<?xml version="1.0" encoding="gb2312" ?>
<rss version="2.0">
<channel>
<title>协议分析</title>
<link>http://www.cnpaf.nethttp://www.cnpaf.net/Class/Analyze/</link>
<description>协议分析</description>
<language>zh-cn</language>
<generator><![CDATA[    &lt;p&gt;版权所有 &lt;a href=&quot;http://www.cnpaf.net&quot;&gt;协议分析网&lt;/a&gt; 信箱:wayky#126.com(把&quot;#&quot;改成&quot;@&quot;)&lt;br /&gt;
Copyright (C)&lt;span style=&quot;FONT-WEIGHT: bold; FONT-SIZE: 8.5pt; FONT-STYLE: italic; FONT-FAMILY: Arial&quot;&gt;
&lt;span style=&quot;COLOR: #f26522&quot;&gt;www.&lt;span style=&quot;COLOR: #006699&quot;&gt;Cnpaf.&lt;/span&gt;N&lt;/span&gt;et &lt;span style=&quot;COLOR: #f26522&quot;&gt;2004-2013&lt;/span&gt; &lt;/span&gt; All Rights Reserved.京公网安备110105010524]]></generator>
<webmaster>wayky@126.com</webmaster>
<item>
    <title><![CDATA[基于Winpcap的网络流媒体识别算法研究与实现]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/201105/25868.html</link>
    <description><![CDATA[0 引言 随着计算机网络、视频压缩等关键技术的快速发展，网络流媒体技术目前已成为继文字和图片之后，互联网信息传播的主要形式。通过网络流媒体技术，用户可以方便地存]]></description>
    <pubDate>2011-05-14</pubDate>
    <category>Winpcap</category>
    <author>小远</author>
    <comments>未知</comments>
</item>
<item>
    <title><![CDATA[使用Wireshark查看局域网内安全问题]]></title>
    <link>http://www.cnpaf.net/Class/SNIFFER/200812/23289.html</link>
    <description><![CDATA[早就听说过局域网的安全性有问题，但是也一直没放在心上，祥子是计算机专业毕业的，平时上网行为很规矩，从不上那些乱七八糟的网站，小方格子里有自己专用的电脑，里面装着网络版的杀毒软件，定时更新病毒库，系统里装着360安全卫生，系统的漏洞]]></description>
    <pubDate>2008-12-26</pubDate>
    <category>Sniffer</category>
    <author>秩名</author>
    <comments>IT168</comments>
</item>
<item>
    <title><![CDATA[使用wireshark找回遗忘管理地址问题]]></title>
    <link>http://www.cnpaf.net/Class/SNIFFER/200812/23288.html</link>
    <description><![CDATA[作为网络管理员的我们经常要针对路由器，交换机，VPN接入等网络设备进行配置，不知道各位是否遇到过忘记了设备管理地址的情况，也许你记得用户名和密码，但是要进行配置就必须访问管理界面，这个管理地址的丢失或遗忘却让我们束手无策。最近笔者就遇到了这么一个让人头]]></description>
    <pubDate>2008-12-26</pubDate>
    <category>Sniffer</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[迅雷协议分析]]></title>
    <link>http://www.cnpaf.net/Class/OtherAnalysis/200810/23085.html</link>
    <description><![CDATA[迅雷登陆验证 --TCP!来源标识.Data(53 Bytes) 00 00 00 35 00 00 00 4d 00 00 .........5...M.. 0040 00 4d 00 00 00 24 65 30 31 37 39 34 64 63 2d 33 .M...$e01794dc-3 0050 61 36 62 2d 34 32 39 39 2d 39 64 33 61 2d 37 38 a6b-4299-9d3a-78 0060 36 66 64 33 39]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>其它技术</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[中国移动飞信协议分析]]></title>
    <link>http://www.cnpaf.net/Class/OtherAnalysis/200810/23084.html</link>
    <description><![CDATA[登录 POST /nav/getsystemconfig.aspx HTTP/1.1 User-Agent: IIC2.0/PC 2.2.0230 Content-Type: application/x-www-form-urlencode; charset=utf-8 Host: nav.fetion.com.cn Content-Length: 75 Connection: Keep-Alive HTTP/1.1 100 Continue configclient type=PC ve]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>其它技术</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[最新QQ2008贺岁协议分析第三版]]></title>
    <link>http://www.cnpaf.net/Class/OtherAnalysis/200810/23080.html</link>
    <description><![CDATA[一、 QQ2008 Touch包0x91 a) 0x2aa8 客户端 原始数据： 02 11 5b 00 91 2a a8 38 25 f5 91 5d 4c af 65 54 44 6d 76 7b ff f0 14 73 e6 0a 95 9d 74 ce b3 b5 fd 61 1d 12 84 a5 04 53 3c b1 d4 f9 27 9c 7c 3f ef f0 bb 3c dc 3f 0f 25 ee 3d 7c 03 QQ2008包头： 02 1]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>其它技术</category>
    <author>Huang Guan</author>
    <comments>www.cnpaf.net</comments>
</item>
<item>
    <title><![CDATA[MSN协议分析]]></title>
    <link>http://www.cnpaf.net/Class/OtherAnalysis/200810/23079.html</link>
    <description><![CDATA[一、概要介绍 msn messenger通常使用端口1863进行通信（在实际中用sniff跟踪发现msn通信都是用1863端口进行通信的）。在msn messenger工作中，本机客户端与三种服务器通过协议进行通信和数据交换。（dispatch服务器、notification服务器tchboard服务器）。在本机客户端]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>其它技术</category>
    <author>秩名</author>
    <comments>本站论坛</comments>
</item>
<item>
    <title><![CDATA[SKYPE协议分析]]></title>
    <link>http://www.cnpaf.net/Class/OtherAnalysis/200810/23078.html</link>
    <description><![CDATA[1 、概述 Skype是由Kazaa于2003年发明的基于P2P 技术的VoIP客户端，用户可以通过Skype通过互联网进行语音和文本的传输。 Skype的通讯协议是不公开的，而且通讯内容是加过密的，哥伦比亚大学的Baset和Schulzrinne完全在实验的基础上对Skype的通讯机制 进行分析，通过分]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>其它技术</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[UDP穿透NAT的原理与实现之P2P篇]]></title>
    <link>http://www.cnpaf.net/Class/OtherAnalysis/200810/23063.html</link>
    <description><![CDATA[首先先介绍一些基本概念： NAT(Network Address Translators)，网络地址转换：网络地址转换是在IP地址日益缺乏的情况下产生的，它的主要目的就是为了能够地址重用。NAT分为两大类，基本的NAT和NAPT(Network Address/Port Translator)。 最开始NAT是运行在路由器上的一个]]></description>
    <pubDate>2008-10-21</pubDate>
    <category>其它技术</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Ethereal 抓包、封包內容分析、查看明码教学]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200810/23062.html</link>
    <description><![CDATA[Ethereal软体介绍 Ethereal 封包监听器，是一套网管人员必备的超强软体。举凡在网路故障排除，监听异常封包，软体封包问题检测等等问题，甚至包含针对网路通讯协定的教育训练，都可以利用这套免费的软体来做到。 Unix 及 Windows 平台封包撷]]></description>
    <pubDate>2008-10-21</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[在Windows下编译Ethereal(Wireshark)]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200810/23057.html</link>
    <description><![CDATA[最近在研究项目下一期中新增的信令跟踪功能，在这个开源盛行的时代，开源工具当然是首]]></description>
    <pubDate>2008-10-21</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用Sniffer分析ARP网络故障]]></title>
    <link>http://www.cnpaf.net/Class/SNIFFER/200810/23044.html</link>
    <description><![CDATA[电信网络内部一套112测试系统，涉及到一系列服务器和测试头(具有TCP/IP三层功能的终端)，原有的拓扑在电信内网(DCN)中。由于测试范围的扩大，有些机房没有内网接入点，变通的方案是在城域网上建立一个VPN，将那些没有DCN接入点的测试头设备接在此VPN上，然后此VPN通过]]></description>
    <pubDate>2008-10-18</pubDate>
    <category>Sniffer</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[SERV-U对Sniffer防范测试]]></title>
    <link>http://www.cnpaf.net/Class/SNIFFER/200810/23043.html</link>
    <description><![CDATA[SERV-U是一款很普及的FTP工具，利用其搭建FTP服务器非常简单。但是默认配置下SERV-U用21端口提供FTP服务，并且数据没有进行任何的加密是明文传递。因此，一个恶意用户可以通过sniffer工具获取FTP用户的帐户和密码。下面，我们部署环境进行SERV-U的Sniffer测试。 一、SE]]></description>
    <pubDate>2008-10-18</pubDate>
    <category>Sniffer</category>
    <author>秩名</author>
    <comments>IT专家网</comments>
</item>
<item>
    <title><![CDATA[WinPcap远程捕获内部结构与定义]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23040.html</link>
    <description><![CDATA[数据结构 struct activehosts Keeps a list of all the opened connections in the active mode. More... struct rpcap_header Common header for all the RPCAP messages. More... struct rpcap_findalldevs_if Format of the message for the interface description (]]></description>
    <pubDate>2008-10-17</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[WinPcap数据包驱动API-Packet.dll]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23039.html</link>
    <description><![CDATA[Packet.dll 是一个动态链接库，并提供了一些低层的函数，用来： 安装，启动和停止NPF设备驱动 从NPF驱动接收数据包 通过NPF驱动发送数据包 获取可用的网络适配器列表 获取适配器的不同信息，比如设备描述，地址列表和掩码 查询并设置一个低层的适配器参数 packet.dll有]]></description>
    <pubDate>2008-10-17</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[如何编译WinPcap]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23038.html</link>
    <description><![CDATA[编译驱动 编译NPF时，有两个主要的路径：Windows NTx和Windows 9x。注意，因为NPF驱动是与平台相关的，所以，为了连接正确的DDK库，我们强烈建议编译的时候，要选择将来会被使用的那个操作系统。比如，如果你使用Windows NT 4 DDK库赖编译驱动，那么在Windows2000或其他]]></description>
    <pubDate>2008-10-17</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[NPF驱动核心指南]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23037.html</link>
    <description><![CDATA[模块 NPF 结构与定义 NPF 函数 数据结构 struct binary_stream A stream of X86 binary code. More... struct JIT_BPF_Filter Structure describing a x86 filtering program created by the jitter. More... 定义 #define EAX 0 #define ECX 1 #define EDX 2 #define]]></description>
    <pubDate>2008-10-17</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[如何使用WinPcap收集并统计网络流量]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23021.html</link>
    <description><![CDATA[统计引擎利用了内核级的数据包过滤器，来有效地为收集到的数据包进行分类。如果你想阅读更多细节，请参阅 NPF驱动核心手册。 为了使用这个特性，编程人员必须打开一个适配器，并且，可以使用 pcap_setmode() 将它设置为统计模式(statistical mode)。特别注意，必须使用]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用WinPcap发送数据包]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23020.html</link>
    <description><![CDATA[尽管从 WinPcap 的名字上看，这个库的目标应该是数据捕捉(Packet Capture)，然而，它也提供了针对很多其它有用的特性。在其中，我们可以找到一组很完整的用于发送数据包的函数。 请注意：原始的libpcap库是不支持发送数据包的，因此，这里展示的函数都属于是WinPcap的扩]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[WinPcap处理脱机堆文件]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23019.html</link>
    <description><![CDATA[WinPcap提供了很多函数来将网络数据流保存到文件并读取它们 -- 本讲将教你如何使用这些函数。我们还将看到如何使用WinPcap内核堆特性来获取一个高性能的堆。(请注意：此时，由于一些有关新内核缓冲的问题，这些特性将无法使用) 堆文件的格式是libpcap的一种。这种格式]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[WinPcap分析数据包]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23018.html</link>
    <description><![CDATA[我们可以捕捉并过滤网络流量了，那就让我们学以致用，来做一个简单使用的程序吧。 在本讲中，我们将会利用上一讲的一些代码，来建立一个更实用的程序。 本程序的主要目标是展示如何解析所捕获的数据包的协议首部。这个程序可以称为UDPdump，打印一些网络上传输的UDP数]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用WinPcap过滤数据包]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23017.html</link>
    <description><![CDATA[WinPcap和Libpcap的最强大的特性之一，是拥有过滤数据包的引擎。 它提供了有效的方法去获取网络中的某些数据包，这也是WinPcap捕获机制中的一个组成部分。 用来过滤数据包的函数是 pcap_compile() 和 pcap_setfilter() 。 pcap_compile() 它将一个高层的布尔过滤表达式]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[不用回调方法使WinPcap可以捕获数据包]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23016.html</link>
    <description><![CDATA[pcap_loop()函数是基于回调的原理来进行数据捕获，这是一种精妙的方法，并且在某些场合中，它是一种很好的选择。 然而，处理回调有时候并不实用 -- 它会增加程序的复杂度，特别是在拥有多线程的C++程序中。 可以通过直接调用pcap_next_ex() 函数来获得一个数据包 -- 只]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[如何让WinPcap打开适配器并捕获数据包]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23015.html</link>
    <description><![CDATA[现在，我们已经知道如何获取适配器的信息了，那我们就开始一项更具意义的工作，打开适配器并捕获数据包。在这讲中，我们会编写一个程序，将每一个通过适配器的数据包打印出来。 打开设备的函数是 pcap_open()。下面是参数 snaplen, flags 和 to_ms 的解释说明 snaplen]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用WinPcap获取已安装设备的高级信息]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23014.html</link>
    <description><![CDATA[(在如何使用WinPcap获取设备列表) 我们展示了如何获取适配器的基本信息 (如设备的名称和描述)。 事实上，WinPcap提供了其他更高级的信息。 特别需要指出的是， 由 pcap_findalldevs_ex() 返回的每一个 pcap_if 结构体，都包含一个 pcap_addr 结构体，这个结构体由如下元]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用WinPcap获取设备列表]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23013.html</link>
    <description><![CDATA[通常，编写基于WinPcap应用程序的第一件事情，就是获得已连接的网络适配器列表。libpcap和WinPcap都提供了 pcap_findalldevs_ex() 函数来实现这个功能: 这个函数返回一个 pcap_if 结构的链表， 每个这样的结构都包含了一个适配器的详细信息。值得注意的是，数据域 name]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[如何使用WinPcap进行编程]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23012.html</link>
    <description><![CDATA[创建一个使用 wpcap.dll 的应用程序 用 Microsoft Visual C++ 创建一个使用 wpcap.dll 的应用程序，需要按一下步骤： 在每一个使用了库的源程序中，将 pcap.h 头文件包含(include)进来。 如果你在程序中使用了WinPcap中提供给Win32平台的特有的函数， 记得在预处理中加]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[WinPcap过滤串表达式的语法]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23011.html</link>
    <description><![CDATA[注意：这篇文档取自tcpdump的指南。原始的版本 www.tcpdump.org 找到。 wpcap的过滤器是以已声明的谓词语法为基础的。过滤器是一个ASCII字符串，它包含了一个过滤表达式。pcap_compile()把这个表达式编译成内核级的包过滤器。 这个表达式会选择那些数据包将会被堆存。]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[WinPcap与Unix兼容的函数]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23010.html</link>
    <description><![CDATA[这些函数是libpcap库的一部分，因此，既能运行在Windows平台，也能运行于Linux平台。 注意： 在函数 pcap_open_live(), pcap_open_dead(), pcap_open_offline(), pcap_setnonblock(), pcap_getnonblock(), pcap_findalldevs(), pcap_lookupdev(), 和 pcap_lookupnet()]]></description>
    <pubDate>2008-10-16</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Winpcap的内部结构]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200810/23000.html</link>
    <description><![CDATA[Winpcap是针对Win32平台上的抓包和网络分析的一个架构。它包括一个核心态的包过滤器，一个底层的动态链接库（packet.dll）和一个高层的不以来于系统的库（wpcap.dll）。 为什么使用architecture而不是library呢？因为抓包是一个要求与网络适配器（网卡）和操作系统交互]]></description>
    <pubDate>2008-10-07</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[借助Sniffer分析网络流量]]></title>
    <link>http://www.cnpaf.net/Class/SNIFFER/200611/19090.html</link>
    <description><![CDATA[各位做维护的同事经常会听到用户对网速太慢的抱怨，但是网速慢的原因有很多，比如软件设置不当，网络设备故障，物理链路问题，感染病毒等，而单单从用户的故障描述里面很难有进一步的发现，所以也许大家一时也不知道从何下手。 Sniffer是一个非常好的流量分析工具，利]]></description>
    <pubDate>2006-11-08</pubDate>
    <category>Sniffer</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[利用WinPcap技术捕获数据包]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200611/18783.html</link>
    <description><![CDATA[前言 随着网络入侵的不断发展，网络安全变得越来越重要，于是网络入侵取证系统的研究也变得日益重要。在网络入侵取证系统中，对网络上传送的数据包进行有效的监听即捕获包是目前取证的关键技术，只有进行高效的数据包捕获，网络管理员才能对所捕获的数据进行一系列的分]]></description>
    <pubDate>2006-11-14</pubDate>
    <category>Winpcap</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Ethereal在Win32下的开发环境建立过程]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200611/18771.html</link>
    <description><![CDATA[SETUPENVIRONMENT 1.DownloadtheDeveloper’sGuidefromEthereal’swebsite(http://www.ethereal.com/).Itisanimportantkeytostartdevelopprogressforthefirsttime: a)Openhttp://www.ethereal.com/docs/; b)ChoosefavoriteDeveloper’sGuideformattodownload; 2.(Recomm]]></description>
    <pubDate>2006-11-07</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Ethereal支持的常用协议端口号]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200611/18770.html</link>
    <description><![CDATA[TCP协议支持 协议名称 TCP端口号 协议名称解释 ACAP 674 AIM 5190 BEEP 10288 CAST 4224 CMP 829 COPS 3288 PKTCABLE_COPS 2126 PKTCABLE_MM_COPS 3918 DAAP 3689 DHCPFO 519 DIAMETER 3868 DISTCC 3632 DLSW 2065 NP 20000 NS 53 DNS 5353 DSI 548 FTPDATA 20 FTP 21]]></description>
    <pubDate>2006-11-07</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Ethereal Capture Options详解]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200611/18769.html</link>
    <description><![CDATA[Options： Interface:选择采集数据包的网卡 IPaddress:选择的网卡所对应的IP地址 Link-layerheadertype:数据链路层的协议，在以太网中一般是EthernetII Buffersize:数据缓存大小设定，默认是1M字节 Capturepacketsinpromiscuousmode:设定在混杂模式下捕获数据，如果不选]]></description>
    <pubDate>2006-11-07</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用Ethereal分析协议数据包]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200611/18294.html</link>
    <description><![CDATA[一、Ethereal：网络数据嗅探器软件 Ethereal是当前较为流行的一种计算机网络调试和数据包嗅探软件。Ethereal基本类似于tcpdump，但Ethereal还具有设计完美的GUI和众多分类信息及过滤选项。用户通过Ethereal，同时将网卡插入混合模式，可以查看到网络中发送的所有通信流]]></description>
    <pubDate>2006-11-01</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[范伟老师的Sniffer培训课程资料]]></title>
    <link>http://www.cnpaf.net/Class/SNIFFER/200610/16702.html</link>
    <description><![CDATA[前言: 范老师现在是Sniffer中国技术服务中心的技术总监，是中国唯一的Sniffer大师（SCM），他有丰富的经验和经典案例，讲课讲得不错。 我是范老师的学生，我2005年学习了Sniffer，发现收获很大，但我不能透露我的单位，因为我想范老师不会允许我把他的讲课内容公开。]]></description>
    <pubDate>2006-10-31</pubDate>
    <category>Sniffer</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[使用Ethereal学习TCP/IP协议]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200610/16498.html</link>
    <description><![CDATA[实验环境搭建： 操作系统为Windows2000 server 版，因为在寝室里只有一台电脑，而且没有网卡（只有一个56K 的老猫），所以安装了虚拟机VMware-workstation（ 网上很多地方可以下载，这里就不提供下载了，安装也很简单）； 虚拟操作系统是RedHat 8.0 ，为了节省空间和加]]></description>
    <pubDate>2006-10-27</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Ethereal软件下载与安装手册]]></title>
    <link>http://www.cnpaf.net/Class/Ethereal/200610/16497.html</link>
    <description><![CDATA[Ethereal网址:http://www.ethereal.com/ 到Ethereal的站站后，点击download，接着选择要安装的系统平台，如Windows或Linux，然后点击下载链接即可进行下载(例如Mainsite或Mirrorsite)。 Ethereal的安装非常简单，只要执行ethereal-setup-x.y.z.exe即可。安装过程如下:]]></description>
    <pubDate>2006-10-26</pubDate>
    <category>Ethereal</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(九)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16307.html</link>
    <description><![CDATA[这一节将展示WinPcap的另一高级功能：收集网络流量的统计信息。WinPcap的统计引擎在内核层次上对到来的数据进行分类。如果你想了解更多的细节请查看NPF驱动指南。 这一节将展示WinPcap的另一高级功能：收集网络流量的统计信息。WinPcap的统计引擎在内核层次上对到来的]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(八)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16306.html</link>
    <description><![CDATA[尽管WinPcap从名字上来看表明他的主要目的是捕获数据包，但是他还为原始网络提供了一些其他的功能，其中之一就是用户可以发送数据包，这也就是本节的主要内容。 尽管WinPcap从名字上来看表明他的主要目的是捕获数据包，但是他还为原始网络提供了一些其他的功能，其中]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(七)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16305.html</link>
    <description><![CDATA[通过以前的学习我门已经熟悉了从网卡上捕获数据包，现在我门将学习如何处理数据包。WINPCAP为我们提供了很多API来将流经网络的数据包保存到一个堆文件并读取堆的内容。这一节将讲述如何使用所有的这些API。 这种文件的格式很简单，但包含了所捕获的数据报的二进制内容]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(六)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16304.html</link>
    <description><![CDATA[现在经过上几节的学习能够进行数据报的捕获和过滤了，我们想用一个简单的realworld程序将我们所学的知识应用于实际。 现在经过上几节的学习能够进行数据报的捕获和过滤了，我们想用一个简单的realworld程序将我们所学的 知识应用于实际。 这一节里我们将利用以前的代码]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(五)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16303.html</link>
    <description><![CDATA[WinPcap或libpca最强大的特点之一就是数据流的过滤引擎。它提供一种高效的方法来只捕获网络数据流的某些数据而且常常和系统的捕获机制相集成。过滤数据的函数是pcap_compile()和pcap_setfilter()来实现的。 WinPcap或libpca最强大的特点之一就是数据流的过滤引擎。它提]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(四)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16302.html</link>
    <description><![CDATA[这一节中是用pcap_next_ex()来代替pcap_loop()来捕获数据包 这节的例子很象先前的一章（获得网卡的高级信息）但是这一节中是用pcap_next_ex()来代替pcap_loop()来捕 获数据包。基于回调包捕获机制的pcap_loop()在某些情况下是不错的选择。但是在一些情况下处理回调并不]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(三)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16301.html</link>
    <description><![CDATA[打开网卡并捕获数据流。。。。 现在我门已经知道了如何去获得网卡的信息现在就让我们开始真正的工作：打开网卡并捕获数据流。在这一节 里我们将写一个打印流经网络的每个数据包信息的程序。打开网卡的功能是通过pcap_open_live()来实现的它 有三个参数snaplenpromiscto]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(二)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16300.html</link>
    <description><![CDATA[在第一章中演示了如何获得已存在适配器的静态信息 在第一章中演示了如何获得已存在适配器的静态信息。实际上WinPcap同样也提供其他的高级信息，特别是pcap_findalldevs()这个函数返回的每个pcap_if结构体都同样包含一个pcap_addr结构的列表，他包含： 一个地址列表，一]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[循序渐进学习使用WINPCAP(一)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16299.html</link>
    <description><![CDATA[一些需要知道的细节描述（前言）： 这一部分展示了如何使用WINPCAP-API的不同的功能，它作为一个使用指南被划分为一系列的课时来带领读者循序渐进的体会PCAP的程序设计的 魅力：从简单的基本功能（如获取网卡的列表，数据包的捕获等）到统计和收集网络流量等高级功能。]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[WinpCap学习笔记(7)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16298.html</link>
    <description><![CDATA[Winpcap的内部结构 这是引自winpcap主页上的一句话： WinPcapisanarchitectureforpacketcaptureandnetworkanalysisfortheWin32platforms.Itincludesakernel-levelpacketfilter,alow-leveldynamiclinklibrary(packet.dll),andahigh-levelandsystem-independentlibrary(w]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>
<item>
    <title><![CDATA[WinpCap学习笔记(6)]]></title>
    <link>http://www.cnpaf.net/Class/winpcap/200610/16297.html</link>
    <description><![CDATA[尽管Winpcap清楚地指出了它的目的是数据包的截获，但是它还提供了一些对于原始网络（rawnetworking）的有用特性。用户可以找到一组完整的发包（sendpackets）函数。需要注意的是，libpcap目前并没有提供任何的发包的方法。 用pcap_sendpacket()发送单个数据包 下面的代]]></description>
    <pubDate>2006-10-16</pubDate>
    <category>Winpcap</category>
    <author>binaryluo</author>
    <comments>binaryluo的博客</comments>
</item>

</channel>
</rss>
