1 PCAP包解析

24字节头部,主要关注Magic4字节0xa1b2c3d4,以及LinkType4字节。

PCAP文件解析

LinkType定义:

常用类型:

0           BSD loopback devices, except for later OpenBSD
1            Ethernet, and Linux loopback devices
6            802.5 Token Ring
7            ARCnet
8            SLIP
9            PPP
10           FDDI
100         LLC/SNAP-encapsulated ATM
101         “raw IP”, with no link
102         BSD/OS SLIP
103         BSD/OS PPP
104         Cisco HDLC
105         802.11
108         later OpenBSD loopback devices (with the AF_value in network byte order)
113         special Linux “cooked” capture
114         LocalTalk

常用类型1、9、101、104、105

相关文章: