2014å¹´10æ31æ¥éå¬ããããã¯ã¼ã¯ ãã±ãããèªãä¼ (ä»®)ãã§ã®ã»ãã·ã§ã³ããã¾æ¹ã㦠Wireshark å ¥éãã®çºè¡¨ã¹ã©ã¤ãã§ãã Wireshark ã®å©ç¨æ¹æ³ã«ã¤ãã¦ãã¤ã³ã¹ãã¼ã«ããåæè¨å®ããã±ãããã£ããã£ã®éå§ã¨ãã£ã«ã¿ãªã³ã°ã¾ã§è§£èª¬ãã¦ãã¾ããRead less
OpenSSLã®èå¼±æ§ãHeartbleedããä¸éãè³ããã¦ãã¾ãããè²ã ã¨ä¹ãé ãã¦ãã¾ã£ãæãããã®ã§ãããããã¨è½ã¡ç©æ¾ããããããã¨æãã¾ãã Heartbleedã§ç§å¯éµãæã«å ¥ãããSSLéä¿¡ã®ä¸èº«å ¨é¨è¦ãã¡ããããã!! ã¨ããäºæ ã«ãªã£ã¦ãã¾ããããªãã¨ãªãçè«çã«ããã ãããªã¨åãããã®ã®ã¤ãã¤ãå ·ä½çãªæé ãåãããªãã ã¨ããããã§ä»åã®ãã¼ãã¨ãã¦ãæå ã«ãµã¼ãã®ç§å¯éµã¨ãSSLéä¿¡ããã±ãããã£ããã£ããpcapãã¡ã¤ã«ãããã¨ãã«ãWiresharkã§ã©ããªæãã§SSLéä¿¡ããã»ã©ããã®ãâ¦â¦ã¨ããå ·ä½çãªæé ãããããæãå«ãã¦ã¾ã¨ãã¦ããããã¨æãã¾ãã ã¨ããããç§èªèº«ãããã£ãã®ã§èªåç¨ã¡ã¢ã§ããªããªããã®ææ¸ã§ã¯"SSL"ã¨ã ãè¨è¿°ããTLSã¯ç¡è¦ãã¦ãã¾ãã åææ¡ä»¶ ã¨ãããã以ä¸ã®ãããªæãã®æ¤è¨¼ç°å¢ã§è©¦ãã¾ããã IPã¢ãã¬ã¹ 説æ ãã¹ãO
æ¦è¦Wireshark ã§HTTP ã®ã¬ã¹ãã³ã¹æéã確èªããæ¹æ³ã¨ããã®éã®æ³¨æç¹ãç´¹ä»ãã¾ãã å 容 HTTP ã®ã¬ã¹ãã³ã¹æéã®ç¢ºèªæ¹æ³ Wireshark ãç¨ããã¨ãHTTP ã®ã¬ã¹ãã³ã¹æéãç°¡åã«ç¢ºèªãããã¨ãã§ãã¾ãã 1. 確èªãããHTTP ã¬ã¹ãã³ã¹ã®ãã±ãã(= HTTP /1.1 200 OKã¨ãã£ããã®)ãã¯ãªãã¯ãã¾ãã âHypertext Transfer Protocolâ ã«ãããâTime since requestâ ã®é¨åãHTTP ã®ã¬ã¹ãã³ã¹æéã§ãã [è£è¶³] âhttp.responseâ ãã£ã«ã¿ã¼ã使ãã¨ãHTTP ã®ã¬ã¹ãã³ã¹æéãæã¤ãã±ããã®ã¿è¡¨ç¤ºããããã¨ãã§ãã¾ãã HTTP ã®ã¬ã¹ãã³ã¹æé確èªæã®æ³¨æç¹ HTTP ã®ã¬ã¹ãã³ã¹æéã調ã¹ãã«ã¯ãè¨å®å¤âAllow subdissector to reassemble TC
WIRESHARK Statistics IO Graphsï¼ï¼Advancedï¼ IO Graphsã§æ¸ãããã®ãããå°ãé«åº¦ãªï¼ï¼ï¼ã°ã©ãã«ã¤ãã¦èª¬æãã¾ãã Advancedã§ã¯ãåä½æéï¼Tick)ã«ãããTCPã®ãã¼ã¿ãµã¤ãº(tcp.len)ã®å¹³åå¤(Avg.)ãæ大å¤(Max.)ãæå°å¤(Min.)ãã°ã©ãåããããåä½æéã«ãããhttpã®ã³ã³ãã³ããµã¤ãº(http.content_length)ã®å¹³åå¤(Avg.)ãæ大å¤(Max.)ãæå°å¤(Min.)ãã°ã©ãåã§ãã¾ãã ããããªã°ã©ããæããããªã®ã§ãä½ãã¨å½¹ã«ç«ã¡ããã§ãã ã§ã¯ãåä½æéã«ãããhttpã®ã³ã³ãã³ããµã¤ãº(http.content_length)ã®ã°ã©ããæãã¦ã¿ã¾ãã ï¼ï¼ãã£ããã£ãã¼ã¿ã®æºå ã¾ãã¯ããã«ããã£ããã£ãã¼ã¿ãç¨æããWiresharkã§éãã¦ãã ããã ï¼ï¼httpã®ã³ã³ã
ãæ¦è¦ã»ã¾ã¨ãã Wiresharkã§ãã£ããã£ãããã±ãããç·¨éãããã®ç·¨éãããã±ãããéä¿¡ã§ãããªã¼ãã³ã½ã¼ã¹ã®ã½ããOstinatoãç´¹ä»ãã¾ãã ãå 容ã ã»Ostinatoã¨ã¯ï¼ Ostinatoã¨ã¯ãâWireshark in Reverse(=Wiresharkã®é)âãç®çã«ãããã¼ã«ã§ããªã¼ãã³ã½ã¼ã¹ã®ããã¸ã§ã¯ãã§ãã Ostinatoãå©ç¨ããã¨ãWiresharkã§ãã£ããã£ãããã±ãããç·¨éãããã®ç·¨éãããã±ãããéä¿¡ãããã¨ãã§ãã¾ãã ã»Ostinatoã®ã¤ã³ã¹ãã¼ã« (Ostinatoã¯ã¯ãã¹ãã©ãããã©ã¼ã ã®ã½ããã§ãããä»åã¯Windowsç°å¢ã¸ã®ã¤ã³ã¹ãã¼ã«ãç´¹ä»ãã¾ãã) Ostinatoã®ã¤ã³ã¹ãã¼ã«ã¯ã以ä¸ã®ãµã¤ãããWin32çããã¦ã³ãã¼ãããZipã解åããã°çµäºã§ãã http://code.google.com/p/ostinato
ããã¼ããã¯ç®ããé±ã ãã®ããæ¹ããã£ããè·å ´ã§å±éããã¨ããï¼ç®ã«è¦ãã¦ä½æ¥ã®ãã¼ã¹ãä¸ãã£ãã RFC ã«æºæ ãããããã¯ã¼ã¯ç³»ã®ã½ããã¦ã§ã¢ã®åä½ã解æããå ´åï¼ãã®ã½ããã¦ã§ã¢ãæ¸ãåºãç¬èªã®ãã°ãçºãã¦ããªãããï¼Wireshark ã§ãã±ããããã£ããã£ãã¦ç¢ºèªããã»ããæ©ãã±ã¼ã¹ãå¤ããããã ã¡ãªã¿ã«ï¼loopback ã¤ã³ã¿ãã§ã¼ã¹ã追å ããã«èªãã¹ãå®ã®ãã±ããããã£ããã£ããæ¹æ³ããããããã
Wiresharkã®IO Graphã«ã¤ãã¦è¨è¿°ãã¾ããIO Graphã¯ããã©ã¼ãã³ã¹ã®ãã©ãã«ã·ã¥ã¼ãã£ã³ã°ã«å½¹ã«ç«ã¤ãã®ã§ãMicrosoftãéå¬ããä¼è°ã®ã»ãã·ã§ã³ã®ä¸ã§ãæçæ§ãç´¹ä»ããã¦ãã¾ããã 以ä¸ãIO Graphã®ä½¿ãæ¹ãè¨è¿°ãã¾ãã IO Graphã使ç¨ããã«ã¯ï¼ IO Graphã使ç¨ããã«ã¯ããã±ãããã£ããã£å¾ãStatistics â> IO Graphã¨ãã©ãã¾ãã ããã¨ä»¥ä¸ã®ããã«IO Graphã表示ããã¾ãã X軸ããã£ããã£éå§ããã®çµéæéã§ãã Y軸ã¯ãPackets/TickãBytes/TickãBits/Tickã¨IOã®ç¨®é¡ãé¸ã¶ãã¨ãã§ãã¾ãã ãã®ããã«ãIO Graphãå©ç¨ããã¨ãã§ããã¤ããã©ã¼ãã³ã¹ãè¯ãã£ãã®ãã»æªãã£ãã®ããä¸ç®ã§ãããã¾ãã ãã©ãã«ã·ã¥ã¼ãã£ã³ã°ã«ä½¿ç¨ IO Graphã®ã°ã©ãä¸ãã¯ãªãã¯ããã¨ãã¯
Wiresharkã§ãã£ããã£ãããã±ããã®ãæ¦è¦ãææ¡ããã®ã«å½¹ã«ç«ã¤3ã¤ã®ææ³ãç´¹ä»ãã¾ãã Summary Statistics â> Summaryãããã£ããã£ãããã±ããã®æ¦è¦ãææ¡ã§ãã¾ãã 以ä¸ã®ç¹ãç¹ã«ä¾¿å©ã§ãã ã»Timeï¼ãã¤ãã©ã®ç¨åº¦ãã±ãããã£ããã£ãè¡ã£ãã®ããããã ã»Captureï¼ãã±ãããã£ããã£ãè¡ã£ãOSãããã ã»Displayï¼ãã±ãããã£ããã£æã®ã¹ã«ã¼ããããããã âDisplayâã¯ç¹ã«ä¾¿å©ã§ãDisplay filterãå¼µã£ãå¾ã®ã¹ã«ã¼ãããã確èªã§ãã¾ãããããã£ã¦ãä¾ãã°ãDisplay Filterã«âip.addr == 23.67.63.88âããã£ã«ã¿ã¼ãè¨å®ããã¨ãIPã23.67.63.88ã¨ã®ã¹ã«ã¼ãããããããã¾ãã Expert Info Analyze â> Expert Info ãããã¯ãå·¦ä¸ã®ä¸¸ã®ã¢ã¤ã³ã³
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}