利用 xcap 构造分片包
目录
目录....................................................................................................................................................2
1. 概述...............................................................................................................................................3
2. Xcap 环境说明 ..............................................................................................................................4
2.1 新建报文组.........................................................................................................................4
2.2 导入数据包.........................................................................................................................5
2.2 查看报文组.........................................................................................................................5
2.2 复制删除报文组.................................................................................................................5
3. 构造分片包...................................................................................................................................6
3.1 造普通/外层分片步骤........................................................................................................7
3.2 造内层分片步骤.................................................................................................................7
3.2.1 建立一个新报文 ....................................................................................................9
3.2.2 将组装的新报文分片 ............................................................................................9
3.2.3 替换原始包内层部分 ............................................................................................9
3.2.4 修改包某些字段 length ..........................................................................................9
4. 总结...............................................................................................................................................9
1. 概述
利用 Xcap 可以有效地造普通分片包、外层分片包和内层分片包。
2. Xcap 环境说明
2.1 新建报文组
进入软件后,首先右键“报文组”,创建新报文组。
2.2 导入数据包
右键“报文组”,选择“从.pcap 文件中读取”,选中想要分片的包,即可导入。
2.3 查看报文组
按住键盘“shift”,单击第 1、2、3 包,即选中这三个包,然后右键,看到倒数第
二选项“查看报文组”,点击一下,即可进入 wireshark,同时可以另存为 pcap、enc 格式等。