阅读:2542回复:2
bus hound捕捉的数据怎样分析呢?
[p] 我初学使用bus hound,捕捉到的数据不知道要如何分析?有没有比较详细一点的资料可以参考。我接了一个U盘,捕捉到这样的数据,请大家指导一下~以下是部分捕捉数据。。。。。。(也不知道设置的对不对)
Device - Device ID (followed by the endpoint for USB devices) (0) 主要 IDE 通道 (2) ST320413A [ROM=3.54] (3) SAMSUNG CD-ROM SC-148T [ROM=TL01] (6) USB Root Hub (14) USB Mass Storage Device Phase - Phase Type CDB Command descriptor block SRB SCSI request block DI Data in SSTS SCSI request block status DO Data out STAK NT IRP stack location IRP NT I/O request packet URB USB request block SNS SCSI sense data Data - Hex dump of the data transferred Descr - Description of the phase Delta - Elapsed time from the previous phase to the current phase Cmd... - Position in the captured data Device Phase Data Description Delta Cmd.Phase.Ofs(rep) ------ ----- ------------------------------------------------------------------------------------------------------ ---------------- ----- ------------------ 3 CDB 00 00 00 00 00 00 TEST UNIT READY 497ms 1.1.0 3 IRP 06 00 94 00 78 48 af ff 00 00 00 00 00 00 00 00 60 35 80 ff 60 35 80 ff 00 00 00 00 12 00 00 00 797us 2.1.0 3 STAK 0f 00 00 e0 70 58 98 ff 00 00 00 00 01 00 00 00 00 00 00 00 98 5d 2c 81 00 00 00 00 d0 31 09 f9 INTERNAL IOCTL 9us 2.2.0 3 SRB 40 00 00 01 00 00 00 00 00 00 06 00 5c 00 00 00 12 00 00 00 10 00 00 00 40 3b 2b 81 00 00 00 00 EXEC SCSI 7us 2.3.0 3 IRP 06 00 90 01 00 00 00 00 00 00 00 00 00 00 00 00 f0 65 25 81 f0 65 25 81 85 01 00 c0 00 00 00 00 16us 1.2.0 3 STAK 0f 00 00 e0 68 23 1f 81 00 00 00 00 13 00 1b 00 00 00 00 00 98 5d 2c 81 00 00 00 00 35 16 2a f9 INTERNAL IOCTL 3us 1.3.0 3 SNS 70 00 02 00 00 00 00 0a 00 00 00 00 3a 00 00 00 00 00 no media 3us 1.4.0 3 SRB 40 00 00 84 02 00 00 00 ff 20 06 12 08 01 00 10 00 00 00 00 14 00 00 00 00 00 00 00 40 3b 2b 81 EXEC SCSI 4us 1.5.0 6 IRP 06 00 90 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0b bb ff 50 0b bb ff 00 00 00 00 00 00 00 00 898us 3.1.0 6 STAK 0f 00 00 e0 fc bb ba ff 00 00 00 00 03 00 22 00 00 00 00 00 18 36 1c 81 00 00 00 00 7d a6 4e f9 INTERNAL IOCTL 13us 3.2.0 14 IRP 06 00 90 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0b bb ff 50 0b bb ff 00 00 00 00 00 00 00 00 7us 4.1.0 14 STAK 0f 00 00 e0 fc bb ba ff 00 00 00 00 03 00 22 00 00 00 00 00 48 da ba ff 00 00 00 00 40 24 61 f9 INTERNAL IOCTL 3us 4.2.0 14.2 DO 55 53 42 43 40 0b bb ff 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 USBC@........... 11us 4.3.0 14.2 URB 48 00 09 00 00 00 00 00 80 d9 ba ff 22 00 00 00 84 aa b8 ff 00 00 00 00 1f 00 00 00 60 bc ba ff BULK/INT XFER 9us 4.4.0 6 IRP 06 00 90 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0b bb ff 50 0b bb ff 00 00 00 00 00 00 00 00 1.9ms 5.1.0 6 STAK 0f 00 00 e0 fc bb ba ff 00 00 00 00 03 00 22 00 00 00 00 00 18 36 1c 81 00 00 00 00 7d a6 4e f9 INTERNAL IOCTL 19us 5.2.0 14 IRP 06 00 90 01 00 00 00 00 00 00 00 00 00 00 00 00 50 0b bb ff 50 0b bb ff 00 00 00 00 00 00 00 00 12us 6.1.0 14 STAK 0f 00 00 e0 fc bb ba ff 00 00 00 00 03 00 22 00 00 00 00 00 48 da ba ff 00 00 00 00 74 28 61 f9 INTERNAL IOCTL 3us 6.2.0 14.1 DI 55 53 42 53 40 0b bb ff 00 00 00 00 00 USBS@........ 13us 6.3.0 14.1 URB 48 00 09 00 00 00 00 00 80 d9 ba ff 22 00 00 00 64 aa b8 ff 01 00 00 00 0d 00 00 00 60 bc ba ff BULK/INT XFER 7us 6.4.0 [/p] |
|
沙发#
发布于:2007-07-19 22:42
你要分析什么数据啊
存储的内容啊 还是描述付啊什么的? |
|
|
板凳#
发布于:2007-07-19 22:43
重学习的角度考虑,你还是先分析鼠标的好,数据没有那么多.
|
|
|