(As translated by Google): I'm sorry, my English is not very good, and we can only write Chinese. Use wireshark process, I encountered a problem, is that I would like to set up filters in Ethereal before, only to grab the HTTP protocol packet, why when I set the NIC to input HTTP is shown by the color filter conditions this means that the settings wrong, but can enter the TCP like. I would like to ask what reason?

Sounds like a display filter versus capture filter question.

(17 Dec '12, 23:53) Jaap ♦

您可以不使用 HTTP作为捕捉过滤器,因为这不是一个有效的libpcap的过滤器语法。而 TCP是一个有效的过滤器。



此致 库尔特

You cannot use http as a capture filter, as that is not a valid libpcap filter syntax. whereas tcp is a valid filter.

See here:

Please use this filter instead: tcp port 80


如果使用tcp port 80这个过滤语法的话,那么他只能抓取经过80端口的HTTP协议哦,如果有些HTTP协调不是通过80端口的又要怎么抓呢?

(18 Dec '12, 17:16) jun

这个要用 高级过滤器才行

抓Http GET 或者 HEAD (80 可以改为任意) tshark 'tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)' -R 'http.request.method == "GET" || http.request.method == "HEAD"

PS:LZ 怎么跑这里来问了 ?

那个高级过滤器要另外安装吗? 不在问在那里问,还有中文版的论坛吗?

(18 Dec '12, 23:49) jun



Can you please repeat the question about installing the filter?

There is no chinese version of this site. I suggest to ask in english (ask a colleague of yours), as Google translate adds some errors, which makes communication somewhat hard.

(19 Dec '12, 00:27) Kurt Knochner ♦

