Re: tcpdump results

Dana Webber <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Ethereal is much easier to understand then tcpdump.
The standard reference for IP is "Tcp Illustrated"

On Wednesday 06 October 2004 17:16, Donald Cunningham wrote:
> Hello all,
> 
> I'm seeing some tcpdump results I don't fully
> understand.  Would one of you kindly point me to a
> reference that will help me understand the output of
> the traces shown below.  In particular I don't
> understand the part of the trace within the curly
> braces:
> 
> 09:16:21.486544 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:138001} > (DF)
> 
> 09:16:21.486546 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:139381} > (DF)
> 
> 09:16:21.487166 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:140761} > (DF)
> 
> 09:16:21.487293 local.ip.address.1494 >
> remote.ip.address.80: . ack 128341 win 48990
> <nop,nop,sack sack 1 {136621:142141} > (DF)
> 
> 
> I know, I know... but I've RTFManpage and it didn't
> help.
> 
> Thanks,
> 
> Don
> 
> 
> 		
> _______________________________
> Do you Yahoo!?
> Declare Yourself - Register online to vote today!
> http://vote.yahoo.com
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
> 
> 

-- 
Dana Webber
[email protected]
http://dunrobin.dyn.dhs.org

Getting a computer system to work is like banging your head against a brick wall until the wall falls down. 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.