top 7 common filter skills
0:输入下面过滤关键字后,回车即可生效
1:IP地址过滤
ip.addr == ip.src ==ip.dst ==
2:协议过滤
dns and httpdns or httparp or icmpsip and rtp
3: tcp ,udp 端口过滤
tcp.port == udp.port ==
4: packet lost如何查看
tcp.analysis.flagstcp.flags.syn ==1 #tcp包的syn字段为1tco.flags.reset ==1
5:过滤掉不需要的包,感叹号的用法
!(arp or dns or icmp)
6:contains关键字的用法(非常好用)
tcp contains youkuudp contains youkuhttp contains ok00
7:http包的过滤
http.request.method== POSThttp.request.method== GEThttp.response.code == 200