Wireshark数据包分析之HTTP协议包解读

Posted

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了Wireshark数据包分析之HTTP协议包解读相关的知识,希望对你有一定的参考价值。

*此篇博客仅作为个人笔记和学习参考

GET方法的数据包分析

技术分享图片

Hypertext Transfer Protocol
GET / HTTP/1.1\r\n #请求行信息#
[Expert Info (Chat/Sequence): GET / HTTP/1.1\r\n] #专家信息#
Request Method: GET #请求的方法#
Request URI: / #请求的URI#
Request Version: HTTP/1.1 #请求的版本#
Host: www.boomgg.cn\r\n #请求主机#
Connection: keep-alive\r\n #使用持久链接#
Upgrade-Insecure-Requests: 1\r\n #升级不安全请求#
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (Khtml, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n #浏览器类型#
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8\r\n #请求的类型#
Accept-Encoding: gzip, deflate, sdch\r\n #请求的编码格式#
Accept-Language: zh-CN,zh;q=0.8\r\n #请求语言#
Cookie: CNZZDATA155540=cnzz_eid%3D2093723420-1483596271-%26ntime%3D1483596271\r\n #Cookie信息#
Cookie pair: CNZZDATA155540=cnzz_eid%3D2093723420-1483596271-%26ntime%3D1483596271\r\n #Cookie对#
[Full request URI: http://www.boomgg.cn/] #请求的URI全称#
[HTTP request 1/3] #HTTP请求进度#
[Response in frame: 12] #响应帧#
[Next request in frame: 15] #下一个请求帧#

技术分享图片

Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n #响应行信息#
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n] #专家信息#
Request Version: HTTP/1.1 #请求版本#
Status Code: 200 #状态码#
Response Phrase: OK #响应短语#
Date: Tue, 31 Jan 2017 07:34:36 GMT\r\n #响应时间#
Server: Apache/2.4.6 (CentOS) php/5.4.16\r\n #服务器信息#
Last-Modified: Tue, 17 Jun 2014 16:00:47 GMT\r\n #上一次修改#
ETag: "4b8d-4fc0a3f32a9c0"\r\n #上一次修改标识#
Accept-Ranges: bytes\r\n #接收范围#
Content-Length: 19341\r\n #内容长度#
Keep-Alive: timeout=5, max=99\r\n #保持响应时间,以及最大值#
Connection: Keep-Alive\r\n #使用持久链接#
Content-Type: text/css\r\n #响应的内容类型#
[HTTP response 2/3] #HTTP响应#
[Time since request: 0.423110000 seconds] #响应使用时长#
[Prev request in frame: 5] #上一个请求的帧#
[Prev response in frame: 12] #上一个响应的帧#
[Request in frame: 15] #请求的帧#
[Next request in frame: 47] #下一个请求的帧#
[Next response in frame: 59] #下一个响应的帧#
File Data: 19341 bytes #文件数据大小#
Line-based text data: text/css #数据#

POST方法的数据包分析

技术分享图片

基本同上
Hypertext Transfer Protocol
POST /Login.aspx HTTP/1.1\r\n
[Expert Info (Chat/Sequence): POST /Login.aspx HTTP/1.1\r\n]
[POST /Login.aspx HTTP/1.1\r\n]
[Severity level: Chat]
[Group: Sequence]
Request Method: POST
Request URI: /Login.aspx
Request Version: HTTP/1.1
Host: 192.168.1.113\r\n
Connection: keep-alive\r\n
Content-Length: 232\r\n
[Content length: 232]
Cache-Control: max-age=0\r\n
Origin: http://192.168.1.113\r\n
Upgrade-Insecure-Requests: 1\r\n
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n
Content-Type: application/x-www-form-urlencoded\r\n
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8\r\n
Referer: http://192.168.1.113/Login.aspx\r\n
Accept-Encoding: gzip, deflate\r\n
Accept-Language: zh-CN,zh;q=0.8\r\n
Cookie: CNZZDATA155540=cnzz_eid%3D1111972901-1485847397-%26ntime%3D1485847397\r\n
Cookie pair: CNZZDATA155540=cnzz_eid%3D1111972901-1485847397-%26ntime%3D1485847397
\r\n
[Full request URI: http://192.168.1.113/Login.aspx]
[HTTP request 3/5]
[Prev request in frame: 103]
[Response in frame: 116]
[Next request in frame: 117]
File Data: 232 bytes
HTML Form URL Encoded: application/x-www-form-urlencoded
Form item: "VIEWSTATE" = "/wEPDwULLTE2NDIxODkzMTdkZJ7MzhenUUfXodvToYkVaXvn0yfdfHjuKEO48w8QcgNA"
Form item: "
EVENTVALIDATION" = "/wEWBAKgrJH+CQLr/4HfAgLPyszgDQKr1YrVCg3Y+W/qSNhR3JLDwqBQ34U2Wh/M2l3/ijyDFw7qhPPT"
Form item: "UserID" = "Kemin" #这里可以看到发送的用户名
Form item: "UserPass" = "Fang" #这里可以看到发送的密码
Form item: "Log" = "Login"

技术分享图片

基本同上
Hypertext Transfer Protocol
HTTP/1.1 200 OK\r\n
[Expert Info (Chat/Sequence): HTTP/1.1 200 OK\r\n]
[HTTP/1.1 200 OK\r\n]
[Severity level: Chat]
[Group: Sequence]
Request Version: HTTP/1.1
Status Code: 200
Response Phrase: OK
Cache-Control: private\r\n
Content-Type: text/html; charset=utf-8\r\n
Content-Encoding: gzip\r\n
Vary: Accept-Encoding\r\n
Server: Microsoft-IIS/7.5\r\n
X-AspNet-Version: 4.0.30319\r\n
X-Powered-By: ASP.NET\r\n
Date: Tue, 31 Jan 2017 07:43:17 GMT\r\n
Content-Length: 1434\r\n
[Content length: 1434]
\r\n
[HTTP response 4/5]
[Time since request: 0.102894000 seconds]
[Prev request in frame: 114]
[Prev response in frame: 116]
[Request in frame: 117]
[Next request in frame: 133]
[Next response in frame: 176]
Content-encoded entity body (gzip): 1434 bytes -> 2563 bytes
File Data: 2563 bytes
Line-based text data: text/html

以上是关于Wireshark数据包分析之HTTP协议包解读的主要内容,如果未能解决你的问题,请参考以下文章

Wireshark数据包分析之DHCP协议包解读

Wireshark数据包分析之UDP协议包解读

Wireshark数据包分析之FTP协议包解读

《Wireshark数据包分析实战》(三)地址解析协议(ARP)

#WEB安全基础 : HTTP协议 | 0x7 学会使用wireshark分析数据包

2021-08-21 网安实验-Wireshark数据抓包分析之DNS协议