Advertisement
Guest User

Ask Ubuntu Letizia

a guest
Aug 22nd, 2014
198
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.04 KB | None | 0 0
  1. USERNAME@exe-server1:~$ sudo tcpdump
  2. [sudo] password for USERNAME:
  3. tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
  4. listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
  5. 18:45:01.965279 IP exe-server1.local.54589 > 192.168.1.1.domain: 61254+ A? icanhazip.com. (31)
  6. 18:45:01.965305 IP exe-server1.local.54589 > 192.168.1.1.domain: 55732+ AAAA? icanhazip.com. (31)
  7. 18:45:02.362903 IP exe-server1.local.37617 > 192.168.1.1.domain: 5645+ PTR? 1.1.168.192.in-addr.arpa. (42)
  8. 18:45:02.377453 IP 192.168.1.1.domain > exe-server1.local.37617: 5645 NXDomain 0/1/0 (119)
  9. 18:45:02.451359 IP 192.168.1.1.domain > exe-server1.local.54589: 55732 1/0/0 AAAA 2001:4801:7824:104:abc5:ba2c:ff11:3fb9 (59)
  10. 18:45:02.451966 IP 192.168.1.1.domain > exe-server1.local.54589: 61254 1/0/0 A 23.253.218.205 (47)
  11. 18:45:02.474290 IP exe-server1.local.58847 > ipv4.icanhazip.com.http: Flags [S], seq 3476719073, win 29200, options [mss 1460,sackOK,TS val 450896 ecr 0,nop,wscale 7], length 0
  12. 18:45:02.477942 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 1.1.168.192.in-addr.arpa. (42)
  13. 18:45:02.477994 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 1.1.168.192.in-addr.arpa. (42)
  14. 18:45:02.721972 IP ipv4.icanhazip.com.http > exe-server1.local.58847: Flags [S.], seq 3146530403, ack 3476719074, win 14480, options [mss 1460,sackOK,TS val 3498196247 ecr 450896,nop,wscale 7], length 0
  15. 18:45:02.722009 IP exe-server1.local.58847 > ipv4.icanhazip.com.http: Flags [.], ack 1, win 229, options [nop,nop,TS val 450958 ecr 3498196247], length 0
  16. 18:45:02.722059 IP exe-server1.local.58847 > ipv4.icanhazip.com.http: Flags [P.], seq 1:78, ack 1, win 229, options [nop,nop,TS val 450958 ecr 3498196247], length 77
  17. 18:45:02.967264 IP ipv4.icanhazip.com.http > exe-server1.local.58847: Flags [.], ack 78, win 114, options [nop,nop,TS val 3498196495 ecr 450958], length 0
  18. 18:45:03.196970 IP ipv4.icanhazip.com.http > exe-server1.local.58847: Flags [P.], seq 1:445, ack 78, win 114, options [nop,nop,TS val 3498196723 ecr 450958], length 444
  19. 18:45:03.196988 IP exe-server1.local.58847 > ipv4.icanhazip.com.http: Flags [.], ack 445, win 237, options [nop,nop,TS val 451076 ecr 3498196723], length 0
  20. 18:45:03.197238 IP ipv4.icanhazip.com.http > exe-server1.local.58847: Flags [F.], seq 445, ack 78, win 114, options [nop,nop,TS val 3498196723 ecr 450958], length 0
  21. 18:45:03.197590 IP exe-server1.local.58847 > ipv4.icanhazip.com.http: Flags [F.], seq 78, ack 446, win 237, options [nop,nop,TS val 451077 ecr 3498196723], length 0
  22. 18:45:03.206474 IP exe-server1.local.51962 > 192.168.1.1.domain: 51171+ A? exeliker.t15.org. (34)
  23. 18:45:03.206486 IP exe-server1.local.51962 > 192.168.1.1.domain: 32256+ AAAA? exeliker.t15.org. (34)
  24. 18:45:03.219844 IP 192.168.1.1.domain > exe-server1.local.51962: 51171 1/0/0 A 31.170.167.71 (50)
  25. 18:45:03.388621 IP 192.168.1.1.domain > exe-server1.local.51962: 32256 0/1/0 (105)
  26. 18:45:03.436602 IP ipv4.icanhazip.com.http > exe-server1.local.58847: Flags [.], ack 79, win 114, options [nop,nop,TS val 3498196964 ecr 451077], length 0
  27. 18:45:03.459206 IP exe-server1.local.44632 > 31.170.167.71.http: Flags [S], seq 1778058700, win 29200, options [mss 1460,sackOK,TS val 451142 ecr 0,nop,wscale 7], length 0
  28. 18:45:03.479313 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 1.1.168.192.in-addr.arpa. (42)
  29. 18:45:03.479363 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 1.1.168.192.in-addr.arpa. (42)
  30. 18:45:03.688813 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 [2q] PTR (QM)? _ipp._tcp.local. PTR (QM)? _ipps._tcp.local. (45)
  31. 18:45:03.688854 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 [2q] PTR (QM)? _ipp._tcp.local. PTR (QM)? _ipps._tcp.local. (45)
  32. 18:45:03.713220 IP 31.170.167.71.http > exe-server1.local.44632: Flags [S.], seq 4250463286, ack 1778058701, win 14600, options [mss 1460,nop,nop,sackOK,nop,wscale 5], length 0
  33. 18:45:03.713250 IP exe-server1.local.44632 > 31.170.167.71.http: Flags [.], ack 1, win 229, length 0
  34. 18:45:03.713318 IP exe-server1.local.44632 > 31.170.167.71.http: Flags [P.], seq 1:179, ack 1, win 229, length 178
  35. 18:45:03.969036 IP 31.170.167.71.http > exe-server1.local.44632: Flags [.], ack 179, win 490, length 0
  36. 18:45:04.111731 IP 31.170.167.71.http > exe-server1.local.44632: Flags [P.], seq 1:475, ack 179, win 490, length 474
  37. 18:45:04.111746 IP exe-server1.local.44632 > 31.170.167.71.http: Flags [.], ack 475, win 237, length 0
  38. 18:45:04.112366 IP exe-server1.local.44632 > 31.170.167.71.http: Flags [F.], seq 179, ack 475, win 237, length 0
  39. 18:45:04.365040 IP 31.170.167.71.http > exe-server1.local.44632: Flags [F.], seq 475, ack 180, win 490, length 0
  40. 18:45:04.365086 IP exe-server1.local.44632 > 31.170.167.71.http: Flags [.], ack 476, win 237, length 0
  41. 18:45:05.481006 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 1.1.168.192.in-addr.arpa. (42)
  42. 18:45:05.481072 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 1.1.168.192.in-addr.arpa. (42)
  43. 18:45:07.372868 ARP, Request who-has exe-server1.local tell 192.168.1.1, length 46
  44. 18:45:07.372886 ARP, Reply exe-server1.local is-at 00:1e:c9:76:de:6a (oui Unknown), length 28
  45. 18:45:07.380372 IP exe-server1.local.49835 > 192.168.1.1.domain: 34878+ PTR? 99.1.168.192.in-addr.arpa. (43)
  46. 18:45:07.394632 IP 192.168.1.1.domain > exe-server1.local.49835: 34878 NXDomain 0/1/0 (120)
  47. 18:45:07.494973 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 99.1.168.192.in-addr.arpa. (43)
  48. 18:45:07.495020 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 99.1.168.192.in-addr.arpa. (43)
  49. 18:45:07.495112 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0*- [0q] 1/0/0 (Cache flush) PTR exe-server1.local. (68)
  50. 18:45:07.495382 IP exe-server1.local.47644 > 192.168.1.1.domain: 50351+ PTR? 205.218.253.23.in-addr.arpa. (45)
  51. 18:45:07.672311 IP 192.168.1.1.domain > exe-server1.local.47644: 50351 1/0/0 PTR ipv4.icanhazip.com. (77)
  52. 18:45:07.672597 IP exe-server1.local.36961 > 192.168.1.1.domain: 11095+ PTR? b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa. (90)
  53. 18:45:07.687586 IP 192.168.1.1.domain > exe-server1.local.36961: 11095 NXDomain 0/1/0 (160)
  54. 18:45:07.687727 IP exe-server1.local.60656 > 192.168.1.1.domain: 19658+ PTR? a.6.e.d.6.7.e.f.f.f.9.c.e.1.2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa. (90)
  55. 18:45:07.702628 IP 192.168.1.1.domain > exe-server1.local.60656: 19658 NXDomain 0/1/0 (160)
  56. 18:45:07.702878 IP exe-server1.local.36349 > 192.168.1.1.domain: 11999+ PTR? 251.0.0.224.in-addr.arpa. (42)
  57. 18:45:07.717168 IP 192.168.1.1.domain > exe-server1.local.36349: 11999 NXDomain 0/1/0 (99)
  58. 18:45:07.817547 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 251.0.0.224.in-addr.arpa. (42)
  59. 18:45:07.817608 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 251.0.0.224.in-addr.arpa. (42)
  60. 18:45:08.818071 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 251.0.0.224.in-addr.arpa. (42)
  61. 18:45:08.818132 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 251.0.0.224.in-addr.arpa. (42)
  62. 18:45:10.819499 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 251.0.0.224.in-addr.arpa. (42)
  63. 18:45:10.819563 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 251.0.0.224.in-addr.arpa. (42)
  64. 18:45:11.674728 IP stackoverflow.com.https > exe-server1.local.41897: Flags [P.], seq 177219484:177219542, ack 1992767661, win 33, options [nop,nop,TS val 2499209889 ecr 378014], length 58
  65. 18:45:11.675085 IP exe-server1.local.41897 > stackoverflow.com.https: Flags [P.], seq 1:38, ack 58, win 245, options [nop,nop,TS val 453196 ecr 2499209889], length 37
  66. 18:45:11.895630 IP stackoverflow.com.https > exe-server1.local.41897: Flags [.], ack 38, win 33, options [nop,nop,TS val 2499210110 ecr 453196], length 0
  67. 18:45:12.720029 IP exe-server1.local.41952 > 192.168.1.1.domain: 51396+ PTR? 71.167.170.31.in-addr.arpa. (44)
  68. 18:45:13.071173 IP 192.168.1.1.domain > exe-server1.local.41952: 51396 NXDomain 0/1/0 (112)
  69. 18:45:13.171603 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 71.167.170.31.in-addr.arpa. (44)
  70. 18:45:13.171653 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 71.167.170.31.in-addr.arpa. (44)
  71. 18:45:14.172960 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 71.167.170.31.in-addr.arpa. (44)
  72. 18:45:14.173032 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 71.167.170.31.in-addr.arpa. (44)
  73. 18:45:16.175381 IP6 fe80::21e:c9ff:fe76:de6a.mdns > ff02::fb.mdns: 0 PTR (QM)? 71.167.170.31.in-addr.arpa. (44)
  74. 18:45:16.175443 IP exe-server1.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 71.167.170.31.in-addr.arpa. (44)
  75. 18:45:18.074044 IP exe-server1.local.34802 > 192.168.1.1.domain: 13160+ PTR? 25.206.252.198.in-addr.arpa. (45)
  76. 18:45:18.088829 IP 192.168.1.1.domain > exe-server1.local.34802: 13160 1/0/0 PTR stackoverflow.com. (76)
  77. 18:45:43.378399 IP exe-server1.local.40145 > 192.168.1.1.domain: 15845+ A? dynupdate.no-ip.com. (37)
  78. 18:45:43.391429 IP 192.168.1.1.domain > exe-server1.local.40145: 15845 1/0/0 A 8.23.224.120 (53)
  79. 18:45:43.391505 IP exe-server1.local.45257 > dynupdate.no-ip.com.8245: Flags [S], seq 2817717037, win 29200, options [mss 1460,sackOK,TS val 461125 ecr 0,nop,wscale 7], length 0
  80. 18:45:43.707027 IP dynupdate.no-ip.com.8245 > exe-server1.local.45257: Flags [S.], seq 1779313781, ack 2817717038, win 14480, options [mss 1460,nop,wscale 7,sackOK,TS val 29243476 ecr 461125], length 0
  81. 18:45:43.707052 IP exe-server1.local.45257 > dynupdate.no-ip.com.8245: Flags [.], ack 1, win 229, options [nop,nop,TS val 461204 ecr 29243476], length 0
  82. 18:45:43.707075 IP exe-server1.local.45257 > dynupdate.no-ip.com.8245: Flags [P.], seq 1:78, ack 1, win 229, options [nop,nop,TS val 461204 ecr 29243476], length 77
  83. 18:45:44.001718 IP dynupdate.no-ip.com.8245 > exe-server1.local.45257: Flags [.], ack 78, win 46, options [nop,nop,TS val 29243549 ecr 461204], length 0
  84. 18:45:44.002933 IP dynupdate.no-ip.com.8245 > exe-server1.local.45257: Flags [P.], seq 1:166, ack 78, win 46, options [nop,nop,TS val 29243549 ecr 461204], length 165
  85. 18:45:44.002955 IP exe-server1.local.45257 > dynupdate.no-ip.com.8245: Flags [.], ack 166, win 237, options [nop,nop,TS val 461278 ecr 29243549], length 0
  86. 18:45:44.003204 IP dynupdate.no-ip.com.8245 > exe-server1.local.45257: Flags [F.], seq 166, ack 78, win 46, options [nop,nop,TS val 29243549 ecr 461204], length 0
  87. 18:45:44.003226 IP exe-server1.local.45257 > dynupdate.no-ip.com.8245: Flags [F.], seq 78, ack 167, win 237, options [nop,nop,TS val 461278 ecr 29243549], length 0
  88. 18:45:44.293389 IP dynupdate.no-ip.com.8245 > exe-server1.local.45257: Flags [.], ack 79, win 46, options [nop,nop,TS val 29243622 ecr 461278], length 0
  89. 18:45:44.379631 IP exe-server1.local.46493 > 192.168.1.1.domain: 2481+ PTR? 120.224.23.8.in-addr.arpa. (43)
  90. 18:45:44.393953 IP 192.168.1.1.domain > exe-server1.local.46493: 2481 1/0/0 PTR dynupdate.no-ip.com. (76)
  91. 18:45:48.386726 ARP, Request who-has exe-server1.local tell 192.168.1.1, length 46
  92. 18:45:48.386746 ARP, Reply exe-server1.local is-at 00:1e:c9:76:de:6a (oui Unknown), length 28
  93. ^C
  94. 88 packets captured
  95. 88 packets received by filter
  96. 0 packets dropped by kernel
  97. USERNAME@exe-server1:~$
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement