admin管理员组

文章数量:1531240

2024年7月21日发(作者:)

查找局域网中的DHCP服务器

某天,在xenserver中的某一台主机启动后发觉IP地址是DHCP获得的,

如不确定,可以先用 67 netstat -an|grep 68 查看哪个端口目前

在监听,tcpdump的port选项就填正listen的那个端口。 开头抓

包 [root@ ~] tcpdump -e -i eth0 -nn port 67 tcpdump:

但是网段却是我从没有配置过的。想了很久都不记得自己曾经架过这么

verbose output ppres, use -v or -vv for full protocol decode

一台DHCP服务器。我要做的就是揪出它,看看是哪台机器在提供DHCP

listening on eth0, link-type EN10MB (Ethernet), capture size 96

服务。google了下,找到了通过的办法,阅历证是可行的。 查看dh

bytes 09:12:24.805483 00:16:3e:14:0a:75 ff:ff:ff:ff:ff:ff,

client的IP地址是172.20.10.54 eth0 Link eap:Ethernet HWar

ethertype IPv4 (0x0800), length 342: 0.0.0.0.68

00:16:3E:14:0A:74 inet addr:172.20.10.54

255.255.255.255.67: BOOTP/DHCP, Request from 00:16:3e:14:0a:75,

Bcast:172.20.10.255 Mask:255.255.255.0 inet6 addr:

length: 300 09:12:24.806055 00:16:3e:14:0a:75

fe80::216:3eff:fe14:a74/64 Scope:Link UP BROADCAST RUNNING

ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342:

MULTICAST MTU:1500 Meic:1 RX packets:2657 errors:0

0.0.0.0.68 255.255.255.255.67: BOOTP/DHCP, Request from

dropp:0 overruns:0 frame:0 TX packets:188 errors:0 dropped:0

00:16:3e:14:0a:75, length: 300 09:13:39.274700

overruns:0 carrier:0 lisions:0 txqueuelen:1000 RX

00:16:3e:14:0a:73 ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800),

bytes:232533 (227.0 KiB) TX bytes:33943 (33.1 KiB) 登陆到

length 342: 0.0.0.0.68 255.255.255.255.67: BOOTP/DHCP, Request

dhcp client上,利用软件抓包,指定端口是67(也有可能是68).假

第 1 页 共 2 页

本文标签: 局域网没有办法端口看看