WIRESHARK - ์‰ฝ๊ฒŒ ๋”ฐ๋ผํ•˜๋Š” ํŠœํ† ๋ฆฌ์–ผ - ํ•„ํ„ฐ

Wireshark ํ•„ํ„ฐ
์ตœ์ข… ์—…๋ฐ์ดํŠธ: 04-02-08




Tool
Tutorial
Ergonomy
Forum



์„ธ๋ถ€๋‚ด์šฉ Wireshark๋ž€ ๋ฌด์—‡์ธ๊ฐ€?
์Šคํฌ๋ฆฐ์ƒท
์ค€๋น„์‚ฌํ•ญ
์„ค์น˜
Wireshark ์‹คํ–‰
ํ”Œ๋žซํผ
ํ•„ํ„ฐ
ํ†ต๊ณ„

Korean translation by JaeYoung Jeon.




If you like our tutorials, don't hesitate to support us and visit our sponsors!
Si vous aimez nos tutoriaux, n'hรฉsitez pas ร  nous supporter et visiter nos sponsors!

Add your advertisement here for a low price !!!
The OpenManiak Statistics provided by Google Analytics for the 12 last months show more that 1 million visits and more than 2 millions pageviews from 224 countries !!!
Check our statistics page for more details and contact us !!


์ฒซ ํŠœํ† ๋ฆฌ์–ผ์—์„œ ๋ณด์•˜๋“ฏ์ด Wireshark์„ ์„ค์น˜ํ•˜๊ณ  ๋„คํŠธ์›Œํฌ ์ •๋ณด๋ฅผ ๋ถ„์„ํ•˜๋Š” ๊ฒƒ์€ ๋งค์šฐ ์‰ฝ์Šต๋‹ˆ๋‹ค.

Wireshark์„ ๋ณ„๋‹ค๋ฅธ ์„ค์ • ์—†์ด ๊ธฐ๋ณธ๊ฐ’์œผ๋กœ ์‹คํ–‰์‹œ์ผฐ์„ ๋•Œ ๊ฐ€์žฅ ๋ฌธ์ œ๊ฐ€ ๋  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์€, ํ™”๋ฉด์— ๋„ˆ๋ฌด ๋งŽ์€ ์ •๋ณด๋“ค์ด ๋‚˜ํƒ€๋‚˜์„œ ์›ํ•˜๋Š” ์ •๋ณด๋ฅผ ์ฐพ๊ธฐ๊ฐ€ ์‰ฝ์ง€ ์•Š๋‹ค๋Š”๋ฐ ์žˆ์Šต๋‹ˆ๋‹ค.
๊ณผ์œ ๋ถˆ๊ธ‰.

์ด๊ฒƒ์ด ๋ฐ”๋กœ ํ•„ํ„ฐ๊ฐ€ ์ค‘์š”ํ•œ ์ด์œ ์ž…๋‹ˆ๋‹ค. ํ•„ํ„ฐ๋Š” ๋ฐฉ๋Œ€ํ•œ ๋กœ๊ทธ ์ค‘์—์„œ ์›ํ•˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ฐพ๋Š”๋ฐ ๋„์›€์„ ์ค„ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

-

-
 
๋กœ๊ทธ์— ๊ธฐ๋ก๋˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์„ ํƒํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ด ํ•„ํ„ฐ๋Š” ์บก์ณ๊ฐ€ ์‹œ์ž‘๋˜๊ธฐ ์ „์— ์ •์˜๋ฉ๋‹ˆ๋‹ค.
์บก์ณ๋œ ๋กœ๊ทธ์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ฐพ์„ ๋•Œ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ๊ฐ€ ์บก์ณ๋˜๋Š” ๋™์•ˆ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
capture ํ•„ํ„ฐ๋‚˜ display ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์„๊นŒ์š”?

์ด ๋‘ ๊ฐ€์ง€ ํ•„ํ„ฐ์˜ ๋ชฉ์ ์€ ์„œ๋กœ ๋‹ค๋ฆ…๋‹ˆ๋‹ค.
capture ํ•„ํ„ฐ๋Š” ๋กœ๊ทธ์˜ ์‚ฌ์ด์ฆˆ๊ฐ€ ๋ถˆํ•„์š”ํ•˜๊ฒŒ ์ปค์ง€๋Š” ๊ฒƒ์„ ๋ง‰๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
display ํ•„ํ„ฐ๋Š” capture ํ•„ํ„ฐ ๋ณด๋‹ค ๋” ๊ฐ•๋ ฅ(๊ทธ๋ฆฌ๊ณ  ๋ณต์žก)ํ•ฉ๋‹ˆ๋‹ค ; ์ด ํ•„ํ„ฐ๋Š” ์›ํ•˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ •ํ™•ํ•˜๊ฒŒ ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค๋‹ˆ๋‹ค.

๋‘ ๊ฐ€์ง€ ํ•„ํ„ฐ์˜ ๊ตฌ๋ฌธ(syntax)์€ ์™„์ „ํžˆ ๋‹ค๋ฆ…๋‹ˆ๋‹ค. ์ด์–ด์ง€๋Š” ํŽ˜์ด์ง€์—์„œ ์ด๊ฒƒ๋“ค์— ๋Œ€ํ•ด ๋ณด์—ฌ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.



                       1. CAPTURE FILTERS            2. DISPLAY FILTERS



1. CAPTURE FILTERS

capture ํ•„ํ„ฐ์˜ ๊ตฌ๋ฌธ์€ TCPdump์ฒ˜๋Ÿผ Lipcap(Linux)์ด๋‚˜ Winpcap(Windows) ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์—์„œ ์“ฐ๋Š” ๊ฒƒ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. Capture ํ•„ํ„ฐ๋Š” ์บก์ณ ๋„์ค‘ ์•„๋ฌด ๋•Œ๋‚˜ ์ˆ˜์ •์ด ๊ฐ€๋Šฅํ•œ display ํ•„ํ„ฐ์™€๋Š” ๋‹ค๋ฅด๊ฒŒ, ๋ฐ˜๋“œ์‹œ ์บก์ณ๋ฅผ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ์„ค์ •์„ ํ•ด์ฃผ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

capture ํ•„ํ„ฐ๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:
- capture -> options ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
- "capture filter" ์นธ์— ์ง์ ‘ ์ž‘์„ฑํ•˜๊ฑฐ๋‚˜, ๋‹ค์Œ ๋ฒˆ ์บก์ณ์— ๋‹ค์‹œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ํ•„ํ„ฐ ์ด๋ฆ„์„ ๋ถ€์—ฌํ•˜๊ธฐ ์œ„ํ•ด "capture filter" ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
- ๋ฐ์ดํ„ฐ๋ฅผ ์บก์ณํ•˜๊ธฐ ์œ„ํ•ด Start๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

wireshark capture options

wireshark capture options

Syntax:
Protocol
Direction
Host(s)
Value
Logical Operations
Other expression
Example:
tcp
dst
10.1.1.1
80
and
tcp dst 10.2.2.2 3128
Protocol:
์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฐ’: ether, fddi, ip, arp, rarp, decnet, lat, sca, moprc, mopdl, tcp and udp.
ํ”„๋กœํ† ์ฝœ์„ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ๋ชจ๋“  ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

Direction:
์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฐ’: src, dst, src and dst, src or dst
์ถœ๋ฐœ์ง€๋‚˜ ๋ชฉ์ ์ง€๋ฅผ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด "src or dst" ํ‚ค์›Œ๋“œ๊ฐ€ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
์˜ˆ๋ฅผ ๋“ค์–ด, "host 10.2.2.2"์€ "src or dst host 10.2.2.2"๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค. Host(s):
์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฐ’: net, port, host, portrange.
ํ˜ธ์ŠคํŠธ๋ฅผ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด "host" ํ‚ค์›Œ๋“œ๊ฐ€ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
์˜ˆ๋ฅผ ๋“ค์–ด, "src 10.1.1.1"์€ "src host 10.1.1.1"๊ณผ ๊ฐ™์€ ์˜๋ฏธ์ž…๋‹ˆ๋‹ค.

Logical Operations:
์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฐ’: not, and, or.
๋ถ€์ • ์—ฐ์‚ฐ("not")์ด ๊ฐ€์žฅ ๋†’์€ ์šฐ์„ ์ˆœ์œ„๋ฅผ ๊ฐ–์Šต๋‹ˆ๋‹ค. ๋…ผ๋ฆฌํ•ฉ("or")๊ณผ ๋…ผ๋ฆฌ๊ณฑ("and")๋Š” ๊ฐ™์€ ์šฐ์„ ์ˆœ์œ„๋ฅผ ๊ฐ€์ง€๋ฉฐ ์™ผ์ชฝ์—์„œ ์˜ค๋ฅธ์ชฝ์œผ๋กœ ์ฒ˜๋ฆฌ๋ฉ๋‹ˆ๋‹ค.
์˜ˆ๋ฅผ ๋“ค์–ด,
"not tcp port 3128 and tcp port 23"์€ "(not tcp port 3128) and tcp port 23"๊ณผ ๋™์ผํ•˜๊ฒŒ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค.
"not tcp port 3128 and tcp port 23" ์€ "not (tcp port 3128 and tcp port 23)"๊ณผ๋Š” ๋™์ผํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.



์‚ฌ์šฉ ์˜ˆ:

tcp dst port 3128
๋ชฉ์ ์ง€๊ฐ€ TCP ํฌํŠธ 3128์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

ip src host 10.1.1.1
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ๊ฐ€ 10.1.1.1์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

host 10.1.2.3
์ถœ๋ฐœ์ง€์™€ ๋ชฉ์ ์ง€ IP ์ฃผ์†Œ๊ฐ€ 10.1.1.1์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

src portrange 2000-2500
์ถœ๋ฐœ์ง€์˜ UDP, TCP ํฌํŠธ๊ฐ€ 2000-2500 ์‚ฌ์ด์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

not imcp
icmp ํŒจํ‚ท์„ ์ œ์™ธํ•œ ๋ชจ๋“  ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค. (icmp๋Š” ๋ณดํ†ต ping ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.)

src host 10.7.2.12 and not dst net 10.200.0.0/16
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ๊ฐ€ 10.7.2.12์ด๋ฉด์„œ, ๋ชฉ์ ์ง€ IP ๋„คํŠธ์›Œํฌ๊ฐ€ 10.200.0.0/16์ด ์•„๋‹Œ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

(src host 10.4.1.12 or src net 10.6.0.0/16) and tcp dst portrange 200-10000 and dst net 10.0.0.0/8
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ๊ฐ€ 10.4.1.12์ด๊ฑฐ๋‚˜, ์ถœ๋ฐœ์ง€ ๋„คํŠธ์›Œํฌ๊ฐ€ 10.6.0.0/16์ธ ํŒจํ‚ท์ค‘์—์„œ ๋ชฉ์ ์ง€ TCP ํฌํŠธ ๋ฒ”์œ„๊ฐ€ 200-10000์ด๋ฉด์„œ, ๋ชฉ์ ์ง€ IP ๋„คํŠธ์›Œํฌ๊ฐ€ 10.0.0.0/8์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.



์ฐธ๊ณ :

"\" ๊ธฐํ˜ธ๋Š” ํ‚ค์›Œ๋“œ ์ž์ฒด๊ฐ€ ๊ฐ’์„ ๋‚˜ํƒ€๋‚ผ ๋•Œ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
"ether proto \ip"( \ip๋Š” "ip"๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค.)
์ด๊ฒƒ์€ IP ํ”„๋กœํ† ์ฝœ์„ ํƒ€์ผ“์œผ๋กœ ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

"ip proto \icmp"(\icmp๋Š” "icmp"๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค.)
์ด๊ฒƒ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ping ์œ ํ‹ธ๋ฆฌํ‹ฐ์—์„œ ์‚ฌ์šฉ๋˜๋Š” icmp ํŒจํ‚ท์„ ํƒ€์ผ“์œผ๋กœ ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

"multicast"์™€ "broadcast" ํ‚ค์›Œ๋“œ๋Š” "ip" ๋‚˜ "ether" ๋‹ค์Œ์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
"no broadcast"๋Š” broadcast ์š”์ฒญ์„ ์ œ์™ธํ•˜๊ณ  ์‹ถ์„ ๋•Œ ์œ ์šฉํ•˜๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.



capture ํ•„ํ„ฐ์˜ ๊ตฌ๋ฌธ์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ํ•„์š”ํ•˜์‹œ๋ฉด TCPdump man page์„ ์ฐธ๊ณ ํ•˜์„ธ์š”.
Other capture filters examples can be found in the Wiki Wireshark website.

ํŽ˜์ด์ง€ ์ฒ˜์Œ์œผ๋กœ



2. DISPLAY FILTERS:

display ํ•„ํ„ฐ๋Š” ์บก์ณ๋œ ๋ฐ์ดํ„ฐ์—์„œ ์›ํ•˜๋Š” ์ •๋ณด๋ฅผ ์ฐพ์„ ๋•Œ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
display ํ•„ํ„ฐ์˜ ๊ฒ€์ƒ‰ ๋Šฅ๋ ฅ์€ capture ํ•„ํ„ฐ ๋ณด๋‹ค ๋” ๋›ฐ์–ด๋‚ฉ๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ํ•„ํ„ฐ์˜ ๋‚ด์šฉ์„ ๋ฐ”๊พธ๊ณ  ์‹ถ์„ ๋•Œ ์บก์ณ ์ž‘์—…์„ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์ง€ ์•Š์•„๋„ ๋ฉ๋‹ˆ๋‹ค.

Syntax: Protocol.
String 1
.
String 2
Comparison operator
Value
Logical Operations
Other expression
Example:
ftp
passive
ip
==
10.2.3.4
xor
icmp.type
Protocol:

OSI layer 2์—์„œ layer 7 ์‚ฌ์ด์— ์žˆ๋Š” ๋งค์šฐ ๋‹ค์–‘ํ•œ ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ๋“ค์€ ๋ฉ”์ธ ํ™”๋ฉด์— ๋ณด์ด๋Š” "Expression..." ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๋ฉด ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

wireshark filter expression

wireshark filter expression

์•„๋ž˜์— ๋ณด์ด๋Š” ๊ทธ๋ฆผ์—์„œ ๊ฐ„๋‹จํ•œ ์„ค๋ช…๊ณผ ํ•จ๊ป˜ ์ง€์› ๊ฐ€๋Šฅํ•œ ํ”„๋กœํ† ์ฝœ๋“ค์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

wireshark supported protocols

wireshark supported protocols

Wireshark ์›น์‚ฌ์ดํŠธ์—์„œ ํ”„๋กœํ† ์ฝœ๊ณผ ๊ทธ๊ฒƒ์˜ ํ•˜์œ„ ์นดํ…Œ๊ณ ๋ฆฌ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ œ๊ณตํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.]

String1, String2 (์„ ํƒ ์‚ฌํ•ญ)

๊ฐ ํ”„๋กœํ† ์ฝœ์˜ ํ•˜์œ„ ํ”„๋กœํ† ์ฝœ ์นดํ…Œ๊ณ ๋ฆฌ.
๊ทธ๊ฒƒ์„ ๋ณด๊ธฐ ์œ„ํ•ด์„œ, ํ”„๋กœํ† ์ฝœ์„ ์„ ํƒํ•œ ๋’ค "+" ํ‘œ์‹œ๋ฅผ ํด๋ฆญํ•˜์„ธ์š”.

wireshark filter expression

๋น„๊ต ์—ฐ์‚ฐ์ž:

6๊ฐœ์˜ ๋น„๊ต ์—ฐ์‚ฐ์ž๋ฅผ ์‚ฌ์šฉ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

์˜๋ฌธ ํ‘œ๊ธฐ:  C์–ธ์–ด ํ‘œ๊ธฐ:  ์˜๋ฏธ:
eq 
== 
๊ฐ™๋‹ค
ne
!=
ํ‹€๋ฆฌ๋‹ค
gt
>
ํฌ๋‹ค
lt
<
์ž‘๋‹ค
ge
>=
ํฌ๊ฑฐ๋‚˜ ๊ฐ™๋‹ค
le
<=
์ž‘๊ฑฐ๋‚˜ ๊ฐ™๋‹ค
๋…ผ๋ฆฌ ํ‘œํ˜„ ์‹:

์˜๋ฌธ ํ‘œ๊ธฐ:  C์–ธ์–ด ํ‘œ๊ธฐ:  ์˜๋ฏธ:
and
&&
๋…ผ๋ฆฌ๊ณฑ
or
||
๋…ผ๋ฆฌํ•ฉ
xor
^^
๋ฐฐํƒ€์  ๋…ผ๋ฆฌํ•ฉ
not
!
๋ถ€์ •
ํ”„๋กœ๊ทธ๋ž˜๋จธ๋“ค์ด ์ž˜ ์•„๋Š” "XOR"์€ ๋ฐฐํƒ€์  ๋…ผ๋ฆฌํ•ฉ ์—ฐ์‚ฐ์œผ๋กœ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ๋‘ ๊ฐ€์ง€ ์กฐ๊ฑด ์‚ฌ์ด์—์„œ ์‚ฌ์šฉ๋˜์—ˆ์„ ๋•Œ, ๋‘ ๊ฐ€์ง€ ์กฐ๊ฑด ์ค‘ ์˜ค์ง ํ•œ๊ฐ€์ง€๋งŒ ๋งŒ์กฑํ–ˆ์„ ๋•Œ ๊ฒฐ๊ณผ ํ™”๋ฉด์— ๋ณด์—ฌ์ง‘๋‹ˆ๋‹ค.
๋‹ค์Œ์˜ display ํ•„ํ„ฐ๋ฅผ ์ด์šฉํ•˜์—ฌ ์˜ˆ์‹œ๋ฅผ ๋ณด์—ฌ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค:
"tcp.dstport 80 xor tcp.dstport 1025"
๋ชฉ์ ์ง€๊ฐ€ TCP ํฌํŠธ 80์ด๊ฑฐ๋‚˜ ์ถœ๋ฐœ์ง€๊ฐ€ TCP ํฌํŠธ 1025์ธ (๋‘ ๊ฐ€์ง€ ๋ชจ๋‘์ธ ๊ฒฝ์šฐ๋Š” ์ œ์™ธํ•˜๊ณ ) ํŒจํ‚ท์ด ๊ฒฐ๊ณผ๋กœ ํ™”๋ฉด์— ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.



์‚ฌ์šฉ ์˜ˆ:

snmp || dns || icmpSNMP ํ˜น์€ DNS ํ˜น์€ ICMP ํŠธ๋ž˜ํ”ฝ์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
ip.addr == 10.1.1.1
์ถœ๋ฐœ์ง€๋‚˜ ๋ชฉ์ ์ง€์˜ IP ์ฃผ์†Œ๊ฐ€ 10.1.1.1์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

ip.src != 10.1.2.3 or ip.dst != 10.4.5.6
์ถœ๋ฐœ์ง€์˜ IP ์ฃผ์†Œ๊ฐ€ 10.1.2.3์ด ์•„๋‹ˆ๊ฑฐ๋‚˜ ๋ชฉ์ ์ง€์˜ IP ์ฃผ์†Œ๊ฐ€ 10.4.5.6์ด ์•„๋‹Œ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
๋‹ค๋ฅธ ๋ง๋กœ ํ•˜์ž๋ฉด, ํ™”๋ฉด์— ๋ณด์—ฌ์ง€๋Š” ํŒจํ‚ท์€ ๋‹ค์Œ๊ณผ ๊ฐ™์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค:
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ : 10.1.2.3์ด ์•„๋‹Œ ๋ชจ๋“  ์ฃผ์†Œ, ๋ชฉ์ ์ง€ IP ์ฃผ์†Œ : 10.1.2.3์ด ์•„๋‹Œ ๋ชจ๋“  ์ฃผ์†Œ
๊ทธ๋ฆฌ๊ณ 
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ : ๋ชจ๋“  ์ฃผ์†Œ, ๋ชฉ์ ์ง€ IP ์ฃผ์†Œ : 10.4.5.6์ด ์•„๋‹Œ ๋ชจ๋“  ์ฃผ์†Œ

ip.src != 10.1.2.3 and ip.dst != 10.4.5.6
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ๊ฐ€ 10.1.2.3์ด ์•„๋‹ˆ๋ฉด์„œ, ๋™์‹œ์— ๋ชฉ์ ์ง€ IP ์ฃผ์†Œ๊ฐ€ 10.4.5.6์ด ์•„๋‹Œ ํŒจํ‚ท์„ ํ™”๋ฉด์— ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
๋‹ค๋ฅธ ๋ง๋กœ ํ•˜์ž๋ฉด, ํ™”๋ฉด์— ๋ณด์—ฌ์ง€๋Š” ํŒจํ‚ท์€ ๋‹ค์Œ๊ณผ ๊ฐ™์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค:
์ถœ๋ฐœ์ง€ IP ์ฃผ์†Œ : 10.1.2.3์ด ์•„๋‹Œ ๋ชจ๋“  ์ฃผ์†Œ, ๊ทธ๋ฆฌ๊ณ  ๋ชฉ์ ์ง€ IP ์ฃผ์†Œ : 10.4.5.6์ด ์•„๋‹Œ ๋ชจ๋“  ์ฃผ์†Œ

tcp.port == 25 ์ถœ๋ฐœ์ง€์™€ ๋ชฉ์ ์ง€์˜ TCP ํฌํŠธ๊ฐ€ 25์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
tcp.dstport == 25๋ชฉ์ ์ง€์˜ TCP ํฌํŠธ๊ฐ€ 25์ธ ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
tcp.flagsTCP ํ”Œ๋ž˜๊ทธ๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
tcp.flags.syn == 0x02TCP SYN ํ”Œ๋ž˜๊ทธ๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ํŒจํ‚ท์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
ํ•„ํ„ฐ ๊ตฌ๋ฌธ์— ๋ฌธ์ œ๊ฐ€ ์—†๋‹ค๋ฉด, ๋…น์ƒ‰์œผ๋กœ ํ•˜์ด๋ผ์ดํŠธ ๋  ๊ฒƒ์ด๋ฉฐ, ์ž˜๋ชป๋๋‹ค๋ฉด ๋ถ‰์€์ƒ‰์œผ๋กœ ํ•˜์ด๋ผ์ดํŠธ ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

wireshark display filter example์˜ฌ๋ฐ”๋ฅธ ๊ตฌ๋ฌธ
wireshark display filter example ์ž˜๋ชป๋œ ๊ตฌ๋ฌธ
display ํ•„ํ„ฐ์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์ •๋ณด๋Š” Wireshark official website๋‚˜ Wiki Wireshark website์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


ํŽ˜์ด์ง€ ์ฒ˜์Œ์œผ๋กœ





If you liked our tutorials, don't hesitate to support us and visit our sponsors!
Si vous aimez nos tutoriaux, n'hรฉsitez pas ร  nous supporter et visiter nos sponsors!