{"id":41103,"date":"2025-05-31T06:02:42","date_gmt":"2025-05-30T22:02:42","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/41103.html"},"modified":"2025-05-31T06:02:42","modified_gmt":"2025-05-30T22:02:42","slug":"wireshark-%e5%9c%a8-macos-%e4%b8%8a%e4%bd%bf%e7%94%a8%e5%8f%8a%e9%97%ae%e9%a2%98%e8%a7%a3%e5%86%b3","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/41103.html","title":{"rendered":"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3"},"content":{"rendered":"<h4>wireshark\u6982\u8ff0<\/h4>\n<p>Wireshark \u662f\u88ab\u5e7f\u6cdb\u4f7f\u7528\u7684\u514d\u8d39\u5f00\u6e90\u7f51\u7edc\u534f\u8bae\u5206\u6790\u8f6f\u4ef6&#xff08;network protocol analyzer&#xff09;\u6216\u7f51\u7edc\u6570\u636e\u5305\u5206\u6790\u5de5\u5177&#xff0c;\u5b83\u53ef\u4ee5\u8ba9\u4f60\u5728\u5fae\u89c2\u5c42\u9762\u4e0a\u67e5\u770b\u7f51\u7edc\u4e0a\u53d1\u751f\u7684\u4e8b\u60c5\u3002\u5b83\u7684\u4e3b\u8981\u529f\u80fd\u662f\u622a\u53d6\u7f51\u7edc\u6570\u636e\u5305&#xff0c;\u5e76\u5c3d\u53ef\u80fd\u8be6\u7ec6\u5730\u5c55\u793a\u7f51\u7edc\u6570\u636e\u5305\u4fe1\u606f\u5185\u5bb9\u3002<\/p>\n<p>\u9879\u76ee\u5730\u5740&#xff1a;https:\/\/github.com\/wireshark\/wireshark<\/p>\n<p>\u672c\u7bc7\u6587\u7ae0\u4e3b\u8981\u8bb2\u8ff0\u5728 Mac \u4f7f\u7528 Wireshark \u65f6\u53ef\u80fd\u9047\u5230\u7684\u4e00\u4e9b\u95ee\u9898&#xff0c;\u5e76\u901a\u8fc7\u4e00\u4e2a\u5b9e\u4f8b\u4ecb\u7ecd\u8be6\u7ec6\u7684\u6293\u5305\u624b\u6cd5\u3002<\/p>\n<h4>\u5e38\u89c1\u95ee\u9898<\/h4>\n<h5>\u6293\u5305\u62a5\u9519<\/h5>\n<h6>\u62a5\u9519\u4fe1\u606f<\/h6>\n<p>You do not have permission to capture on device &#034;bridge100&#034;. ((cannot open BPF device) \/dev\/bpf0: Permission denied)<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220232-683a2af8e0688.png\" alt=\"\" \/><\/p>\n<h6>\u89e3\u51b3\u529e\u6cd5<\/h6>\n<p>\u67e5\u770b \/dev\/bpf* \u6587\u4ef6\u7684\u6743\u9650<\/p>\n<p><span class=\"token function\">ls<\/span> <span class=\"token parameter variable\">-l<\/span> \/dev\/bpf*<\/p>\n<p>\u66f4\u65b0 \/dev\/bpf* \u6587\u4ef6\u6743\u9650\u548c\u7ec4\u6743\u9650<\/p>\n<p><span class=\"token function\">sudo<\/span> <span class=\"token function\">chmod<\/span> g&#043;r \/dev\/bpf* <span class=\"token operator\">&amp;&amp;<\/span> <span class=\"token function\">sudo<\/span> <span class=\"token function\">chgrp<\/span> admin \/dev\/bpf*<\/p>\n<h5>\u7f51\u5361\u592a\u591a<\/h5>\n<p>\u4f7f\u7528 ifconfig \u547d\u4ee4\u53ef\u4ee5\u67e5\u770b\u5230 Mac \u4e2d\u7684\u6240\u6709\u7f51\u7edc\u63a5\u53e3&#xff0c;\u53ef\u80fd\u4f1a\u51fa\u73b0\u6570\u91cf\u7e41\u591a&#xff0c;\u4e0d\u6e05\u695a\u9009\u54ea\u4e2a\u7684\u95ee\u9898\u3002<\/p>\n<p>\u5148\u6765\u770b\u770b\u6211\u7684\u7f51\u5361\u4fe1\u606f\u3002<\/p>\n<p>$ ifconfig<br \/>\nlo0: flags&#061;8049&lt;UP,LOOPBACK,RUNNING,MULTICAST&gt; mtu 16384<br \/>\n        options&#061;1203&lt;RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP&gt;<br \/>\n        inet 127.0.0.1 netmask 0xff000000<br \/>\n        inet6 ::1 prefixlen 128<br \/>\n        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\ngif0: flags&#061;8010&lt;POINTOPOINT,MULTICAST&gt; mtu 1280<br \/>\nstf0: flags&#061;0&lt;&gt; mtu 1280<br \/>\nanpi1: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;400&lt;CHANNEL_IO&gt;<br \/>\n        ether e2:5d:00:2d:ee:ec<br \/>\n        media: none<br \/>\n        status: inactive<br \/>\nanpi0: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;400&lt;CHANNEL_IO&gt;<br \/>\n        ether e2:5d:00:2d:ee:eb<br \/>\n        media: none<br \/>\n        status: inactive<br \/>\nen3: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;400&lt;CHANNEL_IO&gt;<br \/>\n        ether e2:5d:00:2d:ee:cb<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: none<br \/>\n        status: inactive<br \/>\nen4: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;400&lt;CHANNEL_IO&gt;<br \/>\n        ether e2:5d:00:2d:ee:cc<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: none<br \/>\n        status: inactive<br \/>\nen1: flags&#061;8963&lt;UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;460&lt;TSO4,TSO6,CHANNEL_IO&gt;<br \/>\n        ether 36:b2:2d:e4:95:80<br \/>\n        media: autoselect &lt;full-duplex&gt;<br \/>\n        status: inactive<br \/>\nen2: flags&#061;8963&lt;UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;460&lt;TSO4,TSO6,CHANNEL_IO&gt;<br \/>\n        ether 36:b2:2d:e4:95:84<br \/>\n        media: autoselect &lt;full-duplex&gt;<br \/>\n        status: inactive<br \/>\nbridge0: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;63&lt;RXCSUM,TXCSUM,TSO4,TSO6&gt;<br \/>\n        ether 36:b2:2d:e4:95:80<br \/>\n        Configuration:<br \/>\n                id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0<br \/>\n                maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200<br \/>\n                root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0<br \/>\n                ipfilter disabled flags 0x0<br \/>\n        member: en1 flags&#061;3&lt;LEARNING,DISCOVER&gt;<br \/>\n                ifmaxaddr 0 port 8 priority 0 path cost 0<br \/>\n        member: en2 flags&#061;3&lt;LEARNING,DISCOVER&gt;<br \/>\n                ifmaxaddr 0 port 9 priority 0 path cost 0<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: &lt;unknown type&gt;<br \/>\n        status: inactive<br \/>\nap1: flags&#061;8802&lt;BROADCAST,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;400&lt;CHANNEL_IO&gt;<br \/>\n        ether 3e:57:dc:50:21:95<br \/>\n        media: autoselect<br \/>\nen0: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;6460&lt;TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM&gt;<br \/>\n        ether 1c:57:dc:50:21:95<br \/>\n        inet6 fe80::493:9294:92cb:962d%en0 prefixlen 64 secured scopeid 0xc<br \/>\n        inet 10.201.102.126 netmask 0xffffe000 broadcast 10.201.127.255<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: autoselect<br \/>\n        status: active<br \/>\nawdl0: flags&#061;8843&lt;UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;6460&lt;TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM&gt;<br \/>\n        ether ce:41:0d:0a:06:8b<br \/>\n        inet6 fe80::cc41:dff:fe0a:68b%awdl0 prefixlen 64 scopeid 0xd<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: autoselect<br \/>\n        status: active<br \/>\nllw0: flags&#061;8863&lt;UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;400&lt;CHANNEL_IO&gt;<br \/>\n        ether ce:41:0d:0a:06:8b<br \/>\n        inet6 fe80::cc41:dff:fe0a:68b%llw0 prefixlen 64 scopeid 0xe<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: autoselect<br \/>\n        status: inactive<br \/>\nutun0: flags&#061;8051&lt;UP,POINTOPOINT,RUNNING,MULTICAST&gt; mtu 1380<br \/>\n        inet6 fe80::bbb3:6daa:deb9:6132%utun0 prefixlen 64 scopeid 0xf<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\nutun1: flags&#061;8051&lt;UP,POINTOPOINT,RUNNING,MULTICAST&gt; mtu 2000<br \/>\n        inet6 fe80::a590:7109:be1b:f900%utun1 prefixlen 64 scopeid 0x10<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\nutun2: flags&#061;8051&lt;UP,POINTOPOINT,RUNNING,MULTICAST&gt; mtu 1000<br \/>\n        inet6 fe80::ce81:b1c:bd2c:69e%utun2 prefixlen 64 scopeid 0x11<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\nutun3: flags&#061;8051&lt;UP,POINTOPOINT,RUNNING,MULTICAST&gt; mtu 1500<br \/>\n        inet6 fe80::4562:973c:823c:162d%utun3 prefixlen 64 scopeid 0x12<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\nutun4: flags&#061;8051&lt;UP,POINTOPOINT,RUNNING,MULTICAST&gt; mtu 9000<br \/>\n        inet 198.18.0.1 &#8211;&gt; 198.18.0.1 netmask 0xfffe0000<br \/>\nvmenet0: flags&#061;8963&lt;UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        ether 3e:64:95:b7:62:33<br \/>\n        media: autoselect<br \/>\n        status: active<br \/>\nbridge100: flags&#061;8a63&lt;UP,BROADCAST,SMART,RUNNING,ALLMULTI,SIMPLEX,MULTICAST&gt; mtu 1500<br \/>\n        options&#061;3&lt;RXCSUM,TXCSUM&gt;<br \/>\n        ether 1e:57:dc:05:87:64<br \/>\n        inet 192.168.64.1 netmask 0xffffff00 broadcast 192.168.64.255<br \/>\n        inet6 fe80::1c57:dcff:fe05:8764%bridge100 prefixlen 64 scopeid 0x15<br \/>\n        inet6 fd93:45e9:560c:404:1020:f068:469e:d583 prefixlen 64 autoconf secured<br \/>\n        Configuration:<br \/>\n                id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0<br \/>\n                maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200<br \/>\n                root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0<br \/>\n                ipfilter disabled flags 0x0<br \/>\n        member: vmenet0 flags&#061;3&lt;LEARNING,DISCOVER&gt;<br \/>\n                ifmaxaddr 0 port 20 priority 0 path cost 0<br \/>\n        nd6 options&#061;201&lt;PERFORMNUD,DAD&gt;<br \/>\n        media: autoselect<br \/>\n        status: active<br \/>\n(base) <\/p>\n<h6>\u5982\u4f55\u9009\u7f51\u5361<\/h6>\n<p>\u5728\u4f17\u591a\u7f51\u5361\u4e2d&#xff0c;\u91cd\u70b9\u5173\u6ce8 en0 \u548c bridge100 \u8fd9\u4e24\u4e2a\u63a5\u53e3&#xff0c;\u5176\u4ed6\u591a\u6570\u53ef\u4ee5\u5ffd\u7565\u3002<\/p>\n<table>\n<tr>\u63a5\u53e3\u540d\u542b\u4e49 \/ \u4f5c\u7528IP \u5730\u5740\u72b6\u6001<\/tr>\n<tbody>\n<tr>\n<td>lo0<\/td>\n<td>\u672c\u5730\u56de\u73af\u63a5\u53e3&#xff08;localhost&#xff09;<\/td>\n<td>127.0.0.1<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>en0<\/td>\n<td>\u65e0\u7ebf\u7f51\u5361\u6216\u4e3b\u8981\u7269\u7406\u7f51\u5361<\/td>\n<td>10.201.102.126<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>bridge100<\/td>\n<td>Docker \u521b\u5efa\u7684\u865a\u62df\u6865\u63a5\u7f51\u5361<\/td>\n<td>192.168.64.1<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>awdl0<\/td>\n<td>Apple Wireless Direct Link&#xff0c;\u9694\u7a7a\u6295\u9001\u7528<\/td>\n<td>\u6709 IPv6<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>utun*<\/td>\n<td>VPN \u96a7\u9053\u63a5\u53e3&#xff08;\u4e00\u822c\u662f VPN \u8fde\u63a5\u521b\u5efa\u7684&#xff09;<\/td>\n<td>\u6709 IPv6<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>vmenet0<\/td>\n<td>\u865a\u62df\u673a\u7f51\u7edc\u6865\u63a5\u63a5\u53e3&#xff08;\u5982 VMware \u6216 UTM&#xff09;<\/td>\n<td>\u65e0 IPv4<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>en1\/en2\/en3&#8230;<\/td>\n<td>\u5176\u4ed6\u7269\u7406\u6216\u865a\u62df\u7f51\u5361<\/td>\n<td>\u65e0 IPv4<\/td>\n<td>\u274c \u591a\u6570 inactive<\/td>\n<\/tr>\n<tr>\n<td>anpi0\/anpi1<\/td>\n<td>Apple Silicon \u7279\u6709\u63a5\u53e3<\/td>\n<td>\u65e0 IP<\/td>\n<td>\u274c inactive<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>\u6293\u5305\u5b9e\u4f8b<\/h4>\n<p>\u672c\u4f8b\u7528\u4e8e\u5206\u6790\u5728\u6f0f\u6d1e\u590d\u73b0\u6216\u653b\u51fb\u68c0\u6d4b\u4e2d\u6355\u83b7\u7684\u6570\u636e\u6d41\u91cf&#xff0c;\u6b65\u9aa4\u5982\u4e0b&#xff1a;<\/p>\n<h6>\u786e\u5b9a\u9776\u673a IP<\/h6>\n<p>\u53ef\u4ee5\u901a\u8fc7\u67e5\u770b\u9776\u673a&#xff08;\u5982\u865a\u62df\u673a&#xff09;\u4e2d\u7684 IP \u5730\u5740\u83b7\u53d6\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220233-683a2af911ee3.png\" alt=\"\" \/><\/p>\n<h6>\u5224\u65ad\u54ea\u4e2a\u7f51\u5361\u53ef\u4ee5\u8bbf\u95ee\u9776\u673a<\/h6>\n<p>\u5728\u672c\u673a ifconfig \u4e2d\u627e\u5230\u80fd\u8bbf\u95ee\u9776\u673a IP \u7684\u7f51\u5361&#xff0c;\u4e00\u822c\u4e3a bridge100\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220235-683a2afbf0237.png\" alt=\"\" \/><\/p>\n<h6>\u5728 Wireshark \u4e2d\u9009\u62e9\u8be5\u7f51\u5361\u8fdb\u884c\u6293\u5305<\/h6>\n<p>\u542f\u52a8 Wireshark&#xff0c;\u9009\u62e9\u5bf9\u5e94\u7684 bridge100 \u7f51\u5361&#xff0c;\u70b9\u51fb\u5f00\u59cb\u6293\u5305\u5373\u53ef\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220237-683a2afd96a52.png\" alt=\"\" \/><\/p>\n<p>\u5982\u56fe\u8fd9\u662f\u6211\u6293\u7684\u5de5\u5177\u653b\u51fb\u7684\u6d41\u91cf\u6570\u636e&#xff0c;\u8fd9\u6837\u5c31\u53ef\u4ee5\u5355\u72ec\u62ff\u51fa\u6765\u5206\u6790\u4e86\u3002 <img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220238-683a2afe2527f.png\" alt=\"\" \/><\/p>\n<h4>wireshrk\u547d\u4ee4\u901f\u67e5<\/h4>\n<h6>IP \u5730\u5740\u8fc7\u6ee4<\/h6>\n<ul>\n<li>ip.src &#061;&#061; 192.168.1.107&#xff1a;\u6765\u6e90 IP \u662f 192.168.1.107<\/li>\n<li>ip.dst &#061;&#061; 192.168.1.107&#xff1a;\u76ee\u6807 IP \u662f 192.168.1.107<\/li>\n<li>ip.addr &#061;&#061; 192.168.1.107&#xff1a;\u6765\u6e90\u6216\u76ee\u6807 IP \u662f\u8be5\u5730\u5740<\/li>\n<\/ul>\n<h6>\u7aef\u53e3\u8fc7\u6ee4<\/h6>\n<ul>\n<li>tcp.port &#061;&#061; 80&#xff1a;\u6765\u6e90\u6216\u76ee\u6807 TCP \u7aef\u53e3\u4e3a 80<\/li>\n<li>tcp.srcport &#061;&#061; 80&#xff1a;\u6765\u6e90\u7aef\u53e3\u4e3a 80<\/li>\n<li>tcp.dstport &#061;&#061; 80&#xff1a;\u76ee\u6807\u7aef\u53e3\u4e3a 80<\/li>\n<li>udp.port &#061;&#061; 15000&#xff1a;UDP \u4efb\u610f\u7aef\u53e3\u4e3a 15000<\/li>\n<li>tcp.port &gt;&#061; 1 and tcp.port &lt;&#061; 80&#xff1a;TCP \u7aef\u53e3\u8303\u56f4\u8fc7\u6ee4<\/li>\n<\/ul>\n<h6>\u534f\u8bae\u8fc7\u6ee4<\/h6>\n<ul>\n<li>tcp\/ udp\/ icmp\/ http\/ dns\/ ftp\/ ssl<\/li>\n<li>not arp\/!arp&#xff1a;\u6392\u9664 ARP \u5305<\/li>\n<\/ul>\n<h6>MAC \u5730\u5740\u8fc7\u6ee4<\/h6>\n<ul>\n<li>eth.src &#061;&#061; A0:00:00:04:C5:84&#xff1a;\u6765\u6e90 MAC<\/li>\n<li>eth.dst &#061;&#061; A0:00:00:04:C5:84&#xff1a;\u76ee\u6807 MAC<\/li>\n<li>eth.addr &#061;&#061; A0:00:00:04:C5:84&#xff1a;\u4efb\u610f MAC&#xff08;\u6e90\u6216\u76ee\u7684&#xff09;<\/li>\n<\/ul>\n<h6>\u5305\u957f\u5ea6\u8fc7\u6ee4<\/h6>\n<ul>\n<li>udp.length &#061;&#061; 26&#xff1a;UDP \u6570\u636e\u957f\u5ea6<\/li>\n<li>tcp.len &gt;&#061; 7&#xff1a;TCP \u8d1f\u8f7d\u957f\u5ea6<\/li>\n<li>ip.len &#061;&#061; 94&#xff1a;IP \u5c42\u957f\u5ea6<\/li>\n<li>frame.len &#061;&#061; 119&#xff1a;\u6574\u4e2a\u6570\u636e\u5e27\u957f\u5ea6<\/li>\n<\/ul>\n<h6>HTTP \u8fc7\u6ee4<\/h6>\n<h6>\u6309\u65b9\u6cd5<\/h6>\n<ul>\n<li>http.request.method &#061;&#061; \u201cGET\u201d<\/li>\n<li>http.request.method &#061;&#061; \u201cPOST\u201d<\/li>\n<\/ul>\n<h6>\u6309\u5185\u5bb9<\/h6>\n<ul>\n<li>http contains \u201cGET\u201d&#xff1a;\u5305\u542b GET \u5b57\u7b26\u4e32<\/li>\n<li>http contains \u201cHTTP\/1.1 200 OK\u201d&#xff1a;HTTP \u6210\u529f\u54cd\u5e94<\/li>\n<\/ul>\n<h6>TCP \u53c2\u6570\u8fc7\u6ee4<\/h6>\n<ul>\n<li>tcp.flags.syn &#061;&#061; 1&#xff1a;TCP SYN \u5305<\/li>\n<li>tcp.window_size &#061;&#061; 0 and tcp.flags.reset !&#061; 1<\/li>\n<\/ul>\n<h6>\u6570\u636e\u5185\u5bb9\u8fc7\u6ee4&#xff08;\u8fdb\u9636&#xff09;<\/h6>\n<h6>UDP&#xff1a;<\/h6>\n<ul>\n<li>udp[8:3] &#061;&#061; 20:21:22&#xff1a;UDP payload \u524d3\u5b57\u8282\u4e3a\u6307\u5b9a\u503c<\/li>\n<li>udp contains 7c:7c:7d:7d&#xff1a;\u5305\u542b\u4efb\u610f\u4f4d\u7f6e\u5339\u914d\u5185\u5bb9<\/li>\n<\/ul>\n<h6>TCP&#xff1a;<\/h6>\n<ul>\n<li>tcp[20:3] &#061;&#061; 47:45:54&#xff1a;\u7b49\u4ef7\u4e8e tcp[20:3] &#061;&#061; \u201cGET\u201d&#xff08;ASCII&#xff09;<\/li>\n<li>tcp[20:] matches \u201c^GET.*HTTP\/1.1\\\\x0d\\\\x0a\u201d&#xff1a;\u7528\u6b63\u5219\u5339\u914d\u5b8c\u6574 GET \u8bf7\u6c42<\/li>\n<\/ul>\n<h6>\u6b63\u5219\u5339\u914d\u8bed\u6cd5\u901f\u67e5<\/h6>\n<table>\n<tr>\u8868\u8fbe\u5f0f\u8bf4\u660e<\/tr>\n<tbody>\n<tr>\n<td>\\\\d<\/td>\n<td>\u6570\u5b57\u5b57\u7b26<\/td>\n<\/tr>\n<tr>\n<td>\\\\D<\/td>\n<td>\u975e\u6570\u5b57<\/td>\n<\/tr>\n<tr>\n<td>\\\\w<\/td>\n<td>\u5355\u8bcd\u5b57\u7b26 (\u5b57\u6bcd\u3001\u6570\u5b57\u3001\u4e0b\u5212\u7ebf)<\/td>\n<\/tr>\n<tr>\n<td>\\\\s<\/td>\n<td>\u7a7a\u767d\u5b57\u7b26<\/td>\n<\/tr>\n<tr>\n<td>.<\/td>\n<td>\u4efb\u610f\u5b57\u7b26<\/td>\n<\/tr>\n<tr>\n<td>.*<\/td>\n<td>\u4efb\u610f\u6570\u91cf\u4efb\u610f\u5b57\u7b26&#xff08;\u9664\u6362\u884c&#xff09;<\/td>\n<\/tr>\n<tr>\n<td>^<\/td>\n<td>\u5b57\u7b26\u4e32\u5f00\u5934<\/td>\n<\/tr>\n<tr>\n<td>$<\/td>\n<td>\u5b57\u7b26\u4e32\u7ed3\u5c3e<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u4f8b\u5b50&#xff1a;<\/p>\n<ul>\n<li>tcp[20:] matches &#034;^GET.*&#034;&#xff1a;\u5339\u914d\u4ee5 GET \u5f00\u5934\u7684 TCP \u6570\u636e<\/li>\n<li>udp[8:] matches &#034;\\\\\\\\x14\\\\\\\\x05&#034;&#xff1a;\u5339\u914d\u7279\u5b9a\u5b57\u8282\u5e8f\u5217<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb826\u6b21\uff0c\u70b9\u8d5e27\u6b21\uff0c\u6536\u85cf15\u6b21\u3002\u672c\u6587\u4ecb\u7ecd\u4e86\u5728 macOS \u4e0a\u4f7f\u7528 Wireshark \u8fdb\u884c\u7f51\u7edc\u6293\u5305\u7684\u5b8c\u6574\u6d41\u7a0b\uff0c\u5305\u62ec\u5b89\u88c5\u65b9\u6cd5\u3001\u6743\u9650\u914d\u7f6e\u3001\u6293\u5305\u63a5\u53e3\u9009\u62e9\u3001\u8fc7\u6ee4\u89c4\u5219\u8bbe\u7f6e\u53ca\u5e38\u89c1\u534f\u8bae\u5206\u6790\uff0c\u9002\u5408\u521d\u5b66\u8005\u5feb\u901f\u4e0a\u624b\u7f51\u7edc\u6570\u636e\u5206\u6790\u3002<\/p>\n","protected":false},"author":2,"featured_media":41098,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[330,2570,137],"topic":[],"class_list":["post-41103","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-macos","tag-wireshark","tag-137"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/41103.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb826\u6b21\uff0c\u70b9\u8d5e27\u6b21\uff0c\u6536\u85cf15\u6b21\u3002\u672c\u6587\u4ecb\u7ecd\u4e86\u5728 macOS \u4e0a\u4f7f\u7528 Wireshark \u8fdb\u884c\u7f51\u7edc\u6293\u5305\u7684\u5b8c\u6574\u6d41\u7a0b\uff0c\u5305\u62ec\u5b89\u88c5\u65b9\u6cd5\u3001\u6743\u9650\u914d\u7f6e\u3001\u6293\u5305\u63a5\u53e3\u9009\u62e9\u3001\u8fc7\u6ee4\u89c4\u5219\u8bbe\u7f6e\u53ca\u5e38\u89c1\u534f\u8bae\u5206\u6790\uff0c\u9002\u5408\u521d\u5b66\u8005\u5feb\u901f\u4e0a\u624b\u7f51\u7edc\u6570\u636e\u5206\u6790\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/41103.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-30T22:02:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220232-683a2af8e0688.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/41103.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/41103.html\",\"name\":\"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2025-05-30T22:02:42+00:00\",\"dateModified\":\"2025-05-30T22:02:42+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/41103.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/41103.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/41103.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/41103.html","og_locale":"zh_CN","og_type":"article","og_title":"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb826\u6b21\uff0c\u70b9\u8d5e27\u6b21\uff0c\u6536\u85cf15\u6b21\u3002\u672c\u6587\u4ecb\u7ecd\u4e86\u5728 macOS \u4e0a\u4f7f\u7528 Wireshark \u8fdb\u884c\u7f51\u7edc\u6293\u5305\u7684\u5b8c\u6574\u6d41\u7a0b\uff0c\u5305\u62ec\u5b89\u88c5\u65b9\u6cd5\u3001\u6743\u9650\u914d\u7f6e\u3001\u6293\u5305\u63a5\u53e3\u9009\u62e9\u3001\u8fc7\u6ee4\u89c4\u5219\u8bbe\u7f6e\u53ca\u5e38\u89c1\u534f\u8bae\u5206\u6790\uff0c\u9002\u5408\u521d\u5b66\u8005\u5feb\u901f\u4e0a\u624b\u7f51\u7edc\u6570\u636e\u5206\u6790\u3002","og_url":"https:\/\/www.wsisp.com\/helps\/41103.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2025-05-30T22:02:42+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/05\/20250530220232-683a2af8e0688.png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"5 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/41103.html","url":"https:\/\/www.wsisp.com\/helps\/41103.html","name":"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2025-05-30T22:02:42+00:00","dateModified":"2025-05-30T22:02:42+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/41103.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/41103.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/41103.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"Wireshark \u5728 macOS \u4e0a\u4f7f\u7528\u53ca\u95ee\u9898\u89e3\u51b3"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/41103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=41103"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/41103\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/41098"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=41103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=41103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=41103"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=41103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}