- 论坛徽章:
- 0
|
求教:关于traceroute--急!
your filter is just icmp so can not see udp
see this:
clown:/home/clown# tcpdump -vvv \(src host 202.4.147.188 and udp \) or icmp
02:42:18.608351 IP (tos 0x0, ttl 1, id 36205, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33436: [udp sum ok] UDP, length: 10
02:42:18.608759 IP (tos 0xc0, ttl 255, id 59076, offset 0, flags [none], length: 56) 202.4.147.1 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36205, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33436: UDP, length: 10
02:42:18.608858 IP (tos 0x0, ttl 1, id 36206, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33437: [udp sum ok] UDP, length: 10
02:42:18.609263 IP (tos 0xc0, ttl 255, id 59077, offset 0, flags [none], length: 56) 202.4.147.1 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36206, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33437: UDP, length: 10
02:42:18.609716 IP (tos 0x0, ttl 64, id 625, offset 0, flags [DF], length: 70) clown.32774 >; 202.4.130.100.domain: [udp sum ok] 51331+ PTR? 1.147.4.202.in-addr.arpa. (42)
02:42:18.609844 IP (tos 0x0, ttl 2, id 36207, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33438: [udp sum ok] UDP, length: 10
02:42:18.610668 IP (tos 0xc0, ttl 254, id 7537, offset 0, flags [none], length: 56) 202.4.128.177 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36207, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33438: UDP, length: 10
02:42:18.611589 IP (tos 0x0, ttl 64, id 627, offset 0, flags [DF], length: 72) clown.32774 >; 202.4.130.100.domain: [udp sum ok] 51332+ PTR? 177.128.4.202.in-addr.arpa. (44)
02:42:18.611858 IP (tos 0x0, ttl 64, id 627, offset 0, flags [DF], length: 72) clown.32775 >; 202.4.130.100.domain: [udp sum ok] 53531+ PTR? 177.128.4.202.in-addr.arpa. (44)
02:42:18.618776 IP (tos 0x0, ttl 64, id 634, offset 0, flags [DF], length: 72) clown.32776 >; 202.4.130.100.domain: [udp sum ok] 51332+ PTR? 177.128.4.202.in-addr.arpa. (44)
02:42:18.618870 IP (tos 0x0, ttl 64, id 634, offset 0, flags [DF], length: 72) clown.32777 >; 202.4.130.100.domain: [udp sum ok] 53531+ PTR? 177.128.4.202.in-addr.arpa. (44)
02:42:18.620810 IP (tos 0x0, ttl 2, id 36208, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33439: [udp sum ok] UDP, length: 10
02:42:18.621364 IP (tos 0xc0, ttl 254, id 7538, offset 0, flags [none], length: 56) 202.4.128.177 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36208, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33439: UDP, length: 10
02:42:18.624051 IP (tos 0x0, ttl 2, id 36209, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33440: [udp sum ok] UDP, length: 10
02:42:18.625226 IP (tos 0xc0, ttl 254, id 7539, offset 0, flags [none], length: 56) 202.4.128.177 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36209, offset 0, flags [none], length: 3 clown.36203 >; tulip.pku.edu.cn.33440: UDP, length: 10
02:42:18.627401 IP (tos 0x0, ttl 3, id 36210, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33441: [udp sum ok] UDP, length: 10
02:42:18.628702 IP (tos 0xc0, ttl 253, id 64145, offset 0, flags [none], length: 56) 202.4.128.217 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36210, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33441: UDP, length: 10
02:42:18.635044 IP (tos 0x0, ttl 64, id 651, offset 0, flags [DF], length: 72) clown.32778 >; 202.4.130.100.domain: [udp sum ok] 53532+ PTR? 217.128.4.202.in-addr.arpa. (44)
02:42:18.635093 IP (tos 0x0, ttl 64, id 644, offset 0, flags [DF], length: 72) clown.32777 >; 202.4.130.100.domain: [udp sum ok] 51333+ PTR? 217.128.4.202.in-addr.arpa. (44)
02:42:18.636234 IP (tos 0x0, ttl 64, id 652, offset 0, flags [DF], length: 72) clown.32778 >; 202.4.130.100.domain: [udp sum ok] 53532+ PTR? 217.128.4.202.in-addr.arpa. (44)
02:42:18.636321 IP (tos 0x0, ttl 64, id 652, offset 0, flags [DF], length: 72) clown.32779 >; 202.4.130.100.domain: [udp sum ok] 51333+ PTR? 217.128.4.202.in-addr.arpa. (44)
02:42:18.637555 IP (tos 0x0, ttl 3, id 36211, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33442: [udp sum ok] UDP, length: 10
02:42:18.638226 IP (tos 0xc0, ttl 253, id 64146, offset 0, flags [none], length: 56) 202.4.128.217 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36211, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33442: UDP, length: 10
02:42:18.641552 IP (tos 0x0, ttl 3, id 36212, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33443: [udp sum ok] UDP, length: 10
02:42:18.642402 IP (tos 0xc0, ttl 253, id 64147, offset 0, flags [none], length: 56) 202.4.128.217 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36212, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33443: UDP, length: 10
02:42:18.644707 IP (tos 0x0, ttl 4, id 36213, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33444: [udp sum ok] UDP, length: 10
02:42:18.645672 IP (tos 0xc0, ttl 252, id 59760, offset 0, flags [none], length: 56) 202.4.128.18 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36213, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33444: UDP, length: 10
02:42:18.645965 IP (tos 0x0, ttl 64, id 661, offset 0, flags [DF], length: 71) clown.32779 >; 202.4.130.100.domain: [udp sum ok] 51334+ PTR? 18.128.4.202.in-addr.arpa. (43)
02:42:18.651848 IP (tos 0x0, ttl 64, id 667, offset 0, flags [DF], length: 71) clown.32780 >; 202.4.130.100.domain: [udp sum ok] 53533+ PTR? 18.128.4.202.in-addr.arpa. (43)
02:42:18.651959 IP (tos 0x0, ttl 64, id 667, offset 0, flags [DF], length: 71) clown.32781 >; 202.4.130.100.domain: [udp sum ok] 51334+ PTR? 18.128.4.202.in-addr.arpa. (43)
02:42:18.652774 IP (tos 0x0, ttl 64, id 668, offset 0, flags [DF], length: 71) clown.32782 >; 202.4.130.100.domain: [udp sum ok] 53533+ PTR? 18.128.4.202.in-addr.arpa. (43)
02:42:18.653691 IP (tos 0x0, ttl 4, id 36214, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33445: [udp sum ok] UDP, length: 10
02:42:18.654708 IP (tos 0xc0, ttl 252, id 59761, offset 0, flags [none], length: 56) 202.4.128.18 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36214, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33445: UDP, length: 10
02:42:18.657194 IP (tos 0x0, ttl 4, id 36215, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33446: [udp sum ok] UDP, length: 10
02:42:18.658494 IP (tos 0xc0, ttl 252, id 59762, offset 0, flags [none], length: 56) 202.4.128.18 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36215, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33446: UDP, length: 10
02:42:18.660688 IP (tos 0x0, ttl 5, id 36216, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33447: [udp sum ok] UDP, length: 10
02:42:18.661371 IP (tos 0x0, ttl 251, id 0, offset 0, flags [none], length: 56) 202.112.41.73 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36216, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33447: UDP, length: 10
02:42:18.661683 IP (tos 0x0, ttl 64, id 677, offset 0, flags [DF], length: 72) clown.32782 >; 202.4.130.100.domain: [udp sum ok] 51335+ PTR? 73.41.112.202.in-addr.arpa. (44)
02:42:18.661944 IP (tos 0x0, ttl 64, id 677, offset 0, flags [DF], length: 72) clown.32783 >; 202.4.130.100.domain: [udp sum ok] 53534+ PTR? 73.41.112.202.in-addr.arpa. (44)
02:42:18.670770 IP (tos 0x0, ttl 5, id 36217, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33448: [udp sum ok] UDP, length: 10
02:42:18.671498 IP (tos 0x0, ttl 251, id 0, offset 0, flags [none], length: 56) 202.112.41.73 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36217, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33448: UDP, length: 10
02:42:18.671656 IP (tos 0x0, ttl 5, id 36218, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33449: [udp sum ok] UDP, length: 10
02:42:18.672375 IP (tos 0x0, ttl 251, id 0, offset 0, flags [none], length: 56) 202.112.41.73 >; clown: icmp 36: time exceeded in-transit for IP (tos 0x0, ttl 1, id 36218, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33449: UDP, length: 10
02:42:18.675242 IP (tos 0x0, ttl 6, id 36219, offset 0, flags [none], length: 38) clown.36203 >; tulip.pku.edu.cn.33450: [udp sum ok] UDP, length: 10
02:42:26.648816 IP (tos 0x0, ttl 104, id 40854, offset 0, flags [none], length: 92) pc5.fvo-usa.com >; 202.4.147.130: icmp 72: echo request seq 48764
02:42:26.649107 IP (tos 0x0, ttl 64, id 8666, offset 0, flags [DF], length: 72) clown.32783 >; 202.4.130.100.domain: [udp sum ok] 51336+ PTR? 130.147.4.202.in-addr.arpa. (44)
02:42:26.716613 IP (tos 0x0, ttl 64, id 8733, offset 0, flags [DF], length: 74) clown.32783 >; 202.4.130.100.domain: [udp sum ok] 51337+ PTR? 150.137.104.216.in-addr.arpa. (46) |
|