|
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有账号?注册
×
i compile l7-layer into coyote router.and i want to write a QQ patterns.look:http://l7-filter.sourceforge.net/http://l7-filter.sourceforge.net/layer7-patterns/HOWTOwww.qq.comthis is a english edition for qq:http://qqdl.tencent.com/qq2003iii_eng.exeBecause over six multimillionaire people to use QQ in china.QQ have three method to conncet to server.one is udp to port 61.144.238.145:8000,and another is tcp connect to 218.17.209.23:80,three is connect to 218.17.209.42:443.when i login my qq,i use tcpdump command :
CODE
gtr@cjzzf [/home/gtr] # tcpdump -n -v -X -s 500 src host 192.168.1.15 and dst port 8000tcpdump: listening on rl016:33:23.189422 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 13 (ttl 128, id 29759, len 41)0x0000 4500 0029 743f 0000 8011 d8ab c0a8 010f E..)t?..........0x0010 3d90 ee91 0fa1 1f40 0015 3533 020c 3900 =......@..53..9.0x0020 6226 ee00 10a3 0f00 03ff ffff ffff b&............16:33:23.261195 192.168.1.15.4002 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29761, len 56)0x0000 4500 0038 7441 0000 8011 d89a c0a8 010f E..8tA..........0x0010 3d90 ee91 0fa2 1f40 0024 b1ad 020c 3900 =......@.$....9.0x0020 5926 ee00 10a3 0fef 2540 f50e b794 a83b Y&......%@.....;0x0030 cf3a 741e 86fb 4a03 .:t...J.16:33:23.272875 192.168.1.15.4001 > 61.144.238.145.8000: udp 460 (ttl 128, id 29762, len 488)0x0000 4500 01e8 7442 0000 8011 d6e9 c0a8 010f E...tB..........0x0010 3d90 ee91 0fa1 1f40 01d4 f110 020c 3900 =......@......9.0x0020 2226 ee00 10a3 0f1c ec74 5fc8 0125 bd9a "&.......t_..%..0x0030 08dc 722c 802f 8c95 6d34 3eb6 833e 492d ..r,./..m4>..>I-0x0040 a68b 4d41 8d77 1ae9 6b28 9cfe 695e 55af ..MA.w..k(..i^U.0x0050 a18d b9eb a4f3 0e57 0769 fb25 9fcc 026e .......W.i.%...n0x0060 8611 cbea 5ea6 42a5 1f59 c100 93c9 9129 ....^.B..Y.....)0x0070 147c 8908 5679 60a3 e86e da0a 8f37 29eb .|..Vy`..n...7).0x0080 2b0f 82b9 1d32 76e3 d163 28c5 52f1 2b78 +....2v..c(.R.+x0x0090 7dd1 bdce b98c 7f11 2d4e ba8a 3ac3 b5db }.......-N..:...0x00a0 38cf b42f d9ce e2f5 15ae ac8b e02c 27f0 8../.........,'.0x00b0 2754 e509 5327 4518 360b c933 8225 6cbf 'T..S'E.6..3.%l.0x00c0 ed7e 0574 2301 3bc6 8597 84b5 b892 44a7 .~.t#.;.......D.0x00d0 242b e5b6 e414 36fa 1eb3 2f1a 051d 2b57 $+....6.../...+W0x00e0 a5d3 1cad b98d 9291 8b78 3824 0c2d 54c0 .........x8$.-T.0x00f0 d5b4 d672 46ae 9bf0 0078 9271 5d27 60ae ...rF....x.q]'`.0x0100 637f 0abc b528 3b79 4bc1 8ce5 0744 ff11 c....(;yK....D..0x0110 bf27 f568 328b 4ec3 0c45 84f5 1733 90d3 .'.h2.N..E...3..0x0120 9a53 dc50 a8e5 f59b 7b87 8cf9 5a1f 2c4f .S.P....{...Z.,O0x0130 5a14 7c8c a922 ed25 f828 d47b 1f6e 16e4 Z.|..".%.(.{.n..0x0140 0b75 0583 3728 c5db d5fe 17c5 5fb9 927a .u..7(......_..z0x0150 2733 8184 de19 ef6f 7ea6 6438 4fda dee4 '3.....o~.d8O...0x0160 d28a 9856 f1ba 4a22 7b6d 8fb5 1f75 f5de ...V..J"{m...u..0x0170 a43b 93fa a3b1 734a 37ea c087 018a 9ec8 .;....sJ7.......0x0180 f262 a8d0 6f9c bcf7 5441 32dc ae79 0725 .b..o...TA2..y.%0x0190 84f3 d98a 8486 4bf0 d0d6 bf31 7606 0342 ......K....1v..B0x01a0 2f71 2405 fda4 5973 c24b c174 a6c0 7e0b /q$...Ys.K.t..~.0x01b0 c2d6 658b 8d7b 74d6 0e1f 7965 8880 22b0 ..e..{t...ye..".0x01c0 2419 1b12 71ea 7a75 57c4 3e3c d8be d544 $...q.zuW.>..M0x01e0 4409 f6bf 7215 D...r.16:33:23.331322 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29763, len 56)0x0000 4500 0038 7443 0000 8011 d898 c0a8 010f E..8tC..........0x0010 3d90 ee91 0fa1 1f40 0024 9b03 020c 3900 =......@.$....9.0x0020 1d26 ee00 10a3 0f4b e355 9a24 3024 490e .&.....K.U.$0$I.0x0030 4d13 7574 2b8e fd03 M.ut+...16:33:23.331406 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29764, len 56)0x0000 4500 0038 7444 0000 8011 d897 c0a8 010f E..8tD..........0x0010 3d90 ee91 0fa1 1f40 0024 3450 020c 3900 =......@.$4P..9.0x0020 1d26 ef00 10a3 0f02 7062 e055 63c3 8752 .&......pb.Uc..R0x0030 daa6 657e 97cc 3403 ..e~..4.16:33:23.331932 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 36 (ttl 128, id 29765, len 64)0x0000 4500 0040 7445 0000 8011 d88e c0a8 010f E..@tE..........0x0010 3d90 ee91 0fa1 1f40 002c 8a6e 020c 3900 =......@.,.n..9.0x0020 0626 ee00 10a3 0f12 bda6 919e 40a8 ab3b .&..........@..;0x0030 b75e e188 302f 12de 7cb6 f281 5d2b 2603 .^..0/..|...]+&.16:33:23.345665 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29767, len 56)0x0000 4500 0038 7447 0000 8011 d894 c0a8 010f E..8tG..........0x0010 3d90 ee91 0fa1 1f40 0024 f6c7 020c 3900 =......@.$....9.0x0020 0d26 ee00 10a3 0f37 6359 37f6 19d2 63c5 .&.....7cY7...c.0x0030 30f5 0de0 d856 6603 0....Vf.16:33:23.366842 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29768, len 56)0x0000 4500 0038 7448 0000 8011 d893 c0a8 010f E..8tH..........0x0010 3d90 ee91 0fa1 1f40 0024 c95e 020c 3900 =......@.$.^..9.0x0020 6526 ee00 10a3 0f5c 5f27 6024 036b db4a e&.....\_'`$.k.J0x0030 1fd1 6cdb fba8 4503 ..l...E.16:33:23.370678 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 308 (ttl 128, id 29769, len 336)0x0000 4500 0150 7449 0000 8011 d77a c0a8 010f E..PtI.....z....0x0010 3d90 ee91 0fa1 1f40 013c 1871 020c 3900 =......@...0x0090 d67e 3477 16c3 b384 de38 4ee6 0f95 462a .~4w.....8N...F*0x00a0 7865 e384 e263 c542 61a0 5f88 a26a cbc1 xe...c.Ba._..j..0x00b0 8c6e d54c 47e1 224f 533a 348a cbdc 9ced .n.LG."OS:4.....0x00c0 2c13 a6f5 73a8 6fbc b46a baca 4852 4cf4 ,...s.o..j..HRL.0x00d0 13c8 86cc 9eb4 faff 0644 fd50 01c6 0283 .........D.P....0x00e0 1143 9b38 9c63 694c 2c2e 5761 4fca 465c .C.8.ciL,.WaO.F\0x00f0 665d e8da 81d1 3bb0 5f48 2d87 a21d e2e7 f]....;._H-.....0x0100 7df1 5bcc 7afa 4b28 104d 9d14 3b0e 90c8 }.[.z.K(.M..;...0x0110 8298 42e1 fb3d 3523 9041 25a1 4b41 215f ..B..=5#.A%.KA!_0x0120 ca5d 7fad 82d9 fb4b 2301 2a3a dd5c 20e6 .].....K#.*:.\..0x0130 bc7d 9569 41e5 2140 bb4e 11a4 ad5f 804d .}.iA.!@.N..._.M0x0140 bcd4 0095 c86c 735c cc3b 044a f7c9 5103 .....ls\.;.J..Q.16:33:23.382730 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29770, len 56)0x0000 4500 0038 744a 0000 8011 d891 c0a8 010f E..8tJ..........0x0010 3d90 ee91 0fa1 1f40 0024 32aa 020c 3900 =......@.$2...9.0x0020 2726 ee00 10a3 0fa0 d9af 5553 2883 faf3 '&........US(...0x0030 b5a9 68cc 4ad7 8403 ..h.J...16:33:23.416312 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29771, len 56)0x0000 4500 0038 744b 0000 8011 d890 c0a8 010f E..8tK..........0x0010 3d90 ee91 0fa1 1f40 0024 91f5 020c 3900 =......@.$....9.0x0020 6526 ef00 10a3 0f5c 5f27 6024 036b db37 e&.....\_'`$.k.70x0030 9fc3 7bb2 d85b 1003 ..{..[..16:33:23.434826 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 308 (ttl 128, id 29772, len 336)0x0000 4500 0150 744c 0000 8011 d777 c0a8 010f E..PtL.....w....0x0010 3d90 ee91 0fa1 1f40 013c 1469 020c 3900 =......@. 61.144.238.145.8000: [udp sum ok] udp 28 (ttl 128, id 29798, len 56)0x0000 4500 0038 7466 0000 8011 d875 c0a8 010f E..8tf.....u....0x0010 3d90 ee91 0fa1 1f40 0024 2029 020c 3900 =......@.$.)..9.0x0020 6526 f200 10a3 0f11 7aba c36c 2839 caff e&......z..l(9..0x0030 6e18 5f41 f61d 1c03 n._A....16:33:23.822623 192.168.1.15.4001 > 61.144.238.145.8000: [udp sum ok] udp 308 (ttl 128, id 29799, len 336)0x0000 4500 0150 7467 0000 8011 d75c c0a8 010f E..Ptg.....\....0x0010 3d90 ee91 0fa1 1f40 013c c1a3 020c 3900 =......@. |
|