- 论坛徽章:
- 1
|
本帖最后由 shihyu 于 2015-04-18 11:44 编辑
- tcpdump: listening on wlan0, link-type EN10MB (Ethernet), capture size 262144 bytes
- 01:40:48.292932 bc:ae:c5:80:81:84 (oui Unknown) Null > 01:80:c2:00:00:00 (oui Unknown) Unknown DSAP 0x80 Information, send seq 94, rcv seq 87, Flags [Command], length 30
- 01:40:50.086981 IP (tos 0x0, ttl 64, id 34075, offset 0, flags [DF], proto TCP (6), length 60)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [S], cksum 0x6caf (incorrect -> 0x85d2), seq 3766383546, win 14600, options [mss 1460,sackOK,TS val 29816481 ecr 0,nop,wscale 6], length 0
- [+]
- 01:40:50.129679 IP (tos 0x0, ttl 62, id 0, offset 0, flags [DF], proto TCP (6), length 60)
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [S.], cksum 0x0db5 (correct), seq 2605056959, ack 3766383547, win 28800, options [mss 1452,sackOK,TS val 33202075 ecr 29816481,nop,wscale 7], length 0
- 01:40:50.129862 IP (tos 0x0, ttl 64, id 34076, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [.], cksum 0x6ca7 (incorrect -> 0xac10), seq 1, ack 1, win 229, options [nop,nop,TS val 29816485 ecr 33202075], length 0
- 01:40:50.130045 IP (tos 0x0, ttl 64, id 34077, offset 0, flags [DF], proto TCP (6), length 208)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [P.], cksum 0x268f (correct), seq 1:157, ack 1, win 229, options [nop,nop,TS val 29816485 ecr 33202075], length 156: pptp Length=156 CTRL-MSG Magic-Cookie=1a2b3c4d CTRL_MSGTYPE=SCCRQ PROTO_VER(1.0) FRAME_CAP(AS) BEARER_CAP(DA) MAX_CHAN(1) FIRM_REV(0) HOSTNAME(anonymous) VENDOR()
- 01:40:50.163495 IP (tos 0x0, ttl 62, id 40036, offset 0, flags [DF], proto TCP (6), length 52)
- [-]
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [.], cksum 0xab66 (correct), seq 1, ack 157, win 234, options [nop,nop,TS val 33202084 ecr 29816485], length 0
- 01:40:50.167554 IP (tos 0x0, ttl 62, id 40037, offset 0, flags [DF], proto TCP (6), length 208)
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [P.], cksum 0xc2f7 (correct), seq 1:157, ack 157, win 234, options [nop,nop,TS val 33202085 ecr 29816485], length 156: pptp Length=156 CTRL-MSG Magic-Cookie=1a2b3c4d CTRL_MSGTYPE=SCCRP PROTO_VER(1.0) RESULT_CODE(1:Successful channel establishment) ERR_CODE(0:None) FRAME_CAP() BEARER_CAP() MAX_CHAN(1) FIRM_REV(1) HOSTNAME(local) VENDOR(linux)
- 01:40:50.167676 IP (tos 0x0, ttl 64, id 34078, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [.], cksum 0x6ca7 (incorrect -> 0xaaba), seq 157, ack 157, win 245, options [nop,nop,TS val 29816489 ecr 33202085], length 0
- 01:40:50.167860 IP (tos 0x0, ttl 64, id 34079, offset 0, flags [DF], proto TCP (6), length 220)
- 192.168.2.5.51529 > 111111.cksum 0xe372 (correct), seq 157:325, ack 157, win 245, options [nop,nop,TS val 29816489 ecr 33202085], length 168: pptp Length=168 CTRL-MSG Magic-Cookie=1a2b3c4d CTRL_MSGTYPE=OCRQ CALL_ID(43837) CALL_SER_NUM(47437) MIN_BPS(1000) MAX_BPS(100000000) BEARER_TYPE(Any) FRAME_TYPE(E) RECV_WIN(8192) PROC_DELAY(0) PHONE_NO_LEN(0) PHONE_NO() SUB_ADDR()
- 01:40:50.205613 IP (tos 0x0, ttl 62, id 40038, offset 0, flags [DF], proto TCP (6), length 84)
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [P.], cksum 0x9e8f (correct), seq 157:189, ack 325, win 242, options [nop,nop,TS val 33202094 ecr 29816489], length 32: pptp Length=32 CTRL-MSG Magic-Cookie=1a2b3c4d CTRL_MSGTYPE=OCRP CALL_ID(384) PEER_CALL_ID(43837) RESULT_CODE(1:Connected) ERR_CODE(0:None) CAUSE_CODE(0) CONN_SPEED(100000000) RECV_WIN(8192) PROC_DELAY(0) PHY_CHAN_ID(0)
- 01:40:50.211351 IP (tos 0x0, ttl 62, id 40039, offset 0, flags [DF], proto TCP (6), length 52)
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [F.], cksum 0xa9e9 (correct), seq 189, ack 325, win 242, options [nop,nop,TS val 33202096 ecr 29816489], length 0
- 01:40:50.212816 IP (tos 0x0, ttl 64, id 34080, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [F.], cksum 0x6ca7 (incorrect -> 0xa9e2), seq 325, ack 190, win 245, options [nop,nop,TS val 29816494 ecr 33202094], length 0
- 01:40:50.236927 bc:ae:c5:80:81:84 (oui Unknown) Null > 01:80:c2:00:00:00 (oui Unknown) Unknown DSAP 0x80 Information, send seq 94, rcv seq 87, Flags [Command], length 30
- 01:40:50.247640 IP (tos 0x0, ttl 62, id 40040, offset 0, flags [DF], proto TCP (6), length 52)
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [.], cksum 0xa9db (correct), seq 190, ack 326, win 242, options [nop,nop,TS val 33202104 ecr 29816494], length 0
- 01:40:51.218249 IP (tos 0x0, ttl 64, id 11965, offset 0, flags [DF], proto TCP (6), length 60)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [S], cksum 0x4ee0 (incorrect -> 0x6a7b), seq 3361659311, win 14600, options [mss 1460,sackOK,TS val 29816594 ecr 0,nop,wscale 6], length 0
- 01:40:51.246602 IP (tos 0x0, ttl 60, id 0, offset 0, flags [DF], proto TCP (6), length 60)
- 23.49.116.211.443 > 192.168.2.5.47401: Flags [S.], cksum 0x7804 (correct), seq 3244102258, ack 3361659312, win 14480, options [mss 1460,sackOK,TS val 1356647986 ecr 29816594,nop,wscale 5], length 0
- 01:40:51.246938 IP (tos 0x0, ttl 64, id 11966, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [.], cksum 0x4ed8 (incorrect -> 0xde76), seq 1, ack 1, win 229, options [nop,nop,TS val 29816597 ecr 1356647986], length 0
- 01:40:51.254934 IP (tos 0x0, ttl 64, id 11967, offset 0, flags [DF], proto TCP (6), length 427)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [P.], cksum 0x89af (correct), seq 1:376, ack 1, win 229, options [nop,nop,TS val 29816598 ecr 1356647986], length 375
- 01:40:51.278954 IP (tos 0x0, ttl 60, id 56375, offset 0, flags [DF], proto TCP (6), length 52)
- 23.49.116.211.443 > 192.168.2.5.47401: Flags [.], cksum 0xdbde (correct), seq 1, ack 376, win 486, options [nop,nop,TS val 1356648017 ecr 29816598], length 0
- 01:40:51.280449 IP (tos 0x0, ttl 60, id 56376, offset 0, flags [DF], proto TCP (6), length 197)
- 23.49.116.211.443 > 192.168.2.5.47401: Flags [P.], cksum 0xe9b4 (correct), seq 1:146, ack 376, win 486, options [nop,nop,TS val 1356648018 ecr 29816598], length 145
- 01:40:51.280846 IP (tos 0x0, ttl 64, id 11968, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [.], cksum 0x4ed8 (incorrect -> 0xdc3b), seq 376, ack 146, win 245, options [nop,nop,TS val 29816600 ecr 1356648018], length 0
- 01:40:51.286889 IP (tos 0x0, ttl 64, id 11969, offset 0, flags [DF], proto TCP (6), length 111)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [P.], cksum 0x3a06 (correct), seq 376:435, ack 146, win 245, options [nop,nop,TS val 29816601 ecr 1356648018], length 59
- 01:40:51.351348 IP (tos 0x0, ttl 60, id 56377, offset 0, flags [DF], proto TCP (6), length 52)
- 23.49.116.211.443 > 192.168.2.5.47401: Flags [.], cksum 0xdac5 (correct), seq 146, ack 435, win 486, options [nop,nop,TS val 1356648091 ecr 29816601], length 0
- 01:40:51.351775 IP (tos 0x0, ttl 64, id 11970, offset 0, flags [DF], proto TCP (6), length 233)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [P.], cksum 0x09c1 (correct), seq 435:616, ack 146, win 245, options [nop,nop,TS val 29816607 ecr 1356648091], length 181
- 01:40:51.372010 IP (tos 0x0, ttl 60, id 56378, offset 0, flags [DF], proto TCP (6), length 52)
- 23.49.116.211.443 > 192.168.2.5.47401: Flags [.], cksum 0xd9d4 (correct), seq 146, ack 616, win 520, options [nop,nop,TS val 1356648111 ecr 29816607], length 0
- 01:40:51.522110 IP (tos 0x0, ttl 60, id 56379, offset 0, flags [DF], proto TCP (6), length 1433)
- 23.49.116.211.443 > 192.168.2.5.47401: Flags [P.], cksum 0x7df0 (correct), seq 146:1527, ack 616, win 520, options [nop,nop,TS val 1356648260 ecr 29816607], length 1381
- 01:40:51.561664 IP (tos 0x0, ttl 64, id 11971, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.47401 > 23.49.116.211.443: Flags [.], cksum 0x4ed8 (incorrect -> 0xd4ab), seq 616, ack 1527, win 289, options [nop,nop,TS val 29816629 ecr 1356648260], length 0
- 01:40:52.286767 bc:ae:c5:80:81:84 (oui Unknown) Null > 01:80:c2:00:00:00 (oui Unknown) Unknown DSAP 0x80 Information, send seq 94, rcv seq 87, Flags [Command], length 30
复制代码 好像無法正確濾出下面幾行- 01:40:50.129679 IP (tos 0x0, ttl 62, id 0, offset 0, flags [DF], proto TCP (6), length 60)
- 1.4.46.7.1723 > 192.168.2.5.51529: Flags [S.], cksum 0x0db5 (correct), seq 2605056959, ack 3766383547, win 28800, options [mss 1452,sackOK,TS val 33202075 ecr 29816481,nop,wscale 7], length 0
- 01:40:50.129862 IP (tos 0x0, ttl 64, id 34076, offset 0, flags [DF], proto TCP (6), length 52)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [.], cksum 0x6ca7 (incorrect -> 0xac10), seq 1, ack 1, win 229, options [nop,nop,TS val 29816485 ecr 33202075], length 0
- 01:40:50.130045 IP (tos 0x0, ttl 64, id 34077, offset 0, flags [DF], proto TCP (6), length 208)
- 192.168.2.5.51529 > 1.4.46.7.1723: Flags [P.], cksum 0x268f (correct), seq 1:157, ack 1, win 229, options [nop,nop,TS val 29816485 ecr 33202075], length 156: pptp Length=156 CTRL-MSG Magic-Cookie=1a2b3c4d CTRL_MSGTYPE=SCCRQ PROTO_VER(1.0) FRAME_CAP(AS) BEARER_CAP(DA) MAX_CHAN(1) FIRM_REV(0) HOSTNAME(anonymous) VENDOR()
- 01:40:50.163495 IP (tos 0x0, ttl 62, id 40036, offset 0, flags [DF], proto TCP (6), length 52)
复制代码 |
|