Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Script started on Tue Aug 18 13:58:38 2015
- sh -c tcpdump -s0 -i em1 -lenxp host mail.stadium-live.ru and port 25 | tcpshow -cooked -noHostNames
- tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
- listening on em1, link-type EN10MB (Ethernet), capture size 65535 bytes
- ---------------------------------------------------------------------------
- Packet 1
- TIME: 13:58:54.102627
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=60 id=8B82
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=187C
- TCP: port 55192 -> smtp seq=2017905657 ack=0000000000
- hlen=40 (data=0) UAPRSF=000010 wnd=65535 cksum=96EC urg=0
- DATA: <No data>
- ---------------------------------------------------------------------------
- Packet 2
- TIME: 13:58:54.204787 (0.102160)
- LINK: CC:CC:81:70:54:39 -> 00:25:90:34:97:DB type=IPv4
- IP: 78.24.157.10 -> 78.111.93.44 hlen=20 TOS=00 dgramlen=60 id=2040
- MF/DF=0/1 frag=0 TTL=121 proto=TCP cksum=4ABE
- TCP: port smtp -> 55192 seq=2994491985 ack=2017905658
- hlen=40 (data=0) UAPRSF=010010 wnd=8192 cksum=F5A3 urg=0
- DATA: <No data>
- ---------------------------------------------------------------------------
- Packet 3
- TIME: 13:58:54.204826 (0.000039)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=52 id=8B97
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=186F
- TCP: port 55192 -> smtp seq=2017905658 ack=2994491986
- hlen=32 (data=0) UAPRSF=010000 wnd=8208 cksum=96E4 urg=0
- DATA: <No data>
- ---------------------------------------------------------------------------
- Packet 4
- TIME: 13:58:54.409257 (0.204431)
- LINK: CC:CC:81:70:54:39 -> 00:25:90:34:97:DB type=IPv4
- IP: 78.24.157.10 -> 78.111.93.44 hlen=20 TOS=00 dgramlen=146 id=2046
- MF/DF=0/1 frag=0 TTL=121 proto=TCP cksum=4A62
- TCP: port smtp -> 55192 seq=2994491986 ack=2017905658
- hlen=32 (data=94) UAPRSF=011000 wnd=513 cksum=92AF urg=0
- DATA: 220 ********************************************************
- ********************************.
- ---------------------------------------------------------------------------
- Packet 5
- TIME: 13:58:54.409328 (0.000071)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=70 id=8BCB
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=1829
- TCP: port 55192 -> smtp seq=2017905658 ack=2994492080
- hlen=32 (data=18) UAPRSF=011000 wnd=8208 cksum=96F6 urg=0
- DATA: EHLO mail.nca.ru.
- ---------------------------------------------------------------------------
- Packet 6
- TIME: 13:58:54.611831 (0.202503)
- LINK: CC:CC:81:70:54:39 -> 00:25:90:34:97:DB type=IPv4
- IP: 78.24.157.10 -> 78.111.93.44 hlen=20 TOS=00 dgramlen=311 id=204A
- MF/DF=0/1 frag=0 TTL=121 proto=TCP cksum=49B9
- TCP: port smtp -> 55192 seq=2994492080 ack=2017905676
- hlen=32 (data=259) UAPRSF=011000 wnd=512 cksum=2979 urg=0
- DATA: 250-srv-ex1.stadium.ru Hello [78.111.93.44].
- 250-SIZE.
- 250-PIPELINING.
- 250-DSN.
- 250-ENHANCEDSTATUSCODES.
- 250-XXXXXXXA.
- 250-XXXXXXXXXXXXXB.
- 250-AUTH NTLM.
- 250-XXXXXXXXXXXXXXXXXC.
- 250-8BITMIME.
- 250-BINARYMIME.
- 250-XXXXXXXD.
- 250-XXXXXXE.
- 250-XXXXF.
- 250 XXXXXXG.
- ---------------------------------------------------------------------------
- Packet 7
- TIME: 13:58:54.611937 (0.000106)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=179 id=8BDB
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=17AC
- TCP: port 55192 -> smtp seq=2017905676 ack=2994492339
- hlen=32 (data=127) UAPRSF=011000 wnd=8208 cksum=9763 urg=0
- DATA: MAIL FROM:<it@nca.ru> SIZE=1867 BODY=7BIT.
- RCPT TO:<a.balashov@stadium-live.ru> ORCPT=rfc822;a.balashov
- @stadium-live.ru.
- DATA.
- ---------------------------------------------------------------------------
- Packet 8
- TIME: 13:58:54.824575 (0.212638)
- LINK: CC:CC:81:70:54:39 -> 00:25:90:34:97:DB type=IPv4
- IP: 78.24.157.10 -> 78.111.93.44 hlen=20 TOS=00 dgramlen=143 id=204E
- MF/DF=0/1 frag=0 TTL=121 proto=TCP cksum=4A5D
- TCP: port smtp -> 55192 seq=2994492339 ack=2017905803
- hlen=32 (data=91) UAPRSF=011000 wnd=512 cksum=E8AE urg=0
- DATA: 250 2.1.0 Sender OK.
- 250 2.1.5 Recipient OK.
- 354 Start mail input; end with <CRLF>.<CRLF>.
- ---------------------------------------------------------------------------
- Packet 9
- TIME: 13:58:54.824663 (0.000088)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=0 id=8BF9
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=0000
- TCP: port 55192 -> smtp seq=2017905803 ack=2994492430
- hlen=32 (data=4294967244) UAPRSF=011000 wnd=8208 cksum=96C4 urg=0
- DATA:
- ---------------------------------------------------------------------------
- Packet 10
- TIME: 13:58:55.499307 (0.674644)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=1420 id=8C3C
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=1272
- TCP: port 55192 -> smtp seq=2017905803 ack=2994492430
- hlen=32 (data=1368) UAPRSF=010000 wnd=8208 cksum=9C3C urg=0
- DATA: Received: from ncamail.office.local (localhost [127.0.0.1]).
- by mail.nca.ru (Postfix) with ESMTP id 166013F4F5.
- for <a.balashov@stadium-live.ru>; Tue, 18 Aug 2015 13:58:54
- +0300 (MSK).
- Authentication-Results: ncamail.office.local (amavisd-new);.
- dkim=pass (1024-bit key) reason="pass (just generated, assu
- med good)".
- header.d=nca.ru.
- DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nca.r
- u; h=.
- content-transfer-encoding:content-type:content-type:subject
- .
- :subject:mime-version:user-agent:from:from:date:date:messag
- e-id.
- :received:received; s=nca; t=1439895533; bh=maYKk1uz/pALYBi
- HmbV+.
- 6ft+9tfykShPzwVQlktOUB8=; b=XEO85ShFhyehOSnNC1f167CuYmk59B8
- /0P94.
- cmBVUxqcXpBqdcJ3SphkUHoYM/IhdveIjev/yasnsVJJs8XyC60RPrvCbzA
- 3sHgi.
- zzut7jDTsHK/YcIEqKFKXt5JI4UGhiy9aAGkRLtmUQMrjUNYd4xX6pTHxJC
- dl925.
- NDcIScs=.
- X-Virus-Scanned: amavisd-new at office.local.
- Received: from mail.nca.ru ([127.0.0.1]).
- by ncamail.office.local (ncamail.office.local [127.0.0.1])
- (amavisd-new, port 10026).
- with ESMTP id cGJeuawqZRsz for <a.balashov@stadium-live.ru>
- ;.
- Tue, 18 Aug 2015 13:58:53 +0300 (MSK).
- Received: from backupsrv.office.local (backupsrv.office.loca
- l [192.168.253.15]).
- (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 b
- its)).
- (No client certificate requested).
- by mail.nca.ru (Postfix) with ESMTPSA id E106C3F4F4.
- for <a.balashov@stadium-live.ru>; Tue,
- ---------------------------------------------------------------------------
- Packet 11
- TIME: 13:58:56.648752 (1.149445)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=1420 id=8C90
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=121E
- TCP: port 55192 -> smtp seq=2017905803 ack=2994492430
- hlen=32 (data=1368) UAPRSF=010000 wnd=8208 cksum=9C3C urg=0
- DATA: Received: from ncamail.office.local (localhost [127.0.0.1]).
- by mail.nca.ru (Postfix) with ESMTP id 166013F4F5.
- for <a.balashov@stadium-live.ru>; Tue, 18 Aug 2015 13:58:54
- +0300 (MSK).
- Authentication-Results: ncamail.office.local (amavisd-new);.
- dkim=pass (1024-bit key) reason="pass (just generated, assu
- med good)".
- header.d=nca.ru.
- DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nca.r
- u; h=.
- content-transfer-encoding:content-type:content-type:subject
- .
- :subject:mime-version:user-agent:from:from:date:date:messag
- e-id.
- :received:received; s=nca; t=1439895533; bh=maYKk1uz/pALYBi
- HmbV+.
- 6ft+9tfykShPzwVQlktOUB8=; b=XEO85ShFhyehOSnNC1f167CuYmk59B8
- /0P94.
- cmBVUxqcXpBqdcJ3SphkUHoYM/IhdveIjev/yasnsVJJs8XyC60RPrvCbzA
- 3sHgi.
- zzut7jDTsHK/YcIEqKFKXt5JI4UGhiy9aAGkRLtmUQMrjUNYd4xX6pTHxJC
- dl925.
- NDcIScs=.
- X-Virus-Scanned: amavisd-new at office.local.
- Received: from mail.nca.ru ([127.0.0.1]).
- by ncamail.office.local (ncamail.office.local [127.0.0.1])
- (amavisd-new, port 10026).
- with ESMTP id cGJeuawqZRsz for <a.balashov@stadium-live.ru>
- ;.
- Tue, 18 Aug 2015 13:58:53 +0300 (MSK).
- Received: from backupsrv.office.local (backupsrv.office.loca
- l [192.168.253.15]).
- (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 b
- its)).
- (No client certificate requested).
- by mail.nca.ru (Postfix) with ESMTPSA id E106C3F4F4.
- for <a.balashov@stadium-live.ru>; Tue,
- ---------------------------------------------------------------------------
- Packet 12
- TIME: 13:58:58.745974 (2.097222)
- LINK: 00:25:90:34:97:DB -> CC:CC:81:70:54:39 type=IPv4
- IP: 78.111.93.44 -> 78.24.157.10 hlen=20 TOS=00 dgramlen=1420 id=8CBA
- MF/DF=0/1 frag=0 TTL=64 proto=TCP cksum=11F4
- TCP: port 55192 -> smtp seq=2017905803 ack=2994492430
- hlen=32 (data=1368) UAPRSF=010000 wnd=8208 cksum=9C3C urg=0
- DATA: Received: from ncamail.office.local (localhost [127.0.0.1]).
- by mail.nca.ru (Postfix) with ESMTP id 166013F4F5.
- for <a.balashov@stadium-live.ru>; Tue, 18 Aug 2015 13:58:54
- +0300 (MSK).
- Authentication-Results: ncamail.office.local (amavisd-new);.
- dkim=pass (1024-bit key) reason="pass (just generated, assu
- med good)".
- header.d=nca.ru.
- DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nca.r
- u; h=.
- content-transfer-encoding:content-type:content-type:subject
- .
- :subject:mime-version:user-agent:from:from:date:date:messag
- e-id.
- :received:received; s=nca; t=1439895533; bh=maYKk1uz/pALYBi
- HmbV+.
- 6ft+9tfykShPzwVQlktOUB8=; b=XEO85ShFhyehOSnNC1f167CuYmk59B8
- /0P94.
- cmBVUxqcXpBqdcJ3SphkUHoYM/IhdveIjev/yasnsVJJs8XyC60RPrvCbzA
- 3sHgi.
- zzut7jDTsHK/YcIEqKFKXt5JI4UGhiy9aAGkRLtmUQMrjUNYd4xX6pTHxJC
- dl925.
- NDcIScs=.
- X-Virus-Scanned: amavisd-new at office.local.
- Received: from mail.nca.ru ([127.0.0.1]).
- by ncamail.office.local (ncamail.office.local [127.0.0.1])
- (amavisd-new, port 10026).
- with ESMTP id cGJeuawqZRsz for <a.balashov@stadium-live.ru>
- ;.
- Tue, 18 Aug 2015 13:58:53 +0300 (MSK).
- Received: from backupsrv.office.local (backupsrv.office.loca
- l [192.168.253.15]).
- (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 b
- its)).
- (No client certificate requested).
- by mail.nca.ru (Postfix) with ESMTPSA id E106C3F4F4.
- for <a.balashov@stadium-live.ru>; Tue,
- ---------------------------------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement