Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Frame 11: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
- Arrival Time: Jul 27, 2012 02:14:26.505949000 Iran Daylight Time
- Epoch Time: 1343339066.505949000 seconds
- [Time delta from previous captured frame: 0.007324000 seconds]
- [Time delta from previous displayed frame: 0.000000000 seconds]
- [Time since reference or first frame: 1.065033000 seconds]
- Frame Number: 11
- Frame Length: 66 bytes (528 bits)
- Capture Length: 66 bytes (528 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR), Dst: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Destination: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: SR.C.IP.ADDR (SR.C.IP.ADDR), Dst: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 52
- Identification: 0x497e (18814)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0xe764 [correct]
- [Good: True]
- [Bad: False]
- Source: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Destination: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Transmission Control Protocol, Src Port: 46790 (46790), Dst Port: http (80), Seq: 0, Len: 0
- Source port: 46790 (46790)
- Destination port: http (80)
- [Stream index: 4]
- Sequence number: 0 (relative sequence number)
- Header length: 32 bytes
- Flags: 0x02 (SYN)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgement: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port http]
- [Message: Connection establish request (SYN): server port http]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- Window size: 8192
- Checksum: 0x529d [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- Options: (12 bytes)
- Maximum segment size: 1460 bytes
- NOP
- Window scale: 2 (multiply by 4)
- NOP
- NOP
- TCP SACK Permitted Option: True
- Frame 13: 66 bytes on wire (528 bits), 66 bytes captured (528 bits)
- Arrival Time: Jul 27, 2012 02:14:26.638114000 Iran Daylight Time
- Epoch Time: 1343339066.638114000 seconds
- [Time delta from previous captured frame: 0.003135000 seconds]
- [Time delta from previous displayed frame: 0.132165000 seconds]
- [Time since reference or first frame: 1.197198000 seconds]
- Frame Number: 13
- Frame Length: 66 bytes (528 bits)
- Capture Length: 66 bytes (528 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR), Dst: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Destination: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: DE.ST.IP.ADDR (DE.ST.IP.ADDR), Dst: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 52
- Identification: 0x4528 (17704)
- Flags: 0x00
- 0... .... = Reserved bit: Not set
- .0.. .... = Don't fragment: Not set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 119
- Protocol: TCP (6)
- Header checksum: 0x34bb [correct]
- [Good: True]
- [Bad: False]
- Source: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Destination: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Transmission Control Protocol, Src Port: http (80), Dst Port: 46790 (46790), Seq: 0, Ack: 1, Len: 0
- Source port: http (80)
- Destination port: 46790 (46790)
- [Stream index: 4]
- Sequence number: 0 (relative sequence number)
- Acknowledgement number: 1 (relative ack number)
- Header length: 32 bytes
- Flags: 0x12 (SYN, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port http]
- [Message: Connection establish acknowledge (SYN+ACK): server port http]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- Window size: 16384
- Checksum: 0x9808 [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- Options: (12 bytes)
- Maximum segment size: 1400 bytes
- NOP
- Window scale: 0 (multiply by 1)
- NOP
- NOP
- TCP SACK Permitted Option: True
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 11]
- [The RTT to ACK the segment was: 0.132165000 seconds]
- Frame 14: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)
- Arrival Time: Jul 27, 2012 02:14:26.638177000 Iran Daylight Time
- Epoch Time: 1343339066.638177000 seconds
- [Time delta from previous captured frame: 0.000063000 seconds]
- [Time delta from previous displayed frame: 0.000063000 seconds]
- [Time since reference or first frame: 1.197261000 seconds]
- Frame Number: 14
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR), Dst: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Destination: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: SR.C.IP.ADDR (SR.C.IP.ADDR), Dst: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 40
- Identification: 0x497f (18815)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0xe76f [correct]
- [Good: True]
- [Bad: False]
- Source: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Destination: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Transmission Control Protocol, Src Port: 46790 (46790), Dst Port: http (80), Seq: 1, Ack: 1, Len: 0
- Source port: 46790 (46790)
- Destination port: http (80)
- [Stream index: 4]
- Sequence number: 1 (relative sequence number)
- Acknowledgement number: 1 (relative ack number)
- Header length: 20 bytes
- Flags: 0x10 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 16800 (scaled)
- Checksum: 0x0830 [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 13]
- [The RTT to ACK the segment was: 0.000063000 seconds]
- Frame 15: 160 bytes on wire (1280 bits), 160 bytes captured (1280 bits)
- Arrival Time: Jul 27, 2012 02:14:26.648034000 Iran Daylight Time
- Epoch Time: 1343339066.648034000 seconds
- [Time delta from previous captured frame: 0.009857000 seconds]
- [Time delta from previous displayed frame: 0.009857000 seconds]
- [Time since reference or first frame: 1.207118000 seconds]
- Frame Number: 15
- Frame Length: 160 bytes (1280 bits)
- Capture Length: 160 bytes (1280 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp:http]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR), Dst: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Destination: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: SR.C.IP.ADDR (SR.C.IP.ADDR), Dst: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 146
- Identification: 0x4980 (18816)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0xe704 [correct]
- [Good: True]
- [Bad: False]
- Source: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Destination: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Transmission Control Protocol, Src Port: 46790 (46790), Dst Port: http (80), Seq: 1, Ack: 1, Len: 106
- Source port: 46790 (46790)
- Destination port: http (80)
- [Stream index: 4]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 107 (relative sequence number)]
- Acknowledgement number: 1 (relative ack number)
- Header length: 20 bytes
- Flags: 0x18 (PSH, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 1... = Push: Set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 16800 (scaled)
- Checksum: 0x7549 [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [Number of bytes in flight: 106]
- Hypertext Transfer Protocol
- GET / HTTP/1.1\r\n
- [Expert Info (Chat/Sequence): GET / HTTP/1.1\r\n]
- [Message: GET / HTTP/1.1\r\n]
- [Severity level: Chat]
- [Group: Sequence]
- Request Method: GET
- Request URI: /
- Request Version: HTTP/1.1
- User-Agent: curl/7.21.6 (i686-pc-mingw32) libcurl/7.21.6\r\n
- Host: dest.com\r\n
- Accept: */*\r\n
- \r\n
- Frame 16: 160 bytes on wire (1280 bits), 160 bytes captured (1280 bits)
- Arrival Time: Jul 27, 2012 02:14:27.068014000 Iran Daylight Time
- Epoch Time: 1343339067.068014000 seconds
- [Time delta from previous captured frame: 0.419980000 seconds]
- [Time delta from previous displayed frame: 0.419980000 seconds]
- [Time since reference or first frame: 1.627098000 seconds]
- Frame Number: 16
- Frame Length: 160 bytes (1280 bits)
- Capture Length: 160 bytes (1280 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp:http]
- [Coloring Rule Name: Bad TCP]
- [Coloring Rule String: tcp.analysis.flags]
- Ethernet II, Src: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR), Dst: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Destination: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: SR.C.IP.ADDR (SR.C.IP.ADDR), Dst: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 146
- Identification: 0x4981 (18817)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0xe703 [correct]
- [Good: True]
- [Bad: False]
- Source: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Destination: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Transmission Control Protocol, Src Port: 46790 (46790), Dst Port: http (80), Seq: 1, Ack: 1, Len: 106
- Source port: 46790 (46790)
- Destination port: http (80)
- [Stream index: 4]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 107 (relative sequence number)]
- Acknowledgement number: 1 (relative ack number)
- Header length: 20 bytes
- Flags: 0x18 (PSH, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 1... = Push: Set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 16800 (scaled)
- Checksum: 0x7549 [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [Number of bytes in flight: 106]
- [TCP Analysis Flags]
- [This frame is a (suspected) retransmission]
- [Expert Info (Note/Sequence): Retransmission (suspected)]
- [Message: Retransmission (suspected)]
- [Severity level: Note]
- [Group: Sequence]
- [The RTO for this segment was: 0.419980000 seconds]
- [RTO based on delta from frame: 15]
- Hypertext Transfer Protocol
- GET / HTTP/1.1\r\n
- [Expert Info (Chat/Sequence): GET / HTTP/1.1\r\n]
- [Message: GET / HTTP/1.1\r\n]
- [Severity level: Chat]
- [Group: Sequence]
- Request Method: GET
- Request URI: /
- Request Version: HTTP/1.1
- User-Agent: curl/7.21.6 (i686-pc-mingw32) libcurl/7.21.6\r\n
- Host: dest.com\r\n
- Accept: */*\r\n
- \r\n
- Frame 17: 830 bytes on wire (6640 bits), 830 bytes captured (6640 bits)
- Arrival Time: Jul 27, 2012 02:14:27.074026000 Iran Daylight Time
- Epoch Time: 1343339067.074026000 seconds
- [Time delta from previous captured frame: 0.006012000 seconds]
- [Time delta from previous displayed frame: 0.006012000 seconds]
- [Time since reference or first frame: 1.633110000 seconds]
- Frame Number: 17
- Frame Length: 830 bytes (6640 bits)
- Capture Length: 830 bytes (6640 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp:http:data-text-lines]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR), Dst: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Destination: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: DE.ST.IP.ADDR (DE.ST.IP.ADDR), Dst: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 816
- Identification: 0x4a01 (18945)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 119
- Protocol: TCP (6)
- Header checksum: 0xece5 [correct]
- [Good: True]
- [Bad: False]
- Source: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Destination: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Transmission Control Protocol, Src Port: http (80), Dst Port: 46790 (46790), Seq: 1, Ack: 107, Len: 776
- Source port: http (80)
- Destination port: 46790 (46790)
- [Stream index: 4]
- Sequence number: 1 (relative sequence number)
- [Next sequence number: 777 (relative sequence number)]
- Acknowledgement number: 107 (relative ack number)
- Header length: 20 bytes
- Flags: 0x18 (PSH, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 1... = Push: Set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 65429
- Checksum: 0x38d8 [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 15]
- [The RTT to ACK the segment was: 0.425992000 seconds]
- [Number of bytes in flight: 776]
- Hypertext Transfer Protocol
- HTTP/1.1 302 Found\r\n
- [Expert Info (Chat/Sequence): HTTP/1.1 302 Found\r\n]
- [Message: HTTP/1.1 302 Found\r\n]
- [Severity level: Chat]
- [Group: Sequence]
- Request Version: HTTP/1.1
- Response Code: 302
- Date: Thu, 26 Jul 2012 21:44:30 GMT\r\n
- Server: Microsoft-IIS/6.0\r\n
- X-Powered-By: ASP.NET\r\n
- X-AspNet-Version: 2.0.50727\r\n
- Location: http://dest.com/Default.aspx\r\n
- Set-Cookie: Esperantus_Language_ime=en-US; path=/\r\n
- Set-Cookie: Esperantus_Language_fa=en-US; path=/\r\n
- Set-Cookie: PortalAlias=fa; path=/\r\n
- Set-Cookie: refreshed=true; expires=Thu, 26-Jul-2012 21:45:30 GMT; path=/\r\n
- Set-Cookie: .ASPXAUTH=; expires=Mon, 11-Oct-1999 20:30:00 GMT; path=/; HttpOnly\r\n
- Set-Cookie: portalroles=; expires=Mon, 11-Oct-1999 20:30:00 GMT; path=/\r\n
- Cache-Control: private\r\n
- Content-Type: text/html; charset=utf-8\r\n
- Content-Length: 146\r\n
- [Content length: 146]
- \r\n
- Line-based text data: text/html
- <html><head><title>Object moved</title></head><body>\r\n
- <h2>Object moved to <a href="http://dest.com/Default.aspx">here</a>.</h2>\r\n
- </body></html>\r\n
- Frame 18: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)
- Arrival Time: Jul 27, 2012 02:14:27.074862000 Iran Daylight Time
- Epoch Time: 1343339067.074862000 seconds
- [Time delta from previous captured frame: 0.000836000 seconds]
- [Time delta from previous displayed frame: 0.000836000 seconds]
- [Time since reference or first frame: 1.633946000 seconds]
- Frame Number: 18
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR), Dst: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Destination: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: SR.C.IP.ADDR (SR.C.IP.ADDR), Dst: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 40
- Identification: 0x4982 (18818)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0xe76c [correct]
- [Good: True]
- [Bad: False]
- Source: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Destination: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Transmission Control Protocol, Src Port: 46790 (46790), Dst Port: http (80), Seq: 107, Ack: 777, Len: 0
- Source port: 46790 (46790)
- Destination port: http (80)
- [Stream index: 4]
- Sequence number: 107 (relative sequence number)
- Acknowledgement number: 777 (relative ack number)
- Header length: 20 bytes
- Flags: 0x11 (FIN, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...1 = Fin: Set
- [Expert Info (Chat/Sequence): Connection finish (FIN)]
- [Message: Connection finish (FIN)]
- [Severity level: Chat]
- [Group: Sequence]
- Window size: 16024 (scaled)
- Checksum: 0x057f [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 17]
- [The RTT to ACK the segment was: 0.000836000 seconds]
- Frame 20: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)
- Arrival Time: Jul 27, 2012 02:14:27.246996000 Iran Daylight Time
- Epoch Time: 1343339067.246996000 seconds
- [Time delta from previous captured frame: 0.002914000 seconds]
- [Time delta from previous displayed frame: 0.172134000 seconds]
- [Time since reference or first frame: 1.806080000 seconds]
- Frame Number: 20
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: Bad TCP]
- [Coloring Rule String: tcp.analysis.flags]
- Ethernet II, Src: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR), Dst: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Destination: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: DE.ST.IP.ADDR (DE.ST.IP.ADDR), Dst: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 40
- Identification: 0x546b (21611)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 119
- Protocol: TCP (6)
- Header checksum: 0xe583 [correct]
- [Good: True]
- [Bad: False]
- Source: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Destination: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Transmission Control Protocol, Src Port: http (80), Dst Port: 46790 (46790), Seq: 777, Ack: 107, Len: 0
- Source port: http (80)
- Destination port: 46790 (46790)
- [Stream index: 4]
- Sequence number: 777 (relative sequence number)
- Acknowledgement number: 107 (relative ack number)
- Header length: 20 bytes
- Flags: 0x10 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 65429
- Checksum: 0x1590 [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [TCP Analysis Flags]
- [This is a TCP duplicate ack]
- [Duplicate ACK #: 1]
- [Duplicate to the ACK in frame: 17]
- [Expert Info (Note/Sequence): Duplicate ACK (#1)]
- [Message: Duplicate ACK (#1)]
- [Severity level: Note]
- [Group: Sequence]
- Frame 21: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)
- Arrival Time: Jul 27, 2012 02:14:27.247953000 Iran Daylight Time
- Epoch Time: 1343339067.247953000 seconds
- [Time delta from previous captured frame: 0.000957000 seconds]
- [Time delta from previous displayed frame: 0.000957000 seconds]
- [Time since reference or first frame: 1.807037000 seconds]
- Frame Number: 21
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR), Dst: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Destination: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: DE.ST.IP.ADDR (DE.ST.IP.ADDR), Dst: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 40
- Identification: 0x546c (21612)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 119
- Protocol: TCP (6)
- Header checksum: 0xe582 [correct]
- [Good: True]
- [Bad: False]
- Source: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Destination: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Transmission Control Protocol, Src Port: http (80), Dst Port: 46790 (46790), Seq: 777, Ack: 108, Len: 0
- Source port: http (80)
- Destination port: 46790 (46790)
- [Stream index: 4]
- Sequence number: 777 (relative sequence number)
- Acknowledgement number: 108 (relative ack number)
- Header length: 20 bytes
- Flags: 0x10 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 65429
- Checksum: 0x158f [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 18]
- [The RTT to ACK the segment was: 0.173091000 seconds]
- Frame 22: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)
- Arrival Time: Jul 27, 2012 02:14:27.248594000 Iran Daylight Time
- Epoch Time: 1343339067.248594000 seconds
- [Time delta from previous captured frame: 0.000641000 seconds]
- [Time delta from previous displayed frame: 0.000641000 seconds]
- [Time since reference or first frame: 1.807678000 seconds]
- Frame Number: 22
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR), Dst: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Destination: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: DE.ST.IP.ADDR (DE.ST.IP.ADDR), Dst: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 40
- Identification: 0x546d (21613)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 119
- Protocol: TCP (6)
- Header checksum: 0xe581 [correct]
- [Good: True]
- [Bad: False]
- Source: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Destination: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Transmission Control Protocol, Src Port: http (80), Dst Port: 46790 (46790), Seq: 777, Ack: 108, Len: 0
- Source port: http (80)
- Destination port: 46790 (46790)
- [Stream index: 4]
- Sequence number: 777 (relative sequence number)
- Acknowledgement number: 108 (relative ack number)
- Header length: 20 bytes
- Flags: 0x11 (FIN, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...1 = Fin: Set
- [Expert Info (Chat/Sequence): Connection finish (FIN)]
- [Message: Connection finish (FIN)]
- [Severity level: Chat]
- [Group: Sequence]
- Window size: 65429
- Checksum: 0x158e [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- Frame 23: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)
- Arrival Time: Jul 27, 2012 02:14:27.248634000 Iran Daylight Time
- Epoch Time: 1343339067.248634000 seconds
- [Time delta from previous captured frame: 0.000040000 seconds]
- [Time delta from previous displayed frame: 0.000040000 seconds]
- [Time since reference or first frame: 1.807718000 seconds]
- Frame Number: 23
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ip:tcp]
- [Coloring Rule Name: HTTP]
- [Coloring Rule String: http || tcp.port == 80]
- Ethernet II, Src: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR), Dst: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Destination: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- Address: DE:ST:MA:C_:AD:DR (DE:ST:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Source: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- Address: SR:C_:MA:C_:AD:DR (SR:C_:MA:C_:AD:DR)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- Type: IP (0x0800)
- Internet Protocol, Src: SR.C.IP.ADDR (SR.C.IP.ADDR), Dst: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Version: 4
- Header length: 20 bytes
- Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
- 0000 00.. = Differentiated Services Codepoint: Default (0x00)
- .... ..0. = ECN-Capable Transport (ECT): 0
- .... ...0 = ECN-CE: 0
- Total Length: 40
- Identification: 0x4984 (18820)
- Flags: 0x02 (Don't Fragment)
- 0... .... = Reserved bit: Not set
- .1.. .... = Don't fragment: Set
- ..0. .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0xe76a [correct]
- [Good: True]
- [Bad: False]
- Source: SR.C.IP.ADDR (SR.C.IP.ADDR)
- Destination: DE.ST.IP.ADDR (DE.ST.IP.ADDR)
- Transmission Control Protocol, Src Port: 46790 (46790), Dst Port: http (80), Seq: 108, Ack: 778, Len: 0
- Source port: 46790 (46790)
- Destination port: http (80)
- [Stream index: 4]
- Sequence number: 108 (relative sequence number)
- Acknowledgement number: 778 (relative ack number)
- Header length: 20 bytes
- Flags: 0x10 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgement: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- Window size: 16024 (scaled)
- Checksum: 0x057e [validation disabled]
- [Good Checksum: False]
- [Bad Checksum: False]
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 22]
- [The RTT to ACK the segment was: 0.000040000 seconds]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement