikle elimde pcap formatında 3-4GB veri oluyor. bunu saldırı anında span portuna bağlı bir snifferdan almak zorunda kalıyoruz ya da destekliyorsa IPS/Firewall üzerinden. Denizde kum bizde paket misali pcap dosyasının içine dalıp yapılan saldırıyla ilgili ipucu aramaya çalışıyorum.</p>
<p>İlk olarak baktığım klasik flood saldırıları mı yapılmış, hangi ip adreslerinden yapılmış , spoof ip mi kullanılmış yoksa gerçek ipler mi gibi konular. Birşey bulamazsam tcpreplay ile oynatıp Snort imzalarından geçirerek acaba klasik bir araç, yöntem mi kullanılmış bakıyorum ama çoğunlukla bu kadar uğraşmaya gerek kalmadan tcpdump (+cat ,grep , sort, uniq, awk vs)kullanarak analiz raporunu yazabiliyorum. Tcpdump kullanırken de bilinen parametlerinin yanında bu tip saldırılar için faydalı olacak bazı detay parametreler kullanıyorum(tcp flag lerine göre paket gösterme gibi)<span id="more-2136"></span></p>
<p><strong>Sadece SYN bayraklı paketleri yakalama</strong></p>
<p><strong># tcpdump -i bce1 -n &#8216;tcp[tcpflags] &amp; tcp-syn == tcp-syn&#8217;<br />
</strong>tcpdump: verbose output suppressed, use -v or -vv for full protocol decode<br />
listening on bce1, link-type EN10MB (Ethernet), capture size 96 bytes<br />
22:04:22.809998 IP 91.3.119.80.59204 &gt; 19.17.39.40.53: Flags [S], seq 2861145144, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:22.863997 IP 91.3.119.80.59135 &gt; 82.8.86.175.25: Flags [S], seq 539301671, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:22.864007 IP 91.3.119.80.59205 &gt; 19.17.39.40.53: Flags [S], seq 4202405882, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:23.033997 IP 91.3.119.80.64170 &gt; 19.17.39.40.53: Flags [S], seq 1040357906, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:23.146001 IP 91.3.119.80.59170 &gt; 19.17.39.40.53: Flags [S], seq 3560482792, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:23.164997 IP 91.3.119.80.59171 &gt; 20.17.222.88.25: Flags [S], seq 1663706635, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:23.384994 IP 91.3.119.80.59136 &gt; 19.17.39.40.53: Flags [S], seq 192522881, win 65535, options [mss 1460,sackOK,eol], length 0<br />
22:04:23.432994 IP 91.3.119.80.59137 &gt; 19.17.39.40.53: Flags [S], seq 914731000, win 65535, options [mss 1460,sackOK,eol], length 0</p>
<p>ya da aynı işi yapan &#8216;tcp[13] &amp; 2 != 0&#8242; parametresini kullanabilirsiniz. Buradan çıkacak milyonlarca satırı bir dosyaya yazdırıp kaynak ip ve hedef ip adreslerine göre sıralatıyorum. Sonrasonda uniq komutu ile hangi hedef ne kadar istek almış, hangi kaynak ne kadar paket göndermiş bilgileri çıkıyor. Bu da zaten genelde saldırı için büyük bir ipucu sağlıyor. Sonrasında ilgili ip adresleri üzerinde detay işlemlere başlıyorum.</p>
<p>Eğer saldırı klasik syn flood değilse alternatif flagleri deneyerek benzer sonuçları elde edebilirsiniz.</p>
<p><strong>ACK bayraklı paketleri izlemek için</strong></p>
<p># tcpdump -i bce1 -n &#8216;tcp[13] &amp; 16 != 0&#8242;<br />
<strong>FIN bayraklı paketleri izlemek için</strong></p>
<p># tcpdump -i bce1 -n &#8216;tcp[13] &amp; 1 != 0&#8242; and tcp port 80<br />
<strong>SYN-ACK bayraklı paketleri izlemek için</strong></p>
<p># tcpdump -i bce1 -n &#8216;tcp[13] = 18&#8242;<br />
tcp[13] demek TCP başlığındaki 13. byte anlamına gelir. Bu da bayrakları temsil eden byte&#8217;dır. Her bayrak için verilecek değer aşağıdaki resimden alınabilir.</p>
<p><a href="http://blog.lifeoverip.net/wp-content/uploads/2010/03/bayrak1.jpg"><img class="alignleft size-full wp-image-2139" title="bayrak" src="http://blog.lifeoverip.net/wp-content/uploads/2010/03/bayrak1.jpg" alt="" width="662" height="61" /></a><a href="http://blog.lifeoverip.net/wp-content/uploads/2010/03/bayrak.jpg"></a></p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;partner=sociable" title="Print"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;title=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1&amp;bodytext=Bu%20aralar%20nedense%20DOS%20sald%C4%B1r%C4%B1lar%C4%B1nda%20ciddi%20bir%20art%C4%B1%C5%9F%20var.%202010%20y%C4%B1l%C4%B1nda%20daha%20%C3%B6nceki%20hayat%C4%B1mda%20kar%C5%9F%C4%B1la%C5%9Fmad%C4%B1%C4%9F%C4%B1m%20kadar%20DOS%2FDDOS%20olay%C4%B1yla%20kar%C5%9F%C4%B1la%C5%9Ft%C4%B1m.%20Bunlar%C4%B1n%20%C3%A7o%C4%9Fu%20ciddi%2850-100%20Mb%20ile%20yap%C4%B1lan%29%20sald%C4%B1r%C4%B1lar%20olmasa%20da%C2%A0hedef%20sisteml" title="Digg"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F" title="Sphinn"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/sphinn.png" title="Sphinn" alt="Sphinn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;title=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1&amp;notes=Bu%20aralar%20nedense%20DOS%20sald%C4%B1r%C4%B1lar%C4%B1nda%20ciddi%20bir%20art%C4%B1%C5%9F%20var.%202010%20y%C4%B1l%C4%B1nda%20daha%20%C3%B6nceki%20hayat%C4%B1mda%20kar%C5%9F%C4%B1la%C5%9Fmad%C4%B1%C4%9F%C4%B1m%20kadar%20DOS%2FDDOS%20olay%C4%B1yla%20kar%C5%9F%C4%B1la%C5%9Ft%C4%B1m.%20Bunlar%C4%B1n%20%C3%A7o%C4%9Fu%20ciddi%2850-100%20Mb%20ile%20yap%C4%B1lan%29%20sald%C4%B1r%C4%B1lar%20olmasa%20da%C2%A0hedef%20sisteml" title="del.icio.us"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;t=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1" title="Facebook"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;title=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1" title="Mixx"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;title=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1&amp;annotation=Bu%20aralar%20nedense%20DOS%20sald%C4%B1r%C4%B1lar%C4%B1nda%20ciddi%20bir%20art%C4%B1%C5%9F%20var.%202010%20y%C4%B1l%C4%B1nda%20daha%20%C3%B6nceki%20hayat%C4%B1mda%20kar%C5%9F%C4%B1la%C5%9Fmad%C4%B1%C4%9F%C4%B1m%20kadar%20DOS%2FDDOS%20olay%C4%B1yla%20kar%C5%9F%C4%B1la%C5%9Ft%C4%B1m.%20Bunlar%C4%B1n%20%C3%A7o%C4%9Fu%20ciddi%2850-100%20Mb%20ile%20yap%C4%B1lan%29%20sald%C4%B1r%C4%B1lar%20olmasa%20da%C2%A0hedef%20sisteml" title="Google Bookmarks"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F&amp;title=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1" title="StumbleUpon"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F" title="Technorati"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=DDOS%20analizinde%20tcpdump%20kullan%C4%B1m%C4%B1%20-%20http%3A%2F%2Fblog.lifeoverip.net%2F2010%2F03%2F23%2Fddos-analizinde-tcpdump-kullanimi%2F" title="Twitter"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>

<p>Related posts:<ol><li><a href='http://blog.lifeoverip.net/2007/04/30/tcpdump-ile-pasif-isletim-sistemi-saptama/' rel='bookmark' title='Permanent Link: tcpdump ile pasif isletim sistemi saptama'>tcpdump ile pasif isletim sistemi saptama</a></li>
<li><a href='http://blog.lifeoverip.net/2009/01/06/tcpdump-tshark-ile-cdp-paketleri/' rel='bookmark' title='Permanent Link: tcpdump &amp; tshark ile CDP paketleri'>tcpdump &amp; tshark ile CDP paketleri</a></li>
<li><a href='http://blog.lifeoverip.net/2008/01/10/tcpdumpi-saldiri-tespit-sistemi-olarak-kullanma/' rel='bookmark' title='Permanent Link: tcpdump&#8217;i saldiri tespit sistemi olarak kullanma'>tcpdump&#8217;i saldiri tespit sistemi olarak kullanma</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.lifeoverip.net/2010/03/23/ddos-analizinde-tcpdump-kullanimi/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Thsark ile TCP/IP Paket Analizi</title>
		<link>http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/</link>
		<comments>http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 12:34:59 +0000</pubDate>
		<dc:creator>Huzeyfe ONAL</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Network Tools]]></category>
		<category><![CDATA[Sniffer]]></category>
		<category><![CDATA[tcp/ip analys]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[tshark]]></category>

		<guid isPermaLink="false">http://blog.lifeoverip.net/?p=911</guid>
		<description><![CDATA[Tshark, güçlü bir ağ protokolleri analiz programıdır. Tshark komut satırından çalışır ve yine bir ag trafik analiz programı olan Wireshark&#8217;da bulunan  çoğu özelliği destekler. Komut satırından çalışan ve çok bilinen diğer bir trafik analiz aracı da tcpdump&#8217;dır. Tshark ile tcpdump&#8217;ın ayrıldığı en belirgin nokta Tshark&#8217;ın trafik analizinde protokolleri tanıyabilmesi ve bunları detaylı bir şekilde gösterebilmesidir. [...]


Related posts:<ol><li><a href='http://blog.lifeoverip.net/2009/09/13/paket-analizi-protokol-analizi-kavramlari/' rel='bookmark' title='Permanent Link: Paket analizi, protokol analizi kavramları'>Paket analizi, protokol analizi kavramları</a></li>
<li><a href='http://blog.lifeoverip.net/2009/06/06/l2-seviyesinde-paket-islemleriarping/' rel='bookmark' title='Permanent Link: L2 seviyesinde paket işlemleri(arping)'>L2 seviyesinde paket işlemleri(arping)</a></li>
<li><a href='http://blog.lifeoverip.net/2007/03/26/scapy-calismalari-iii-paket-dinleyicileri-belirleme/' rel='bookmark' title='Permanent Link: Scapy Calismalari-III [Paket Dinleyicileri Belirleme]'>Scapy Calismalari-III [Paket Dinleyicileri Belirleme]</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wireshark.org/docs/man-pages/tshark.html">Tshark</a>, güçlü bir  ağ protokolleri analiz programıdır. Tshark komut satırından çalışır ve yine bir ag trafik analiz programı olan Wireshark&#8217;da bulunan  çoğu özelliği destekler.</p>
<p>Komut satırından çalışan ve çok bilinen diğer bir trafik analiz aracı da tcpdump&#8217;dır.</p>
<p>Tshark ile tcpdump&#8217;ın ayrıldığı en belirgin nokta Tshark&#8217;ın trafik analizinde protokolleri tanıyabilmesi ve bunları detaylı bir şekilde gösterebilmesidir. Aşağıda vereceğim örneklerde<br />
protokol tanımanın ne manaya geldiği daha iyi anlaşılacaktır. Kişisel olarak Tshark&#8217;ı imkanım olduğu ortamlarda tcpdump&#8217;a tercih ediyorum.</p>
<p>Bu ikili, networking konuları ile ilgilenen herkesin a-z&#8217;ye bilmesinde fayda olan araçlardır.</p>
<p><strong>Basit Tshark Kullanımı</strong></p>
<p>tshark, çeşitli işlevleri olan bir sürü parametreye sahiptir. Eğer herhangi bir paramnetre kullanmadan çalıştırılırsa ilk aktif ağ arabirimi üzerinden geçen trafiği yakalayıp ekrana basar.</p>
<blockquote><p><strong> home-labs ~ # tshark</strong><br />
Running as user &#8220;root&#8221; and group &#8220;root&#8221;. This could be dangerous.<br />
Capturing on eth0<br />
0.000000 192.168.2.23 -&gt; 80.93.212.86 ICMP Echo (ping) request<br />
0.012641 80.93.212.86 -&gt; 192.168.2.23 ICMP Echo (ping) reply<br />
0.165214 192.168.2.23 -&gt; 192.168.2.22 SSH Encrypted request packet len=52<br />
0.165444 192.168.2.22 -&gt; 192.168.2.23 SSH Encrypted response packet len=52<br />
0.360152 192.168.2.23 -&gt; 192.168.2.22 TCP pcia-rxp-b &gt; ssh [ACK] Seq=53 Ack=53 Win=59896 Len=0<br />
0.612504 192.168.2.22 -&gt; 192.168.2.23 SSH Encrypted response packet len=116<br />
1.000702 192.168.2.23 -&gt; 80.93.212.86 ICMP Echo (ping) request<br />
1.013761 80.93.212.86 -&gt; 192.168.2.23 ICMP Echo (ping) reply<br />
1.057335 192.168.2.23 -&gt; 192.168.2.22 SSH Encrypted request packet len=52<br />
16 packets captured</p></blockquote>
<p>Eğer çıktıların ekrana değil de sonradan analiz için  bir dosyaya yazdırılması isteniyorsa -w dosya_ismi parametresi kullanılır.</p>
<blockquote><p><strong># tshark -w home_labs.pcap</strong><br />
Running as user &#8220;root&#8221; and group &#8220;root&#8221;. This could be dangerous.<br />
Capturing on eth0</p>
<p>24</p></blockquote>
<p>Gerektiğinde home_labs.pcap dosyası libpcap destekli herhangi bir analiz programı tarafından okunabilir. tshark ya da tcpdump ile kaydedilen dosyadan paket okumak<br />
için -r parametresi kullanılır.</p>
<p><strong>Arabirim Belirtme</strong></p>
<p>İstediğiniz arabirim üzerinden dinleme yapılması istenirse -i arabirim_ismi parametresi kullanılır.</p>
<p><strong>#tshark -i eth12</strong><br />
gibi.</p>
<p>-n parametresi ile de host isimlerinin ve servis isimlerinin çözülmemesi sağlanır.</p>
<p><strong>Detaylı Paket Çıktısı</strong></p>
<p>Paketleri ekrandan izlerken ilgili protokole ait tüm detayları görmek için -V parametresi kullanılabilir.</p>
<p>Mesela udp 53(DNS) paketlerini detaylı çıktısını incelyelim.</p>
<blockquote><p><em>home-labs#thsark -i eth0 udp port 53</em><br />
Frame 2 (100 bytes on wire, 100 bytes captured)<br />
Arrival Time: Jan 17, 2009 11:54:34.174323000<br />
[Time delta from previous captured frame: 0.001332000 seconds]<br />
[Time delta from previous displayed frame: 0.001332000 seconds]<br />
[Time since reference or first frame: 0.001332000 seconds]<br />
Frame Number: 2<br />
Frame Length: 100 bytes<br />
Capture Length: 100 bytes<br />
[Frame is marked: False]<br />
[Protocols in frame: eth:ip:udp:dns]<br />
Ethernet II, Src: Arcadyan_a7:22:5c (00:1a:2a:a7:22:5c), Dst: Giga-Byt_5a:1b:96 (00:1f:d0:5a:1b:96)<br />
Destination: Giga-Byt_5a:1b:96 (00:1f:d0:5a:1b:96)<br />
Address: Giga-Byt_5a:1b:96 (00:1f:d0:5a:1b:96)<br />
&#8230;. &#8230;0 &#8230;. &#8230;. &#8230;. &#8230;. = IG bit: Individual address (unicast)<br />
&#8230;. ..0. &#8230;. &#8230;. &#8230;. &#8230;. = LG bit: Globally unique address (factory default)<br />
Source: Arcadyan_a7:22:5c (00:1a:2a:a7:22:5c)<br />
Address: Arcadyan_a7:22:5c (00:1a:2a:a7:22:5c)<br />
&#8230;. &#8230;0 &#8230;. &#8230;. &#8230;. &#8230;. = IG bit: Individual address (unicast)<br />
&#8230;. ..0. &#8230;. &#8230;. &#8230;. &#8230;. = LG bit: Globally unique address (factory default)<br />
Type: IP (0&#215;0800)<br />
Internet Protocol, Src: 192.168.2.1 (192.168.2.1), Dst: 192.168.2.23 (192.168.2.23)<br />
Version: 4<br />
Header length: 20 bytes<br />
Differentiated Services Field: 0&#215;00 (DSCP 0&#215;00: Default; ECN: 0&#215;00)<br />
0000 00.. = Differentiated Services Codepoint: Default (0&#215;00)<br />
&#8230;. ..0. = ECN-Capable Transport (ECT): 0<br />
&#8230;. &#8230;0 = ECN-CE: 0<br />
Total Length: 86<br />
Identification: 0&#215;0000 (0)<br />
Flags: 0&#215;04 (Don&#8217;t Fragment)<br />
0&#8230; = Reserved bit: Not set<br />
.1.. = Don&#8217;t fragment: Set<br />
..0. = More fragments: Not set<br />
Fragment offset: 0<br />
Time to live: 64<br />
Protocol: UDP (0&#215;11)<br />
Header checksum: 0xb52e [correct]<br />
[Good: True]<br />
[Bad : False]<br />
Source: 192.168.2.1 (192.168.2.1)<br />
Destination: 192.168.2.23 (192.168.2.23)<br />
User Datagram Protocol, Src Port: domain (53), Dst Port: blueberry-lm (1432)<br />
Source port: domain (53)<br />
Destination port: blueberry-lm (1432)<br />
Length: 66<br />
Checksum: 0x2a35 [correct]<br />
[Good Checksum: True]<br />
[Bad Checksum: False]<br />
Domain Name System (response)<br />
[Request In: 1]<br />
[Time: 0.001332000 seconds]<br />
<strong>Transaction ID: 0&#215;0001<br />
Flags: 0&#215;8100 (Standard query response, No error)<br />
1&#8230; &#8230;. &#8230;. &#8230;. = Response: Message is a response<br />
.000 0&#8230; &#8230;. &#8230;. = Opcode: Standard query (0)<br />
&#8230;. .0.. &#8230;. &#8230;. = Authoritative: Server is not an authority for domain<br />
&#8230;. ..0. &#8230;. &#8230;. = Truncated: Message is not truncated<br />
&#8230;. &#8230;1 &#8230;. &#8230;. = Recursion desired: Do query recursively<br />
&#8230;. &#8230;. 0&#8230; &#8230;. = Recursion available: Server can&#8217;t do recursive queries<br />
&#8230;. &#8230;. .0.. &#8230;. = Z: reserved (0)<br />
&#8230;. &#8230;. ..0. &#8230;. = Answer authenticated: Answer/authority portion was not authenticated by the server<br />
&#8230;. &#8230;. &#8230;. 0000 = Reply code: No error (0)</strong><br />
Questions: 1<br />
Answer RRs: 1<br />
Authority RRs: 0<br />
Additional RRs: 0<br />
Queries<br />
1.2.168.192.in-addr.arpa: type PTR, class IN<br />
Name: 1.2.168.192.in-addr.arpa<br />
Type: PTR (Domain name pointer)<br />
Class: IN (0&#215;0001)<br />
Answers<br />
1.2.168.192.in-addr.arpa: type PTR, class IN, RT<br />
Name: 1.2.168.192.in-addr.arpa<br />
Type: PTR (Domain name pointer)<br />
Class: IN (0&#215;0001)<br />
Time to live: 2 hours, 46 minutes, 40 seconds<br />
Data length: 4<br />
Domain name: RT</p></blockquote>
<p>Benzer bir paketin tcpdump ile görüntüsü aşağıdaki gibi olacaktır. Her iki çıktıdan da görüleceği gibi Tshark ile protokol ve katmanlara ait tüm detaylar çözümlenirken tcpdump&#8217;da sadece özet bilgiler yer alır.</p>
<blockquote><p><strong> # tcpdump -i eth0 -n udp port 53 -vv</strong><br />
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes</p>
<p>11:57:12.096474 IP (tos 0&#215;0, ttl 128, id 21291, offset 0, flags [none], proto UDP (17), length 59) 192.168.2.23.1446 &gt; 192.168.2.1.53: [udp sum ok] 2+ A?</p>
<p>www.linux.com. (31)<br />
11:57:12.820246 IP (tos 0&#215;0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 215) 192.168.2.1.53 &gt; 192.168.2.23.1446: 2 q: A? www.linux.com. 2/3/3</p>
<p>www.linux.com. CNAME linux.com., linux.com.[|domain]</p></blockquote>
<p><strong>Tshark&#8217;da Filtreler</strong></p>
<p>Tshark aynı Wireshark&#8217;da olduğu gibi iki çeşit filtreleme özelliğine sahiptir. Bunlardan biri trafik yakalama esnasında kullanılan ve tcpdump ile hemen hemen aynı<br />
özelliklere(Berkley Paket Filter) sahip olan capture filter, diğeri de yakalanan trafik üzerinde detaylı analiz yapmaya yarayan Display filter dır.<br />
<em><strong>Display filterlar aynı zamanda paket yakalama esnasında da kullanılabilir.</strong><br />
</em></p>
<p><strong>Display filter Kavramı</strong></p>
<p>Display filter özelliği ile Tshark çözümleyebildiği protokollere ait tüm detayları gösterebilir ve sadece bu detaylara ait paketleri yakalamaya yardımcı olur. Mesela<br />
amacımız tüm dns trafiği değil de dns trafiği içerisinde sadece www.lifeoverip.net domainine ait sorgulamaları yakalamak istersek aşağıdaki gibi bir filtreleme işimize yarayacaktır.</p>
<p><strong><em>Note: Display Filter için  -R &#8216;filtreleme detayı&#8217; seçeneği kullanılır.</em></strong><em></em></p>
<blockquote><p><strong># tshark -i eth0 -n -R &#8216;dns.qry.name==www.lifeoverip.net&#8217;</strong><br />
Running as user &#8220;root&#8221; and group &#8220;root&#8221;. This could be dangerous.<br />
Capturing on eth0<br />
11.467730 192.168.2.23 -&gt; 192.168.2.1  DNS Standard query A www.lifeoverip.net<br />
13.467968 192.168.2.23 -&gt; 192.168.2.1  DNS Standard query A www.lifeoverip.net<br />
17.936486 192.168.2.23 -&gt; 192.168.2.1  DNS Standard query A www.lifeoverip.net<br />
17.938038  192.168.2.1 -&gt; 192.168.2.23 DNS Standard query response A 80.93.212.86</p></blockquote>
<p>Böylece normal snifferlarda sadece udp 53&#8242;u dinleyerek bulmaya çalıştığımız detaylar Tshark ile kolayca belirtilebiliyor.</p>
<p>Display Filterlari akılda tutmak ya da ilgili protokole ait tüm detayları bilmek zor olabilir. Bunun için gerektiğinde başvurulacak sağlam bir kaynak var: <a href="http://www.wireshark.org/docs/dfref/">wireshark<br />
Display Filter Reference</a>. Bu adresten ilgili protokole ait desteklenen tüm filtrelemeler incelenebilir.</p>
<p><img class="alignleft size-full wp-image-912" title="dns_filter" src="http://netsec.lifeoverip.net/wp-content/uploads/2009/01/dns_filter.png" alt="dns_filter" width="595" height="503" /></p>
<p><strong>Örnek: HTTP trafiği içerisinde GET, PUT ve OPTIONS kullanılan istekleri yakalama.</strong></p>
<blockquote><p><strong>home-labs#tshark -i eth0 -n -R &#8216;http.request.method contains GET or http.request.method contains PUT or http.request.method contains OPTIONS&#8217;</strong></p>
<p>Running as user &#8220;root&#8221; and group &#8220;root&#8221;. This could be dangerous.<br />
Capturing on eth0<br />
7.571543 192.168.2.22 -&gt; 80.93.212.86 HTTP OPTIONS / HTTP/1.111<br />
14.925700 192.168.2.22 -&gt; 80.93.212.86 HTTP GET / HTRTP/1.1</p></blockquote>
<p>Bir TCP Bağlantısına ait başlangıç ve bitiş  paketlerini yakalama</p>
<p>İçerisinde SYN veya FIN bayrağı set edilmiş paketleri yakalamak için</p>
<blockquote><p><strong># tshark -n -R &#8216;tcp.port==80 and tcp.flags.fin==1 or tcp.flags.syn==1&#8242;</strong><br />
Running as user &#8220;root&#8221; and group &#8220;root&#8221;. This could be dangerous.<br />
Capturing on eth0<br />
1.245831 192.168.2.22 -&gt; 80.93.212.86 TCP 36566 &gt; 80 [SYN] Seq=0 Win=5840 Len=0 MSS=1460 TSV=2759271 TSER=0 WS=5<br />
1.259797 80.93.212.86 -&gt; 192.168.2.22 TCP 80 &gt; 36566 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1452 WS=1 TSV=2754203455 TSER=2759271<br />
3.966800 80.93.212.86 -&gt; 192.168.2.22 TCP 80 &gt; 36566 [FIN, ACK] Seq=212 Ack=11 Win=66240 Len=0 TSV=2754206160 TSER=2759947<br />
3.966919 192.168.2.22 -&gt; 80.93.212.86 TCP 36566 &gt; 80 [FIN, ACK] Seq=11 Ack=213 Win=6912 Len=0 TSV=2759952 TSER=2754206160</p></blockquote>
<p><strong> Filtrelemelerde kullanılacak operatörler(==, !=, contains, vs) için http://www.wireshark.org/docs/dfref/ adresi incelenebilir.</strong></p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;partner=sociable" title="Print"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;title=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi&amp;bodytext=Tshark%2C%20g%C3%BC%C3%A7l%C3%BC%20bir%20%20a%C4%9F%20protokolleri%20analiz%20program%C4%B1d%C4%B1r.%20Tshark%20komut%20sat%C4%B1r%C4%B1ndan%20%C3%A7al%C4%B1%C5%9F%C4%B1r%20ve%20yine%20bir%20ag%20trafik%20analiz%20program%C4%B1%20olan%20Wireshark%27da%20bulunan%C2%A0%20%C3%A7o%C4%9Fu%20%C3%B6zelli%C4%9Fi%20destekler.%0A%0AKomut%20sat%C4%B1r%C4%B1ndan%20%C3%A7al%C4%B1%C5%9Fan%20ve%20%C3%A7ok%20bilinen%20di%C4%9Fer%20b" title="Digg"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F" title="Sphinn"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/sphinn.png" title="Sphinn" alt="Sphinn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;title=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi&amp;notes=Tshark%2C%20g%C3%BC%C3%A7l%C3%BC%20bir%20%20a%C4%9F%20protokolleri%20analiz%20program%C4%B1d%C4%B1r.%20Tshark%20komut%20sat%C4%B1r%C4%B1ndan%20%C3%A7al%C4%B1%C5%9F%C4%B1r%20ve%20yine%20bir%20ag%20trafik%20analiz%20program%C4%B1%20olan%20Wireshark%27da%20bulunan%C2%A0%20%C3%A7o%C4%9Fu%20%C3%B6zelli%C4%9Fi%20destekler.%0A%0AKomut%20sat%C4%B1r%C4%B1ndan%20%C3%A7al%C4%B1%C5%9Fan%20ve%20%C3%A7ok%20bilinen%20di%C4%9Fer%20b" title="del.icio.us"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;t=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi" title="Facebook"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;title=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi" title="Mixx"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;title=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi&amp;annotation=Tshark%2C%20g%C3%BC%C3%A7l%C3%BC%20bir%20%20a%C4%9F%20protokolleri%20analiz%20program%C4%B1d%C4%B1r.%20Tshark%20komut%20sat%C4%B1r%C4%B1ndan%20%C3%A7al%C4%B1%C5%9F%C4%B1r%20ve%20yine%20bir%20ag%20trafik%20analiz%20program%C4%B1%20olan%20Wireshark%27da%20bulunan%C2%A0%20%C3%A7o%C4%9Fu%20%C3%B6zelli%C4%9Fi%20destekler.%0A%0AKomut%20sat%C4%B1r%C4%B1ndan%20%C3%A7al%C4%B1%C5%9Fan%20ve%20%C3%A7ok%20bilinen%20di%C4%9Fer%20b" title="Google Bookmarks"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F&amp;title=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi" title="StumbleUpon"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F" title="Technorati"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Thsark%20ile%20TCP%2FIP%20Paket%20Analizi%20-%20http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F17%2Fthsark-ile-tcpip-paket-analizi%2F" title="Twitter"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>

<p>Related posts:<ol><li><a href='http://blog.lifeoverip.net/2009/09/13/paket-analizi-protokol-analizi-kavramlari/' rel='bookmark' title='Permanent Link: Paket analizi, protokol analizi kavramları'>Paket analizi, protokol analizi kavramları</a></li>
<li><a href='http://blog.lifeoverip.net/2009/06/06/l2-seviyesinde-paket-islemleriarping/' rel='bookmark' title='Permanent Link: L2 seviyesinde paket işlemleri(arping)'>L2 seviyesinde paket işlemleri(arping)</a></li>
<li><a href='http://blog.lifeoverip.net/2007/03/26/scapy-calismalari-iii-paket-dinleyicileri-belirleme/' rel='bookmark' title='Permanent Link: Scapy Calismalari-III [Paket Dinleyicileri Belirleme]'>Scapy Calismalari-III [Paket Dinleyicileri Belirleme]</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>tcpdump &amp; tshark ile CDP paketleri</title>
		<link>http://blog.lifeoverip.net/2009/01/06/tcpdump-tshark-ile-cdp-paketleri/</link>
		<comments>http://blog.lifeoverip.net/2009/01/06/tcpdump-tshark-ile-cdp-paketleri/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 11:15:30 +0000</pubDate>
		<dc:creator>Huzeyfe ONAL</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[cdp]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[tshark]]></category>

		<guid isPermaLink="false">http://blog.lifeoverip.net/?p=885</guid>
		<description><![CDATA[CDP Cisco cihazlarin kendilerini tanitmalari/tanimalari icin kullandiklari bir protokoldur. CDP paketleri multicast yayilma gosterirler ve agda bulunan herhangi birisi bu paketleri dinleyerek calisan sistemler hakkinda detayli bilgi edinebilir. CDP ile bir Cisco sisteme ait Cihazin host adresi, IP Adresi, Interface bilgileri, Detaylı IOS bilgisi, Platform bilgisi, VTP domain ismi vs gibi bilgiler alinabilir. CDP paketlerini [...]


Related posts:<ol><li><a href='http://blog.lifeoverip.net/2008/01/10/tcpdumpi-saldiri-tespit-sistemi-olarak-kullanma/' rel='bookmark' title='Permanent Link: tcpdump&#8217;i saldiri tespit sistemi olarak kullanma'>tcpdump&#8217;i saldiri tespit sistemi olarak kullanma</a></li>
<li><a href='http://blog.lifeoverip.net/2010/03/23/ddos-analizinde-tcpdump-kullanimi/' rel='bookmark' title='Permanent Link: DDOS analizinde tcpdump kullanımı'>DDOS analizinde tcpdump kullanımı</a></li>
<li><a href='http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/' rel='bookmark' title='Permanent Link: Thsark ile TCP/IP Paket Analizi'>Thsark ile TCP/IP Paket Analizi</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Cisco_Discovery_Protocol">CDP </a>Cisco cihazlarin kendilerini tanitmalari/tanimalari icin kullandiklari bir protokoldur. CDP paketleri multicast yayilma gosterirler ve agda bulunan herhangi birisi bu paketleri dinleyerek calisan sistemler hakkinda detayli bilgi edinebilir.</p>
<p>CDP ile bir Cisco sisteme ait Cihazin host adresi, IP Adresi, Interface bilgileri, Detaylı IOS bilgisi, Platform bilgisi, VTP domain ismi vs gibi bilgiler alinabilir. CDP paketlerini tcpdump, tshark ya da benzeri bir sniffer/ag dinleyici bir programla yakalayabilirsiniz.</p>
<p><strong>#tcpdump -nn -v -i rl0 -s 1500 -c 1 &#8216;ether[20:2] == 0&#215;2000&#8242;</strong></p>
<p>11:47:05.413153 CDPv2, ttl: 180s, checksum: 692 (unverified), length 364<br />
Device-ID (0&#215;01), length: 8 bytes: &#8217;3548-700&#8242;<br />
Address (0&#215;02), length: 13 bytes: IPv4 (1) 2.1.94.2<br />
Port-ID (0&#215;03), length: 16 bytes: &#8216;FastEthernet0/23&#8242;<br />
Capability (0&#215;04), length: 4 bytes: (0x0000000a): Transparent Bridge, L2 Switch<br />
Version String (0&#215;05), length: 231 bytes:<br />
Cisco Internetwork Operating System Software<br />
IOS &#8482; C3500XL Software (C3500XL-C3H2S-M), Version 12.0(5.3)WC(1), MAINTENANCE INTERIM SOFTWARE<br />
Copyright (c) 1986-2001 by cisco Systems, Inc.<br />
Compiled Mon 30-Apr-01 07:51 by devgoyal<br />
Platform (0&#215;06), length: 17 bytes: &#8216;cisco WS-C3548-XL&#8217;<br />
Protocol-Hello option (0&#215;08), length: 32 bytes:<br />
VTP Management Domain (0&#215;09), length: 7 bytes: &#8216;aaabbbcccx&#8217;</p>
<p>Tshark ile gorunumu daha aciklayici ciktilar elde edebilirsiniz.</p>
<p><strong>bt ~ # tshark -i eth1 -V -f &#8220;ether host 01:00:0c:cc:cc:cc&#8221;</strong><br />
Cisco Discovery Protocol<br />
Version: 2<br />
TTL: 180 seconds<br />
Checksum: 0xd50d [incorrect, should be 0xd60b]<span id="more-885"></span><br />
[Good: False]<br />
[Bad : True]<br />
Device ID: SMG1117N0XW(x9-User)<br />
Type: Device ID (0&#215;0001)<br />
Length: 33<br />
Device ID: SMG1117N0XW(Kx-User)<br />
Addresses<br />
Type: Addresses (0&#215;0002)<br />
Length: 17<br />
Number of addresses: 1<br />
IP address: x.x.x.x.<br />
Protocol type: NLPID<br />
Protocol length: 1<br />
Protocol: IP<br />
Address length: 4<br />
IP address: x.x.x.x<br />
Port ID: 9/11<br />
Type: Port ID (0&#215;0003)<br />
Length: 8<br />
Sent through Interface: x/11<br />
Capabilities<br />
Type: Capabilities (0&#215;0004)<br />
Length: 8<br />
Capabilities: 0x0000002a<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;0 = Not a Router<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. ..1. = Is  a Transparent Bridge<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. .0.. = Not a Source Route Bridge<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. 1&#8230; = Is  a Switch<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;0 &#8230;. = Not a Host<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. ..1. &#8230;. = Is  IGMP capable<br />
&#8230;. &#8230;. &#8230;. &#8230;. &#8230;. &#8230;. .0.. &#8230;. = Not a Repeater<br />
Software Version<br />
Type: Software version (0&#215;0005)<br />
Length: 102<br />
Software Version: WS-C6509-E Software, Version McpSW: 8.5(8) NmpSW: 8.5(8)<br />
Copyright (c) 1995-2006 by Cisco Systems<br />
Platform: WS-C6509-E<br />
Type: Platform (0&#215;0006)<br />
Length: 14<br />
Platform: WS-C6509-E<br />
VTP Management Domain:<br />
Type: VTP Management Domain (0&#215;0009)<br />
Length: 4<br />
VTP Management Domain:<br />
Native VLAN: x<br />
Type: Native VLAN (0x000a)<br />
Length: 6<br />
Native VLAN: x<br />
Duplex: Full<br />
Type: Duplex (0x000b)<br />
Length: 5<br />
Duplex: Full<br />
VoIP VLAN Reply: xxx<br />
Type: VoIP VLAN Reply (0x000e)<br />
Length: 7<br />
Data<br />
Voice VLAN:xxx<br />
Trust Bitmap: 0&#215;00<br />
Type: Trust Bitmap (0&#215;0012)<br />
Length: 5<br />
Trust Bitmap: 00<br />
Untrusted port CoS: 0&#215;00<br />
Type: Untrusted Port CoS (0&#215;0013)<br />
Length: 5<br />
Untrusted port CoS: 00<br />
System Name: x.x.x.x<br />
Type: System Name (0&#215;0014)<br />
Length: 20<br />
System Name: x.x.x.x<br />
System Object Identifier<br />
Type: System Object ID (0&#215;0015)<br />
Length: 14<br />
System Object Identifier: 06082B0601040109052C<br />
Management Addresses<br />
Type: Management Address (0&#215;0016)<br />
Length: 17<br />
Number of addresses: 1<br />
IP address: x.x.x.x<br />
Protocol type: NLPID<br />
Protocol length: 1<br />
Protocol: IP<br />
Address length: 4<br />
IP address: x.x.x.x<br />
Location: x.x.x.x<br />
Type: Location (0&#215;0017)<br />
Length: 20<br />
UNKNOWN: 0&#215;00<br />
Location: x.x.x.x<br />
Power Available: 7000 mW, 4294967295 mW<br />
Type: Power Available (0x001a)<br />
Length: 16<br />
Request-ID: 0<br />
Management-ID: 1<br />
Power Available: 7000 mW<br />
Power Available: 4294967295 mW</p>
<p>Frame 12 (327 bytes on wire, 327 bytes captured)<br />
Arrival Time: Jan  6, 2009 11:09:47.458170000<br />
[Time delta from previous captured frame: 60.087622000 seconds]<br />
[Time delta from previous displayed frame: 60.087622000 seconds]<br />
[Time since reference or first frame: 661.176321000 seconds]<br />
Frame Number: 12<br />
Frame Length: 327 bytes<br />
Capture Length: 327 bytes<br />
[Frame is marked: False]<br />
[Protocols in frame: eth:llc:cdp:data]<br />
IEEE 802.3 Ethernet<br />
Destination: CDP/VTP/DTP/PAgP/UDLD (01:00:0c:cc:cc:cc)<br />
Address: CDP/VTP/DTP/PAgP/UDLD (01:00:0c:cc:cc:cc)<br />
&#8230;. &#8230;1 &#8230;. &#8230;. &#8230;. &#8230;. = IG bit: Group address (multicast/broadcast)<br />
&#8230;. ..0. &#8230;. &#8230;. &#8230;. &#8230;. = LG bit: Globally unique address (factory default)<br />
Source: Cisco_:3e (00:1b:53::3e)<br />
Address: Cisco_40:17:3e (00:1b:53:40:17:3e)<br />
&#8230;. &#8230;0 &#8230;. &#8230;. &#8230;. &#8230;. = IG bit: Individual address (unicast)<br />
&#8230;. ..0. &#8230;. &#8230;. &#8230;. &#8230;. = LG bit: Globally unique address (factory default)<br />
Length: 313<br />
Logical-Link Control<br />
DSAP: SNAP (0xaa)<br />
IG Bit: Individual<br />
SSAP: SNAP (0xaa)<br />
CR Bit: Command<br />
Control field: U, func=UI (0&#215;03)<br />
000. 00.. = Command: Unnumbered Information (0&#215;00)<br />
&#8230;. ..11 = Frame type: Unnumbered frame (0&#215;03)<br />
Organization Code: Cisco (0x00000c)<br />
PID: CDP (0&#215;2000)</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;partner=sociable" title="Print"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;title=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri&amp;bodytext=CDP%20Cisco%20cihazlarin%20kendilerini%20tanitmalari%2Ftanimalari%20icin%20kullandiklari%20bir%20protokoldur.%20CDP%20paketleri%20multicast%20yayilma%20gosterirler%20ve%20agda%20bulunan%20herhangi%20birisi%20bu%20paketleri%20dinleyerek%20calisan%20sistemler%20hakkinda%20detayli%20bilgi%20edinebilir.%0A%0ACDP%20" title="Digg"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F" title="Sphinn"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/sphinn.png" title="Sphinn" alt="Sphinn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;title=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri&amp;notes=CDP%20Cisco%20cihazlarin%20kendilerini%20tanitmalari%2Ftanimalari%20icin%20kullandiklari%20bir%20protokoldur.%20CDP%20paketleri%20multicast%20yayilma%20gosterirler%20ve%20agda%20bulunan%20herhangi%20birisi%20bu%20paketleri%20dinleyerek%20calisan%20sistemler%20hakkinda%20detayli%20bilgi%20edinebilir.%0A%0ACDP%20" title="del.icio.us"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;t=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri" title="Facebook"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;title=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri" title="Mixx"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;title=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri&amp;annotation=CDP%20Cisco%20cihazlarin%20kendilerini%20tanitmalari%2Ftanimalari%20icin%20kullandiklari%20bir%20protokoldur.%20CDP%20paketleri%20multicast%20yayilma%20gosterirler%20ve%20agda%20bulunan%20herhangi%20birisi%20bu%20paketleri%20dinleyerek%20calisan%20sistemler%20hakkinda%20detayli%20bilgi%20edinebilir.%0A%0ACDP%20" title="Google Bookmarks"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F&amp;title=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri" title="StumbleUpon"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F" title="Technorati"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=tcpdump%20%26amp%3B%20tshark%20ile%20CDP%20paketleri%20-%20http%3A%2F%2Fblog.lifeoverip.net%2F2009%2F01%2F06%2Ftcpdump-tshark-ile-cdp-paketleri%2F" title="Twitter"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>

<p>Related posts:<ol><li><a href='http://blog.lifeoverip.net/2008/01/10/tcpdumpi-saldiri-tespit-sistemi-olarak-kullanma/' rel='bookmark' title='Permanent Link: tcpdump&#8217;i saldiri tespit sistemi olarak kullanma'>tcpdump&#8217;i saldiri tespit sistemi olarak kullanma</a></li>
<li><a href='http://blog.lifeoverip.net/2010/03/23/ddos-analizinde-tcpdump-kullanimi/' rel='bookmark' title='Permanent Link: DDOS analizinde tcpdump kullanımı'>DDOS analizinde tcpdump kullanımı</a></li>
<li><a href='http://blog.lifeoverip.net/2009/01/17/thsark-ile-tcpip-paket-analizi/' rel='bookmark' title='Permanent Link: Thsark ile TCP/IP Paket Analizi'>Thsark ile TCP/IP Paket Analizi</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.lifeoverip.net/2009/01/06/tcpdump-tshark-ile-cdp-paketleri/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
