



(源码见 https://github.com/tanjiti/packet_analysis)python print_pcap.py --pcapfile=da
ta/pcap_pub/wireshark/mysql_complete.pcap
[TCP] [1216309825.14 2008-07-17 15:50:25] 192.168.0.254:56162(00:00:00:00:00:00) ----->192.168.0.254:3306(00:00:00:00:00:00) SEQ=3436755789 ACK=0 FLAGS=['SYN'] WIN=32792 DA
TA= ttl=64 DA TA_BINARY= LEN=0 [TCP] [1216309825.14 2008-07-17 15:50:25] 192.168.0.254:3306(00:00:00:00:00:00) ----->192.168.0.254:56162(00:00:00:00:00:00) SEQ=3442775511 ACK=3436755790 FLAGS=['ACK', 'SYN'] WIN=32768 DA
TA= ttl=64 DA TA_BINARY= LEN=0 [TCP] [1216309825.14 2008-07-17 15:50:25] 192.168.0.254:56162(00:00:00:00:00:00) ----->192.168.0.254:3306(00:00:00:00:00:00) SEQ=3436755790 ACK=3442775512 FLAGS=['ACK'] WIN=513 DA
TA= ttl=64 DA TA_BINARY= LEN=0
(2)UDP头
包含源端口地址,目的端口地址

(3)ICMP头
包含:ICMP Type与各种Type对应的Code
