</p><p># snoop</p><p>Using device /dev/pcn0 (promiscuous mode)</p><p>192.168.8.18 -> 192.168.255.255 NBT NS Query Request for WORKGROUP[1c], Success</p><p>192.168.253.35 -> solaris TELNET C port=1246</p><p>solaris -> 192.168.253.35 TELNET R port=1246 Using device /dev/pc</p><p>solaris -> 192.168.253.35 TELNET R port=1246 Using device /dev/pc</p><p>192.168.4.150 -> (broadcast) ARP C Who is 192.168.4.200, 192.168.4.200 ?</p><p>192.168.4.200 -> (broadcast) ARP C Who is 192.168.4.150, 192.168.4.150 ?</p><p>#</p><p>
</p><p>抓源地址或目的为 202.101.98.55的数据流:</p><p>
</p><p># snoop 202.101.98.55</p><p>Using device /dev/pcn0 (promiscuous mode)</p><p>192.168.253.35 -> dns.fz.fj.cn DNS C http://www.163.com/. Internet Addr ?</p><p>dns.fz.fj.cn -> 192.168.253.35 DNS R http://www.163.com/. Internet CNAME http://www.cache.split.netease.com/.</p><p>
</p><p># snoop 192.168.253.35 202.101.98.55</p><p>Using device /dev/pcn0 (promiscuous mode)</p><p>192.168.253.35 -> dns.fz.fj.cn DNS C http://www.google.com/. Internet Addr ?</p><p>dns.fz.fj.cn -> 192.168.253.35 DNS R http://www.google.com/. Internet CNAME http://www.l.google.com/.</p><p>#</p><p>