Re: tcpdump results
Dana Webber <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Ethereal is much easier to understand then tcpdump.
The standard reference for IP is "Tcp Illustrated"
On Wednesday 06 October 2004 17:16, Donald Cunningham wrote:
> Hello all,
>
> I'm seeing some tcpdump results I don't fully
> understand. Would one of you kindly point me to a
> reference that will help me understand the output of
> the traces shown below. In particular I don't
> understand the part of the trace within the curly
> braces:
>
> 09:16:21.486544 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:138001} > (DF)
>
> 09:16:21.486546 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:139381} > (DF)
>
> 09:16:21.487166 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:140761} > (DF)
>
> 09:16:21.487293 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:142141} > (DF)
>
>
> I know, I know... but I've RTFManpage and it didn't
> help.
>
> Thanks,
>
> Don
>
>
>
> _______________________________
> Do you Yahoo!?
> Declare Yourself - Register online to vote today!
> http://vote.yahoo.com
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
>
>
--
Dana Webber
[email protected]
http://dunrobin.dyn.dhs.org
Getting a computer system to work is like banging your head against a brick wall until the wall falls down.
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions