Advertisement
Guest User

Untitled

a guest
Mar 28th, 2020
139
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 23.43 KB | None | 0 0
  1. root@OpenWrt:~# tcpdump -i eth1.1 -vn 'tcp portrange 20-21 or (tcp portrange 40000-50000 and host 10.0.0.100)'
  2. tcpdump: listening on eth1.1, link-type EN10MB (Ethernet), capture size 262144 bytes
  3. 14:54:03.073304 IP (tos 0x28, ttl 106, id 44455, offset 0, flags [none], proto TCP (6), length 40)
  4. 95.210.104.142.15616 > 10.0.0.100.46786: Flags [R], cksum 0xecce (correct), seq 653646500, win 64240, length 0
  5. 14:54:04.047862 IP (tos 0x0, ttl 47, id 13066, offset 0, flags [DF], proto TCP (6), length 261)
  6. 84.223.8.172.57565 > 10.0.0.100.46786: Flags [P.], cksum 0xf523 (correct), seq 4171183486:4171183707, ack 1993062813, win 255, length 221
  7. 14:54:04.048264 IP (tos 0x20, ttl 64, id 56135, offset 0, flags [DF], proto TCP (6), length 40)
  8. 10.0.0.100.46786 > 84.223.8.172.57565: Flags [.], cksum 0x4eec (correct), ack 221, win 501, length 0
  9. 14:54:04.191690 IP (tos 0x0, ttl 113, id 7952, offset 0, flags [DF], proto TCP (6), length 57)
  10. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [P.], cksum 0x561f (correct), seq 4223594601:4223594618, ack 1443643648, win 513, length 17
  11. 14:54:04.213471 IP (tos 0x20, ttl 64, id 58031, offset 0, flags [DF], proto TCP (6), length 53)
  12. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [P.], cksum 0x1562 (correct), seq 1:14, ack 17, win 501, length 13
  13. 14:54:04.213491 IP (tos 0x20, ttl 64, id 58032, offset 0, flags [DF], proto TCP (6), length 5800)
  14. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x1633 (incorrect -> 0x1de0), seq 14:5774, ack 17, win 501, length 5760
  15. 14:54:04.241379 IP (tos 0x0, ttl 114, id 27605, offset 0, flags [DF], proto TCP (6), length 212)
  16. 93.67.88.190.60331 > 10.0.0.100.46786: Flags [P.], cksum 0xf733 (correct), seq 970496351:970496523, ack 2003021745, win 16589, length 172
  17. 14:54:04.241731 IP (tos 0x20, ttl 64, id 26512, offset 0, flags [DF], proto TCP (6), length 40)
  18. 10.0.0.100.46786 > 93.67.88.190.60331: Flags [.], cksum 0x5013 (correct), ack 172, win 501, length 0
  19. 14:54:04.355532 IP (tos 0x0, ttl 113, id 7953, offset 0, flags [DF], proto TCP (6), length 40)
  20. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x7b91 (correct), ack 1454, win 516, length 0
  21. 14:54:04.355957 IP (tos 0x20, ttl 64, id 58036, offset 0, flags [DF], proto TCP (6), length 2920)
  22. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x0af3 (incorrect -> 0x0c83), seq 5774:8654, ack 17, win 501, length 2880
  23. 14:54:04.360199 IP (tos 0x0, ttl 113, id 7954, offset 0, flags [DF], proto TCP (6), length 40)
  24. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x7051 (correct), ack 4334, win 516, length 0
  25. 14:54:04.360636 IP (tos 0x20, ttl 64, id 58038, offset 0, flags [DF], proto TCP (6), length 2920)
  26. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x0af3 (incorrect -> 0xe660), seq 8654:11534, ack 17, win 501, length 2880
  27. 14:54:04.416151 IP (tos 0x0, ttl 113, id 7955, offset 0, flags [DF], proto TCP (6), length 40)
  28. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x6ab7 (correct), ack 5774, win 510, length 0
  29. 14:54:04.416553 IP (tos 0x20, ttl 64, id 58040, offset 0, flags [DF], proto TCP (6), length 1480)
  30. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x3de3 (correct), seq 11534:12974, ack 17, win 501, length 1440
  31. 14:54:04.497201 IP (tos 0x20, ttl 64, id 26513, offset 0, flags [DF], proto TCP (6), length 46)
  32. 10.0.0.100.46786 > 93.67.88.190.60331: Flags [P.], cksum 0xd583 (correct), seq 1:7, ack 172, win 501, length 6
  33. 14:54:04.527799 IP (tos 0x0, ttl 113, id 7956, offset 0, flags [DF], proto TCP (6), length 52)
  34. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0xc88c (correct), ack 5774, win 510, options [nop,nop,sack 1 {7214:8654}], length 0
  35. 14:54:04.528224 IP (tos 0x20, ttl 64, id 58041, offset 0, flags [DF], proto TCP (6), length 1480)
  36. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x47ed (correct), seq 12974:14414, ack 17, win 501, length 1440
  37. 14:54:04.532822 IP (tos 0x0, ttl 113, id 7957, offset 0, flags [DF], proto TCP (6), length 52)
  38. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0xc2ec (correct), ack 5774, win 510, options [nop,nop,sack 1 {7214:10094}], length 0
  39. 14:54:04.533234 IP (tos 0x20, ttl 64, id 58042, offset 0, flags [DF], proto TCP (6), length 1480)
  40. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0xcd17 (correct), seq 14414:15854, ack 17, win 501, length 1440
  41. 14:54:04.534661 IP (tos 0x0, ttl 113, id 7958, offset 0, flags [DF], proto TCP (6), length 52)
  42. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0xbd4c (correct), ack 5774, win 510, options [nop,nop,sack 1 {7214:11534}], length 0
  43. 14:54:04.535092 IP (tos 0x20, ttl 64, id 58043, offset 0, flags [DF], proto TCP (6), length 1480)
  44. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x0bcb (correct), seq 5774:7214, ack 17, win 501, length 1440
  45. 14:54:04.563094 IP (tos 0x0, ttl 113, id 7959, offset 0, flags [DF], proto TCP (6), length 52)
  46. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0xb7ac (correct), ack 5774, win 510, options [nop,nop,sack 1 {7214:12974}], length 0
  47. 14:54:04.669161 IP (tos 0x0, ttl 113, id 7960, offset 0, flags [DF], proto TCP (6), length 52)
  48. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0xb20c (correct), ack 5774, win 510, options [nop,nop,sack 1 {7214:14414}], length 0
  49. 14:54:04.669569 IP (tos 0x20, ttl 64, id 58044, offset 0, flags [DF], proto TCP (6), length 584)
  50. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [P.], cksum 0x04da (correct), seq 15854:16398, ack 17, win 501, length 544
  51. 14:54:04.671369 IP (tos 0x0, ttl 113, id 7961, offset 0, flags [DF], proto TCP (6), length 52)
  52. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0xac6c (correct), ack 5774, win 510, options [nop,nop,sack 1 {7214:15854}], length 0
  53. 14:54:04.676102 IP (tos 0x0, ttl 113, id 7962, offset 0, flags [DF], proto TCP (6), length 40)
  54. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x4351 (correct), ack 15854, win 516, length 0
  55. 14:54:04.747566 IP (tos 0x0, ttl 49, id 11757, offset 0, flags [DF], proto TCP (6), length 108)
  56. 2.238.25.57.50548 > 10.0.0.100.46786: Flags [P.], cksum 0xab95 (correct), seq 1075102756:1075102824, ack 3508817585, win 1024, length 68
  57. 14:54:04.747773 IP (tos 0x20, ttl 64, id 25933, offset 0, flags [DF], proto TCP (6), length 40)
  58. 10.0.0.100.46786 > 2.238.25.57.50548: Flags [.], cksum 0xe6ca (correct), ack 68, win 501, length 0
  59. 14:54:04.748049 IP (tos 0x20, ttl 64, id 25934, offset 0, flags [DF], proto TCP (6), length 58)
  60. 10.0.0.100.46786 > 2.238.25.57.50548: Flags [P.], cksum 0x03cd (correct), seq 1:19, ack 68, win 501, length 18
  61. 14:54:04.801590 IP (tos 0x0, ttl 114, id 29427, offset 0, flags [DF], proto TCP (6), length 40)
  62. 93.67.88.190.60331 > 10.0.0.100.46786: Flags [.], cksum 0x1137 (correct), ack 7, win 16587, length 0
  63. 14:54:04.801957 IP (tos 0x20, ttl 64, id 26514, offset 0, flags [DF], proto TCP (6), length 191)
  64. 10.0.0.100.46786 > 93.67.88.190.60331: Flags [P.], cksum 0x5829 (correct), seq 7:158, ack 172, win 501, length 151
  65. 14:54:04.825439 IP (tos 0x0, ttl 113, id 7963, offset 0, flags [DF], proto TCP (6), length 40)
  66. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x4133 (correct), ack 16398, win 514, length 0
  67. 14:54:05.151090 IP (tos 0x0, ttl 114, id 30388, offset 0, flags [DF], proto TCP (6), length 40)
  68. 93.67.88.190.60331 > 10.0.0.100.46786: Flags [.], cksum 0x10c5 (correct), ack 158, win 16550, length 0
  69. 14:54:05.462298 IP (tos 0x0, ttl 49, id 11758, offset 0, flags [DF], proto TCP (6), length 40)
  70. 2.238.25.57.50548 > 10.0.0.100.46786: Flags [.], cksum 0xe4ad (correct), ack 19, win 1024, length 0
  71. 14:54:06.086112 IP (tos 0x0, ttl 52, id 56701, offset 0, flags [DF], proto TCP (6), length 106)
  72. 62.10.52.198.57514 > 10.0.0.100.46786: Flags [P.], cksum 0x42b4 (correct), seq 1688234044:1688234098, ack 674353255, win 2227, options [nop,nop,TS val 665364986 ecr 3213891298], length 54
  73. 14:54:06.086490 IP (tos 0x20, ttl 64, id 34749, offset 0, flags [DF], proto TCP (6), length 52)
  74. 10.0.0.100.46786 > 62.10.52.198.57514: Flags [.], cksum 0xba83 (correct), ack 54, win 501, options [nop,nop,TS val 3213905604 ecr 665364986], length 0
  75. 14:54:07.814568 IP (tos 0x0, ttl 113, id 12075, offset 0, flags [DF], proto TCP (6), length 193)
  76. 79.30.63.119.65057 > 10.0.0.100.46786: Flags [P.], cksum 0x9a91 (correct), seq 3614259085:3614259238, ack 683793620, win 511, length 153
  77. 14:54:07.814953 IP (tos 0x20, ttl 64, id 41503, offset 0, flags [DF], proto TCP (6), length 40)
  78. 10.0.0.100.46786 > 79.30.63.119.65057: Flags [.], cksum 0x4ad8 (correct), ack 153, win 501, length 0
  79. 14:54:07.970392 IP (tos 0x0, ttl 47, id 24111, offset 0, flags [DF], proto TCP (6), length 60)
  80. 37.161.219.6.8516 > 10.0.0.100.21: Flags [S], cksum 0x4c91 (correct), seq 803644623, win 65535, options [mss 1300,sackOK,TS val 1243872 ecr 0,nop,wscale 9], length 0
  81. 14:54:07.970670 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
  82. 10.0.0.100.21 > 37.161.219.6.8516: Flags [S.], cksum 0x588e (correct), seq 2639344104, ack 803644624, win 65160, options [mss 1460,sackOK,TS val 1506528197 ecr 1243872,nop,wscale 7], length 0
  83. 14:54:08.069448 IP (tos 0x0, ttl 47, id 24112, offset 0, flags [DF], proto TCP (6), length 52)
  84. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x852e (correct), ack 1, win 172, options [nop,nop,TS val 1243881 ecr 1506528197], length 0
  85. 14:54:08.075129 IP (tos 0x0, ttl 64, id 35389, offset 0, flags [DF], proto TCP (6), length 86)
  86. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0xda25 (correct), seq 1:35, ack 1, win 510, options [nop,nop,TS val 1506528302 ecr 1243881], length 34: FTP, length: 34
  87. 220 Welcome to Jorman FTP Server
  88. 14:54:08.168170 IP (tos 0x0, ttl 47, id 24113, offset 0, flags [DF], proto TCP (6), length 52)
  89. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x8498 (correct), ack 35, win 172, options [nop,nop,TS val 1243892 ecr 1506528302], length 0
  90. 14:54:08.196336 IP (tos 0x0, ttl 47, id 24114, offset 0, flags [DF], proto TCP (6), length 68)
  91. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xfca3 (correct), seq 1:17, ack 35, win 172, options [nop,nop,TS val 1243892 ecr 1506528302], length 16: FTP, length: 16
  92. USER anonymous
  93. 14:54:08.196690 IP (tos 0x0, ttl 64, id 35390, offset 0, flags [DF], proto TCP (6), length 52)
  94. 10.0.0.100.21 > 37.161.219.6.8516: Flags [.], cksum 0x82bd (correct), ack 17, win 510, options [nop,nop,TS val 1506528423 ecr 1243892], length 0
  95. 14:54:08.196695 IP (tos 0x0, ttl 64, id 35391, offset 0, flags [DF], proto TCP (6), length 86)
  96. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x3b72 (correct), seq 35:69, ack 17, win 510, options [nop,nop,TS val 1506528423 ecr 1243892], length 34: FTP, length: 34
  97. 331 Please specify the password.
  98. 14:54:08.310406 IP (tos 0x0, ttl 47, id 24115, offset 0, flags [DF], proto TCP (6), length 65)
  99. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0x6aeb (correct), seq 17:30, ack 69, win 172, options [nop,nop,TS val 1243905 ecr 1506528423], length 13: FTP, length: 13
  100. PASS ***
  101. 14:54:08.319751 IP (tos 0x0, ttl 64, id 35392, offset 0, flags [DF], proto TCP (6), length 75)
  102. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0xa06e (correct), seq 69:92, ack 30, win 510, options [nop,nop,TS val 1506528546 ecr 1243905], length 23: FTP, length: 23
  103. 230 Login successful.
  104. 14:54:08.359155 IP (tos 0x0, ttl 113, id 7964, offset 0, flags [DF], proto TCP (6), length 57)
  105. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [P.], cksum 0x15c0 (correct), seq 17:34, ack 16398, win 514, length 17
  106. 14:54:08.359724 IP (tos 0x20, ttl 64, id 58045, offset 0, flags [DF], proto TCP (6), length 4360)
  107. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x1093 (incorrect -> 0x01c6), seq 16398:20718, ack 34, win 501, length 4320
  108. 14:54:08.412099 IP (tos 0x0, ttl 47, id 24116, offset 0, flags [DF], proto TCP (6), length 58)
  109. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xee84 (correct), seq 30:36, ack 92, win 172, options [nop,nop,TS val 1243916 ecr 1506528546], length 6: FTP, length: 6
  110. FEAT
  111. 14:54:08.412423 IP (tos 0x0, ttl 64, id 35393, offset 0, flags [DF], proto TCP (6), length 67)
  112. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x573f (correct), seq 92:107, ack 36, win 510, options [nop,nop,TS val 1506528639 ecr 1243916], length 15: FTP, length: 15
  113. 211-Features:
  114. 14:54:08.412428 IP (tos 0x0, ttl 64, id 35394, offset 0, flags [DF], proto TCP (6), length 108)
  115. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x9207 (correct), seq 107:163, ack 36, win 510, options [nop,nop,TS val 1506528639 ecr 1243916], length 56: FTP, length: 56
  116. EPRT
  117. EPSV
  118. MDTM
  119. PASV
  120. REST STREAM
  121. SIZE
  122. TVFS
  123. 14:54:08.412677 IP (tos 0x0, ttl 64, id 35395, offset 0, flags [DF], proto TCP (6), length 61)
  124. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x6a5c (correct), seq 163:172, ack 36, win 510, options [nop,nop,TS val 1506528639 ecr 1243916], length 9: FTP, length: 9
  125. 211 End
  126. 14:54:08.485190 IP (tos 0x0, ttl 113, id 7965, offset 0, flags [DF], proto TCP (6), length 40)
  127. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x35e0 (correct), ack 19278, win 516, length 0
  128. 14:54:08.485632 IP (tos 0x20, ttl 64, id 58048, offset 0, flags [DF], proto TCP (6), length 2920)
  129. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x0af3 (incorrect -> 0x76e7), seq 20718:23598, ack 34, win 501, length 2880
  130. 14:54:08.511084 IP (tos 0x0, ttl 113, id 7966, offset 0, flags [DF], proto TCP (6), length 40)
  131. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x3046 (correct), ack 20718, win 510, length 0
  132. 14:54:08.511518 IP (tos 0x20, ttl 64, id 58050, offset 0, flags [DF], proto TCP (6), length 2920)
  133. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x0af3 (incorrect -> 0x7b7c), seq 23598:26478, ack 34, win 501, length 2880
  134. 14:54:08.519810 IP (tos 0x0, ttl 47, id 24117, offset 0, flags [DF], proto TCP (6), length 52)
  135. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x8282 (correct), ack 163, win 172, options [nop,nop,TS val 1243926 ecr 1506528639], length 0
  136. 14:54:08.519838 IP (tos 0x0, ttl 47, id 24118, offset 0, flags [DF], proto TCP (6), length 57)
  137. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xe407 (correct), seq 36:41, ack 172, win 172, options [nop,nop,TS val 1243926 ecr 1506528639], length 5: FTP, length: 5
  138. PWD
  139. 14:54:08.520306 IP (tos 0x0, ttl 64, id 35396, offset 0, flags [DF], proto TCP (6), length 86)
  140. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x86be (correct), seq 172:206, ack 41, win 510, options [nop,nop,TS val 1506528747 ecr 1243926], length 34: FTP, length: 34
  141. 257 "/" is the current directory
  142. 14:54:08.630353 IP (tos 0x0, ttl 47, id 24119, offset 0, flags [DF], proto TCP (6), length 58)
  143. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xd722 (correct), seq 41:47, ack 206, win 172, options [nop,nop,TS val 1243938 ecr 1506528747], length 6: FTP, length: 6
  144. NOOP
  145. 14:54:08.630780 IP (tos 0x0, ttl 64, id 35397, offset 0, flags [DF], proto TCP (6), length 66)
  146. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0xe766 (correct), seq 206:220, ack 47, win 510, options [nop,nop,TS val 1506528857 ecr 1243938], length 14: FTP, length: 14
  147. 200 NOOP ok.
  148. 14:54:08.641797 IP (tos 0x0, ttl 113, id 7967, offset 0, flags [DF], proto TCP (6), length 40)
  149. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x2500 (correct), ack 23598, win 516, length 0
  150. 14:54:08.642231 IP (tos 0x20, ttl 64, id 58052, offset 0, flags [DF], proto TCP (6), length 2920)
  151. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [.], cksum 0x0af3 (incorrect -> 0x97c5), seq 26478:29358, ack 34, win 501, length 2880
  152. 14:54:08.657571 IP (tos 0x0, ttl 113, id 7968, offset 0, flags [DF], proto TCP (6), length 40)
  153. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x19c0 (correct), ack 26478, win 516, length 0
  154. 14:54:08.657954 IP (tos 0x20, ttl 64, id 58054, offset 0, flags [DF], proto TCP (6), length 3477)
  155. 10.0.0.100.46786 > 79.35.166.17.62192: Flags [P.], cksum 0x0d20 (incorrect -> 0x3a5f), seq 29358:32795, ack 34, win 501, length 3437
  156. 14:54:08.740772 IP (tos 0x0, ttl 47, id 24120, offset 0, flags [DF], proto TCP (6), length 59)
  157. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xc0ba (correct), seq 47:54, ack 220, win 172, options [nop,nop,TS val 1243948 ecr 1506528857], length 7: FTP, length: 7
  158. CWD /
  159. 14:54:08.741236 IP (tos 0x0, ttl 64, id 35398, offset 0, flags [DF], proto TCP (6), length 89)
  160. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0xf3f7 (correct), seq 220:257, ack 54, win 510, options [nop,nop,TS val 1506528968 ecr 1243948], length 37: FTP, length: 37
  161. 250 Directory successfully changed.
  162. 14:54:08.750745 IP (tos 0x0, ttl 113, id 7969, offset 0, flags [DF], proto TCP (6), length 40)
  163. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x0e80 (correct), ack 29358, win 516, length 0
  164. 14:54:08.757635 IP (tos 0x0, ttl 113, id 7970, offset 0, flags [DF], proto TCP (6), length 40)
  165. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x0340 (correct), ack 32238, win 516, length 0
  166. 14:54:08.812643 IP (tos 0x0, ttl 113, id 7971, offset 0, flags [DF], proto TCP (6), length 40)
  167. 79.35.166.17.62192 > 10.0.0.100.46786: Flags [.], cksum 0x0116 (correct), ack 32795, win 513, length 0
  168. 14:54:08.849663 IP (tos 0x0, ttl 47, id 24121, offset 0, flags [DF], proto TCP (6), length 58)
  169. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xebf5 (correct), seq 54:60, ack 257, win 172, options [nop,nop,TS val 1243960 ecr 1506528968], length 6: FTP, length: 6
  170. FEAT
  171. 14:54:08.850093 IP (tos 0x0, ttl 64, id 35399, offset 0, flags [DF], proto TCP (6), length 67)
  172. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x54a1 (correct), seq 257:272, ack 60, win 510, options [nop,nop,TS val 1506529076 ecr 1243960], length 15: FTP, length: 15
  173. 211-Features:
  174. 14:54:08.850098 IP (tos 0x0, ttl 64, id 35400, offset 0, flags [DF], proto TCP (6), length 117)
  175. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x7892 (correct), seq 272:337, ack 60, win 510, options [nop,nop,TS val 1506529077 ecr 1243960], length 65: FTP, length: 65
  176. EPRT
  177. EPSV
  178. MDTM
  179. PASV
  180. REST STREAM
  181. SIZE
  182. TVFS
  183. 211 End
  184. 14:54:08.968409 IP (tos 0x0, ttl 47, id 24122, offset 0, flags [DF], proto TCP (6), length 52)
  185. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x7fdb (correct), ack 337, win 172, options [nop,nop,TS val 1243970 ecr 1506529076], length 0
  186. 14:54:08.975604 IP (tos 0x0, ttl 47, id 24123, offset 0, flags [DF], proto TCP (6), length 58)
  187. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xcc15 (correct), seq 60:66, ack 337, win 172, options [nop,nop,TS val 1243970 ecr 1506529076], length 6: FTP, length: 6
  188. SYST
  189. 14:54:08.976034 IP (tos 0x0, ttl 64, id 35401, offset 0, flags [DF], proto TCP (6), length 71)
  190. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x169a (correct), seq 337:356, ack 66, win 510, options [nop,nop,TS val 1506529202 ecr 1243970], length 19: FTP, length: 19
  191. 215 UNIX Type: L8
  192. 14:54:09.089800 IP (tos 0x0, ttl 47, id 24124, offset 0, flags [DF], proto TCP (6), length 58)
  193. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xce86 (correct), seq 66:72, ack 356, win 172, options [nop,nop,TS val 1243984 ecr 1506529202], length 6: FTP, length: 6
  194. PASV
  195. 14:54:09.090191 IP (tos 0x0, ttl 64, id 35402, offset 0, flags [DF], proto TCP (6), length 100)
  196. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x29f8 (correct), seq 356:404, ack 72, win 510, options [nop,nop,TS val 1506529317 ecr 1243984], length 48: FTP, length: 48
  197. 227 Entering Passive Mode (10,0,0,100,158,54).
  198. 14:54:09.199582 IP (tos 0x0, ttl 47, id 3405, offset 0, flags [DF], proto TCP (6), length 60)
  199. 37.161.219.6.8521 > 10.0.0.100.40502: Flags [S], cksum 0x8f66 (correct), seq 4247254551, win 65535, options [mss 1300,sackOK,TS val 1243994 ecr 0,nop,wscale 9], length 0
  200. 14:54:09.199953 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
  201. 10.0.0.100.40502 > 37.161.219.6.8521: Flags [S.], cksum 0x5f1e (correct), seq 1328068489, ack 4247254552, win 65160, options [mss 1460,sackOK,TS val 1506529426 ecr 1243994,nop,wscale 7], length 0
  202. 14:54:09.219158 IP (tos 0x0, ttl 47, id 24125, offset 0, flags [DF], proto TCP (6), length 52)
  203. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x7e80 (correct), ack 404, win 172, options [nop,nop,TS val 1243997 ecr 1506529317], length 0
  204. 14:54:09.323316 IP (tos 0x0, ttl 47, id 3406, offset 0, flags [DF], proto TCP (6), length 52)
  205. 37.161.219.6.8521 > 10.0.0.100.40502: Flags [.], cksum 0x8bbd (correct), ack 1, win 172, options [nop,nop,TS val 1244004 ecr 1506529426], length 0
  206. 14:54:09.330479 IP (tos 0x0, ttl 47, id 24126, offset 0, flags [DF], proto TCP (6), length 58)
  207. 37.161.219.6.8516 > 10.0.0.100.21: Flags [P.], cksum 0xd1c3 (correct), seq 72:78, ack 404, win 172, options [nop,nop,TS val 1244004 ecr 1506529317], length 6: FTP, length: 6
  208. LIST
  209. 14:54:09.331274 IP (tos 0x0, ttl 64, id 35403, offset 0, flags [DF], proto TCP (6), length 91)
  210. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0x66e3 (correct), seq 404:443, ack 78, win 510, options [nop,nop,TS val 1506529558 ecr 1244004], length 39: FTP, length: 39
  211. 150 Here comes the directory listing.
  212. 14:54:09.331279 IP (tos 0x8, ttl 64, id 58045, offset 0, flags [DF], proto TCP (6), length 244)
  213. 10.0.0.100.40502 > 37.161.219.6.8521: Flags [P.], cksum 0x3f83 (correct), seq 1:193, ack 1, win 510, options [nop,nop,TS val 1506529558 ecr 1244004], length 192
  214. 14:54:09.331283 IP (tos 0x8, ttl 64, id 58046, offset 0, flags [DF], proto TCP (6), length 52)
  215. 10.0.0.100.40502 > 37.161.219.6.8521: Flags [F.], cksum 0x8926 (correct), seq 193, ack 1, win 510, options [nop,nop,TS val 1506529558 ecr 1244004], length 0
  216. 14:54:09.423315 IP (tos 0x0, ttl 47, id 24127, offset 0, flags [DF], proto TCP (6), length 52)
  217. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x7d4d (correct), ack 443, win 172, options [nop,nop,TS val 1244018 ecr 1506529558], length 0
  218. 14:54:09.438618 IP (tos 0x0, ttl 47, id 3407, offset 0, flags [DF], proto TCP (6), length 52)
  219. 37.161.219.6.8521 > 10.0.0.100.40502: Flags [.], cksum 0x8a69 (correct), ack 193, win 174, options [nop,nop,TS val 1244018 ecr 1506529558], length 0
  220. 14:54:09.439889 IP (tos 0x0, ttl 47, id 3408, offset 0, flags [DF], proto TCP (6), length 52)
  221. 37.161.219.6.8521 > 10.0.0.100.40502: Flags [F.], cksum 0x8a67 (correct), seq 1, ack 194, win 174, options [nop,nop,TS val 1244018 ecr 1506529558], length 0
  222. 14:54:09.440272 IP (tos 0x8, ttl 64, id 58047, offset 0, flags [DF], proto TCP (6), length 52)
  223. 10.0.0.100.40502 > 37.161.219.6.8521: Flags [.], cksum 0x88aa (correct), ack 2, win 510, options [nop,nop,TS val 1506529667 ecr 1244018], length 0
  224. 14:54:09.440278 IP (tos 0x0, ttl 64, id 35404, offset 0, flags [DF], proto TCP (6), length 76)
  225. 10.0.0.100.21 > 37.161.219.6.8516: Flags [P.], cksum 0xb5f4 (correct), seq 443:467, ack 78, win 510, options [nop,nop,TS val 1506529667 ecr 1244018], length 24: FTP, length: 24
  226. 226 Directory send OK.
  227. 14:54:09.531311 IP (tos 0x0, ttl 47, id 24128, offset 0, flags [DF], proto TCP (6), length 52)
  228. 37.161.219.6.8516 > 10.0.0.100.21: Flags [.], cksum 0x7cbe (correct), ack 467, win 172, options [nop,nop,TS val 1244028 ecr 1506529667], length 0
  229. ^C
  230. 94 packets captured
  231. 112 packets received by filter
  232. 0 packets dropped by kernel
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement