Read data stream WireShark

Disclaimer: This article is a blogger original article, shall not be reproduced without the bloggers allowed. https://blog.csdn.net/boatImpish/article/details/78390858

Read data stream

wireshark is a very powerful network analysis tool. Today, 171,025 pairs a little familiar with it, record it.

To summarize what is currently known

  • len: refers to a specific protocol, the length of the string MsgBody. To view the contents to see len = 0, can be a look up.
  • First, determine the content to be transmitted is the number of bytes, generally Integer is four bytes, a Short is two of their own, a byte is 8 bit, is 256 possibilities, can represent 256 different digital. Therefore, the transmission data of type Integer, 4 bytes is sufficient, transmitting a Short data, two bytes is sufficient. In WireShark can be selected in hex bytes may be selected for display bit bytes, the specific content may be selected if the ASCII or EBCDIC view to view. When selecting hexadecimal view, a single grid is a change in the (0 ~ F) range or the letter, four bytes to 2 to the power 32, which is required to represent eight lattice ; if it is binary, then it needs 32 grid to represent. This is what we often see, so to understand it.

Guess you like

Origin blog.csdn.net/boatImpish/article/details/78390858