⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 433.htm

📁 unix高级编程原吗
💻 HTM
字号:
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<title>CTerm非常精华下载</title>
</head>
<body bgcolor="#FFFFFF">
<table border="0" width="100%" cellspacing="0" cellpadding="0" height="577">
<tr><td width="32%" rowspan="3" height="123"><img src="DDl_back.jpg" width="300" height="129" alt="DDl_back.jpg"></td><td width="30%" background="DDl_back2.jpg" height="35"><p align="center"><a href="http://apue.dhs.org"><font face="黑体"><big><big>apue</big></big></font></a></td></tr>
<tr>
<td width="68%" background="DDl_back2.jpg" height="44"><big><big><font face="黑体"><p align="center">               ● UNIX网络编程                       (BM: clown)                </font></big></big></td></tr>
<tr>
<td width="68%" height="44" bgcolor="#000000"><font face="黑体"><big><big><p   align="center"></big></big><a href="http://cterm.163.net"><img src="banner.gif" width="400" height="60" alt="banner.gif"border="0"></a></font></td>
</tr>
<tr><td width="100%" colspan="2" height="100" align="center" valign="top"><br><p align="center">[<a href="index.htm">回到开始</a>][<a href="317.htm">上一层</a>][<a href="434.htm">下一篇</a>]
<hr><p align="left"><small> ddxxkk 于 2000-12-18 11:27:37 加贴在 绿盟科技论坛(bbs.nsfocus.com)--UNIX系统安 <br>

全: <br>

  <br>

/*TCP/IP包检查(所有发到本地的TCP包) <br>

*/ <br>

    #include <stdio.h> <br>

    #include <sys/socket.h> <br>

    #include <netinet/in.h> <br>

    #include <arpa/inet.h> <br>

//IP和TCP头的定义 开始 <br>

//ip <br>

struct ip { <br>

    unsigned int        ip_length:4;    /*little-endian IP头长度(单位为32位)4位* <br>

/ <br>

    unsigned int        ip_version:4;   //版本号4 <br>

    unsigned char       ip_tos;         //服务类型 8 <br>

    unsigned short int     ip_total_length:16; //数据总长度16 <br>

    unsigned short int     ip_id;           //标识16 <br>

    unsigned short      ip_flags;        //标志+分段偏移16 <br>

    unsigned char       ip_ttl;          //生存时间8 <br>

    unsigned char       ip_protocol;     //传输协议8 <br>

    unsigned short      ip_cksum;        //头校验和16 <br>

    unsigned long int        ip_source;       //源地址32 <br>



    unsigned long int        ip_dest;         //目标地址32 <br>

}; <br>

/* TCP */ <br>

struct tcp { <br>

    unsigned short      tcp_source_port; //源端口(16位) <br>

    unsigned short      tcp_dest_port;   //目的端口(16位) <br>

    unsigned int        tcp_seqno;       //序号(32位) <br>

    unsigned int        tcp_ackno;       //确认号 收到的TCP信息的序号+1 <br>

    unsigned int        tcp_res1:4,     /*little-endian*///数据偏移4位 <br>

    tcp_hlen:4,                         //保留4 <br>

    tcp_fin:1,                          //标志 结束 <br>

     tcp_syn:1,                          //标志 同步 <br>

    tcp_rst:1,                          //标志 重置 <br>

    tcp_psh:1,                          //标志 入栈 <br>

    tcp_ack:1,                          //标志 确认 <br>

    tcp_urg:1,                          //标志 紧急 <br>

    tcp_res2:2;                         //保留2 <br>

    unsigned short      tcp_winsize;        //窗口16位 <br>

    unsigned short      tcp_cksum;          //校验和16 位 <br>

    unsigned short      tcp_urgent;         //紧急指针 <br>

}; <br>

//IP和TCP头的定义 结束 <br>



  <br>

    int main() <br>

    { <br>

        int sock, bytes_recieved, fromlen,n,id,s; <br>

        unsigned char buffer[65535]; <br>

        struct sockaddr_in from,ff; <br>

        struct ip  *ip; <br>

        struct tcp *tcp; <br>

//        ff.sin_addr.s_addr=0xc0a80b26; <br>

//        printf("test id %s \n",inet_ntoa(ff.sin_addr)); <br>

  <br>

        //建立原始TCP包方式 收到IP+TCP信息包 <br>

        sock = socket(AF_INET, SOCK_RAW, IPPROTO_TCP); <br>

        id=1; <br>

    while(1) <br>

     { <br>

       fromlen = sizeof(from); <br>

        //接收包 <br>

       bytes_recieved = recvfrom(sock, buffer, sizeof(buffer),0,(struct sockaddr <br>

 *)&from, &fromlen); <br>

       if (bytes_recieved>0) <br>

         { <br>

         { <br>

        //IP头为最小160位 8位一个字节 共20个字节 (0x14) 后为添加内容TCP,UDP等 <br>

信息 <br>

        ip = (struct ip *)buffer; <br>

        //tcp信息包 从整个IP/TCP包 buffer + (4*ip->ip_length) 地址处开始 <br>

        tcp = (struct tcp *)(buffer + (4*ip->ip_length)); <br>

         if (ntohs(tcp->tcp_dest_port)!=23 )  //可以改为其它(说明不显示TELNET的 <br>

信息) <br>

         { <br>

        printf("\n ID=::: %d\n",id); <br>

        printf("Bytes received ::: %5d\n",bytes_recieved); <br>

        printf("---- IP info begin ---- \n"); <br>

        printf("IP header length ::: %d\n",ip->ip_length); <br>

        printf("IP sum      size ::: %d\n",ntohs(ip->ip_total_length)); <br>

        printf("Protocol ::: %d\n",ip->ip_protocol); <br>

//        printf("ip_source address ::: %x\n",ntohl(ip->ip_source)); <br>

//      printf("ip_dest address ::: %x\n",ntohl(ip->ip_dest)); <br>

        ff.sin_addr.s_addr=ip->ip_source; <br>

        printf("IP_source address ::: %s \n",inet_ntoa(ff.sin_addr)); <br>

        ff.sin_addr.s_addr=ip->ip_dest; <br>

        printf("IP_dest address ::: %s \n",inet_ntoa(ff.sin_addr)); <br>

           for (n=0;n<4*ip->ip_length;n++){printf("%02X ",buffer[n]);} <br>

            printf("\n"); <br>



         printf("----  IP info end  ----  \n"); <br>

         printf("----TCP info begin ----  \n"); <br>

        /* ntohs  网络的 short int 转为本地的 short int <br>

        unsinged short int ntons(unsigned short int netshort) <br>

        */ <br>

          printf("Source port ::: %d\n",ntohs(tcp->tcp_source_port)); <br>

          printf("Dest port  ::: %d\n",ntohs(tcp->tcp_dest_port)); <br>

//        printf("Source address ::: %s\n",inet_ntoa(from.sin_addr)); <br>

//列出收到的TCP信息内容 一般TCP头20个字节所以TCP后20个字节是传送的信息 <br>

          for (n=(4*ip->ip_length+20);n<ntohs(ip->ip_total_length);n++){printf(" <br>

%c",buffer[n]);} <br>

          printf("----TCP info end    ----  \n"); <br>

          id=id+1; <br>

         }  //>23 end <br>

       } //>0 end <br>

     } //while end <br>

} <br>

</small><hr>
<p align="center">[<a href="index.htm">回到开始</a>][<a href="317.htm">上一层</a>][<a href="434.htm">下一篇</a>]
<p align="center"><a href="http://cterm.163.net">欢迎访问Cterm主页</a></p>
</table>
</body>
</html>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -