hoterran / tcpcollect

Watch sql base libpcap
141 stars 59 forks source link

对于协议 compress 的支持 #18

Closed hoterran closed 11 years ago

hoterran commented 11 years ago

某些用户会在连接的时候开启 compress 的功能,这就导致接下来的 sql 和结果集 不再显示的可以抓取,对于这种用户,直接过滤所有接下来的交互。

hoterran commented 11 years ago

T 42.120.127.2:3306 -> 110.76.41.144:51947 [AP] 47 00 00 00 0a 35 2e 31 2e 36 31 2d 41 6c 69 62 G....5.1.61-Alib 61 62 61 2d 31 32 31 30 31 31 2d 6c 6f 67 00 d9 aba-121011-log.. c4 15 00 66 23 75 47 44 5b 22 31 00 ff f7 21 02 ...f#uGD["1...!. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 70 61 ..............pa 74 46 3f 47 27 2d 4d 7a 42 77 00 tF?G'-MzBw.

T 110.76.41.144:51947 -> 42.120.127.2:3306 [AP] 43 00 00 01 a5 a2 02 00 00 00 00 40 08 00 00 00 C..........@.... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 72 33 33 30 30 71 35 32 36 36 39 37 ....r3300q526697 33 00 14 10 66 d2 04 4a 87 c8 f9 a8 6a 6d 97 70 3...f..J....jm.p 8d 1c 9e e4 9b 57 11 .....W. f

T 42.120.127.2:3306 -> 110.76.41.144:51947 [AP] 07 00 00 02 00 00 00 02 00 00 00 ...........

T 110.76.41.144:51947 -> 42.120.127.2:3306 [AP] 07 00 00 00 00 00 00 03 00 00 00 1b 01 00 ..............

T 42.120.127.2:3306 -> 110.76.41.144:51947 [AP] 09 00 00 01 00 00 00 05 00 00 01 fe 00 00 02 00 ................

T 110.76.41.144:51947 -> 42.120.127.2:3306 [AP] 53 00 00 00 6b 00 00 78 9c 4b 67 60 60 60 0e 76 S...k..x.Kg```.v 0d 51 48 ce 48 2c 4a 4c 2e 49 2d 8a 2f 4e 2d 89 .QH.H,JL.I-./N-. 4f ce cf cb 4b 4d 2e c9 cc cf b3 2d 2d 49 b3 d0 O...KM.....--I.. 41 93 2e 4a 2d 2e cd 29 29 c6 2a 97 9c 93 99 9a A..J-..)).*..... 57 62 9b 94 99 97 58 54 a9 53 5c 98 13 9f 9b 9f Wb....XT.S..... 92 6a ab ae 0e 00 07 86 27 4a .j......'J

hoterran commented 11 years ago

a5 a2 02 00 就是 client_flag ,这里的是 compress 压缩协议