Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 10/22-00:37:17.230995 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:44796 IpLen:20 DgmLen:48 DF
- ******S* Seq: 0x8A208200 Ack: 0x0 Win: 0xFC00 TcpLen: 28
- TCP Options (4) => MSS: 1260 NOP NOP SackOK
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:17.241533 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:44799 IpLen:20 DgmLen:40 DF
- ***A**** Seq: 0x8A208201 Ack: 0x1305E9B6 Win: 0xFC00 TcpLen: 20
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:17.242152 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:44800 IpLen:20 DgmLen:396 DF
- ***AP*** Seq: 0x8A208201 Ack: 0x1305E9B6 Win: 0xFC00 TcpLen: 20
- 47 45 54 20 2F 20 48 54 54 50 2F 31 2E 31 0D 0A GET / HTTP/1.1..
- 48 6F 73 74 3A 20 79 61 2E 72 75 0D 0A 55 73 65 Host: ya.ru..Use
- 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A 69 6C 6C 61 r-Agent: Mozilla
- 2F 35 2E 30 20 28 57 69 6E 64 6F 77 73 20 4E 54 /5.0 (Windows NT
- 20 35 2E 31 3B 20 72 76 3A 31 36 2E 30 29 20 47 5.1; rv:16.0) G
- 65 63 6B 6F 2F 32 30 31 30 30 31 30 31 20 46 69 ecko/20100101 Fi
- 72 65 66 6F 78 2F 31 36 2E 30 0D 0A 41 63 63 65 refox/16.0..Acce
- 70 74 3A 20 74 65 78 74 2F 68 74 6D 6C 2C 61 70 pt: text/html,ap
- 70 6C 69 63 61 74 69 6F 6E 2F 78 68 74 6D 6C 2B plication/xhtml+
- 78 6D 6C 2C 61 70 70 6C 69 63 61 74 69 6F 6E 2F xml,application/
- 78 6D 6C 3B 71 3D 30 2E 39 2C 2A 2F 2A 3B 71 3D xml;q=0.9,*/*;q=
- 30 2E 38 0D 0A 41 63 63 65 70 74 2D 4C 61 6E 67 0.8..Accept-Lang
- 75 61 67 65 3A 20 72 75 2D 52 55 2C 72 75 3B 71 uage: ru-RU,ru;q
- 3D 30 2E 38 2C 65 6E 2D 55 53 3B 71 3D 30 2E 35 =0.8,en-US;q=0.5
- 2C 65 6E 3B 71 3D 30 2E 33 0D 0A 41 63 63 65 70 ,en;q=0.3..Accep
- 74 2D 45 6E 63 6F 64 69 6E 67 3A 20 67 7A 69 70 t-Encoding: gzip
- 2C 20 64 65 66 6C 61 74 65 0D 0A 43 6F 6E 6E 65 , deflate..Conne
- 63 74 69 6F 6E 3A 20 6B 65 65 70 2D 61 6C 69 76 ction: keep-aliv
- 65 0D 0A 52 65 66 65 72 65 72 3A 20 68 74 74 70 e..Referer: http
- 3A 2F 2F 79 61 2E 72 75 2F 0D 0A 43 6F 6F 6B 69 ://ya.ru/..Cooki
- 65 3A 20 79 61 6E 64 65 78 75 69 64 3D 39 32 34 e: yandexuid=924
- 36 31 32 35 39 32 31 33 35 30 38 39 30 39 36 38 6125921350890968
- 0D 0A 0D 0A ....
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:17.266361 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:44801 IpLen:20 DgmLen:40 DF
- ***A**** Seq: 0x8A208365 Ack: 0x1305F38E Win: 0xFC00 TcpLen: 20
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:17.266476 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:44802 IpLen:20 DgmLen:40 DF
- ***A**** Seq: 0x8A208365 Ack: 0x1305F566 Win: 0xFA29 TcpLen: 20
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:17.387453 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:44848 IpLen:20 DgmLen:40 DF
- ***A***F Seq: 0x8A208365 Ack: 0x1305F566 Win: 0xFA29 TcpLen: 20
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:19.859682 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:45139 IpLen:20 DgmLen:40 DF
- ***A***F Seq: 0x8A208365 Ack: 0x1305F566 Win: 0xFA29 TcpLen: 20
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- 10/22-00:37:20.269915 x.170.99.178:3874 -> 93.158.134.3:80
- TCP TTL:128 TOS:0x0 ID:45168 IpLen:20 DgmLen:40 DF
- ***A**** Seq: 0x8A208366 Ack: 0x1305F566 Win: 0xFA29 TcpLen: 20
- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
- ^CCan't acquire (-1) - ipfw_daq_acquire: can't select divert socket (Interrupted system call)
- !
- ===============================================================================
- Packet I/O Totals:
- Received: 8
- Analyzed: 8 (100.000%)
- Dropped: 0 ( 0.000%)
- Filtered: 0 ( 0.000%)
- Outstanding: 0 ( 0.000%)
- Injected: 3
- ===============================================================================
- Breakdown by protocol (includes rebuilt packets):
- Eth: 0 ( 0.000%)
- VLAN: 0 ( 0.000%)
- IP4: 8 (100.000%)
- Frag: 0 ( 0.000%)
- ICMP: 0 ( 0.000%)
- UDP: 0 ( 0.000%)
- TCP: 8 (100.000%)
- IP6: 0 ( 0.000%)
- IP6 Ext: 0 ( 0.000%)
- IP6 Opts: 0 ( 0.000%)
- Frag6: 0 ( 0.000%)
- ICMP6: 0 ( 0.000%)
- UDP6: 0 ( 0.000%)
- TCP6: 0 ( 0.000%)
- Teredo: 0 ( 0.000%)
- ICMP-IP: 0 ( 0.000%)
- EAPOL: 0 ( 0.000%)
- IP4/IP4: 0 ( 0.000%)
- IP4/IP6: 0 ( 0.000%)
- IP6/IP4: 0 ( 0.000%)
- IP6/IP6: 0 ( 0.000%)
- GRE: 0 ( 0.000%)
- GRE Eth: 0 ( 0.000%)
- GRE VLAN: 0 ( 0.000%)
- GRE IP4: 0 ( 0.000%)
- GRE IP6: 0 ( 0.000%)
- GRE IP6 Ext: 0 ( 0.000%)
- GRE PPTP: 0 ( 0.000%)
- GRE ARP: 0 ( 0.000%)
- GRE IPX: 0 ( 0.000%)
- GRE Loop: 0 ( 0.000%)
- MPLS: 0 ( 0.000%)
- ARP: 0 ( 0.000%)
- IPX: 0 ( 0.000%)
- Eth Loop: 0 ( 0.000%)
- Eth Disc: 0 ( 0.000%)
- IP4 Disc: 0 ( 0.000%)
- IP6 Disc: 0 ( 0.000%)
- TCP Disc: 0 ( 0.000%)
- UDP Disc: 0 ( 0.000%)
- ICMP Disc: 0 ( 0.000%)
- All Discard: 0 ( 0.000%)
- Other: 0 ( 0.000%)
- Bad Chk Sum: 0 ( 0.000%)
- Bad TTL: 0 ( 0.000%)
- S5 G 1: 0 ( 0.000%)
- S5 G 2: 0 ( 0.000%)
- Total: 8
- ===============================================================================
- Action Stats:
- Alerts: 2 ( 25.000%)
- Logged: 2 ( 25.000%)
- Passed: 0 ( 0.000%)
- Limits:
- Match: 0
- Queue: 0
- Log: 0
- Event: 0
- Alert: 0
- Verdicts:
- Allow: 2 ( 25.000%)
- Block: 5 ( 62.500%)
- Replace: 0 ( 0.000%)
- Whitelist: 0 ( 0.000%)
- Blacklist: 1 ( 12.500%)
- Ignore: 0 ( 0.000%)
- ===============================================================================
- Normalizer statistics:
- ip4::trim: 0
- ip4::tos: 0
- ip4::df: 0
- ip4::rf: 0
- ip4::ttl: 0
- ip4::opts: 0
- icmp4::echo: 0
- tcp::syn_opt: 0
- tcp::ts_ecr: 0
- tcp::opt: 0
- tcp::pad: 0
- tcp::rsv: 0
- tcp::ecn_pkt: 0
- tcp::ns: 0
- tcp::urg: 0
- tcp::urp: 0
- tcp::trim: 0
- tcp::ecn_ssn: 0
- tcp::ts_nop: 0
- tcp::ips_data: 0
- tcp::block: 0
- ===============================================================================
- Frag3 statistics:
- Total Fragments: 0
- Frags Reassembled: 0
- Discards: 0
- Memory Faults: 0
- Timeouts: 0
- Overlaps: 0
- Anomalies: 0
- Alerts: 0
- Drops: 0
- FragTrackers Added: 0
- FragTrackers Dumped: 0
- FragTrackers Auto Freed: 0
- Frag Nodes Inserted: 0
- Frag Nodes Deleted: 0
- ===============================================================================
- Stream5 statistics:
- Total sessions: 1
- TCP sessions: 1
- UDP sessions: 0
- ICMP sessions: 0
- IP sessions: 0
- TCP Prunes: 0
- UDP Prunes: 0
- ICMP Prunes: 0
- IP Prunes: 0
- TCP StreamTrackers Created: 1
- TCP StreamTrackers Deleted: 1
- TCP Timeouts: 0
- TCP Overlaps: 0
- TCP Segments Queued: 0
- TCP Segments Released: 0
- TCP Rebuilt Packets: 0
- TCP Segments Used: 0
- TCP Discards: 2
- TCP Gaps: 0
- UDP Sessions Created: 0
- UDP Sessions Deleted: 0
- UDP Timeouts: 0
- UDP Discards: 0
- Events: 0
- Internal Events: 0
- TCP Port Filter
- Dropped: 0
- Inspected: 0
- Tracked: 3
- UDP Port Filter
- Dropped: 0
- Inspected: 0
- Tracked: 0
- ===============================================================================
- HTTP Inspect - encodings (Note: stream-reassembled packets included):
- POST methods: 0
- GET methods: 0
- HTTP Request Headers extracted: 0
- HTTP Request Cookies extracted: 0
- Post parameters extracted: 0
- HTTP response Headers extracted: 0
- HTTP Response Cookies extracted: 0
- Unicode: 0
- Double unicode: 0
- Non-ASCII representable: 0
- Directory traversals: 0
- Extra slashes ("//"): 0
- Self-referencing paths ("./"): 0
- HTTP Response Gzip packets extracted: 0
- Gzip Compressed Data Processed: n/a
- Gzip Decompressed Data Processed: n/a
- Total packets processed: 1
- ===============================================================================
- SMTP Preprocessor Statistics
- Total sessions : 0
- Max concurrent sessions : 0
- ===============================================================================
- dcerpc2 Preprocessor Statistics
- Total sessions: 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement