Advertisement
Guest User

Untitled

a guest
Mar 28th, 2020
145
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.98 KB | None | 0 0
  1. root@OpenWrt:~# tcpdump -i eth0.2 -vn host 37.160.207.143
  2. tcpdump: listening on eth0.2, link-type EN10MB (Ethernet), capture size 262144 bytes
  3. 14:25:28.308722 IP (tos 0x0, ttl 48, id 2286, offset 0, flags [DF], proto TCP (6), length 60)
  4. 37.160.207.143.48616 > 192.168.1.138.21: Flags [S], cksum 0x46d4 (correct), seq 2540271178, win 65535, options [mss 1300,sackOK,TS val 1212068 ecr 0,nop,wscale 9], length 0
  5. 14:25:28.309378 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6), length 60)
  6. 192.168.1.138.21 > 37.160.207.143.48616: Flags [S.], cksum 0x1a16 (correct), seq 3702068538, ack 2540271179, win 65160, options [mss 1460,sackOK,TS val 557652581 ecr 1212068,nop,wscale 7], length 0
  7. 14:25:28.496119 IP (tos 0x0, ttl 48, id 2287, offset 0, flags [DF], proto TCP (6), length 52)
  8. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x46ad (correct), ack 1, win 172, options [nop,nop,TS val 1212086 ecr 557652581], length 0
  9. 14:25:28.502629 IP (tos 0x0, ttl 63, id 60522, offset 0, flags [DF], proto TCP (6), length 86)
  10. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x9b4c (correct), seq 1:35, ack 1, win 510, options [nop,nop,TS val 557652774 ecr 1212086], length 34: FTP, length: 34
  11. 220 Welcome to Jorman FTP Server
  12. 14:25:28.602006 IP (tos 0x0, ttl 48, id 2288, offset 0, flags [DF], proto TCP (6), length 52)
  13. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x45bc (correct), ack 35, win 172, options [nop,nop,TS val 1212100 ecr 557652774], length 0
  14. 14:25:28.606812 IP (tos 0x0, ttl 48, id 2289, offset 0, flags [DF], proto TCP (6), length 68)
  15. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0xbdc7 (correct), seq 1:17, ack 35, win 172, options [nop,nop,TS val 1212100 ecr 557652774], length 16: FTP, length: 16
  16. USER anonymous
  17. 14:25:28.607285 IP (tos 0x0, ttl 63, id 60523, offset 0, flags [DF], proto TCP (6), length 52)
  18. 192.168.1.138.21 > 37.160.207.143.48616: Flags [.], cksum 0x43f2 (correct), ack 17, win 510, options [nop,nop,TS val 557652878 ecr 1212100], length 0
  19. 14:25:28.607707 IP (tos 0x0, ttl 63, id 60524, offset 0, flags [DF], proto TCP (6), length 86)
  20. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0xfca5 (correct), seq 35:69, ack 17, win 510, options [nop,nop,TS val 557652879 ecr 1212100], length 34: FTP, length: 34
  21. 331 Please specify the password.
  22. 14:25:28.715925 IP (tos 0x0, ttl 48, id 2290, offset 0, flags [DF], proto TCP (6), length 65)
  23. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0x2c21 (correct), seq 17:30, ack 69, win 172, options [nop,nop,TS val 1212111 ecr 557652879], length 13: FTP, length: 13
  24. PASS ***
  25. 14:25:28.724648 IP (tos 0x0, ttl 63, id 60525, offset 0, flags [DF], proto TCP (6), length 75)
  26. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x61aa (correct), seq 69:92, ack 30, win 510, options [nop,nop,TS val 557652996 ecr 1212111], length 23: FTP, length: 23
  27. 230 Login successful.
  28. 14:25:28.854118 IP (tos 0x0, ttl 48, id 2291, offset 0, flags [DF], proto TCP (6), length 58)
  29. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0xafbe (correct), seq 30:36, ack 92, win 172, options [nop,nop,TS val 1212124 ecr 557652996], length 6: FTP, length: 6
  30. FEAT
  31. 14:25:28.854979 IP (tos 0x0, ttl 63, id 60526, offset 0, flags [DF], proto TCP (6), length 67)
  32. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x1854 (correct), seq 92:107, ack 36, win 510, options [nop,nop,TS val 557653126 ecr 1212124], length 15: FTP, length: 15
  33. 211-Features:
  34. 14:25:28.855004 IP (tos 0x0, ttl 63, id 60527, offset 0, flags [DF], proto TCP (6), length 117)
  35. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x3c46 (correct), seq 107:172, ack 36, win 510, options [nop,nop,TS val 557653126 ecr 1212124], length 65: FTP, length: 65
  36. EPRT
  37. EPSV
  38. MDTM
  39. PASV
  40. REST STREAM
  41. SIZE
  42. TVFS
  43. 211 End
  44. 14:25:28.953435 IP (tos 0x0, ttl 48, id 2292, offset 0, flags [DF], proto TCP (6), length 52)
  45. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x438d (correct), ack 172, win 172, options [nop,nop,TS val 1212135 ecr 557653126], length 0
  46. 14:25:28.960917 IP (tos 0x0, ttl 48, id 2293, offset 0, flags [DF], proto TCP (6), length 57)
  47. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0xa51b (correct), seq 36:41, ack 172, win 172, options [nop,nop,TS val 1212135 ecr 557653126], length 5: FTP, length: 5
  48. PWD
  49. 14:25:28.961515 IP (tos 0x0, ttl 63, id 60528, offset 0, flags [DF], proto TCP (6), length 86)
  50. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x47d3 (correct), seq 172:206, ack 41, win 510, options [nop,nop,TS val 557653233 ecr 1212135], length 34: FTP, length: 34
  51. 257 "/" is the current directory
  52. 14:25:29.092581 IP (tos 0x0, ttl 48, id 2294, offset 0, flags [DF], proto TCP (6), length 58)
  53. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0x9836 (correct), seq 41:47, ack 206, win 172, options [nop,nop,TS val 1212148 ecr 557653233], length 6: FTP, length: 6
  54. NOOP
  55. 14:25:29.093414 IP (tos 0x0, ttl 63, id 60529, offset 0, flags [DF], proto TCP (6), length 66)
  56. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0xa864 (correct), seq 206:220, ack 47, win 510, options [nop,nop,TS val 557653365 ecr 1212148], length 14: FTP, length: 14
  57. 200 NOOP ok.
  58. 14:25:29.200974 IP (tos 0x0, ttl 48, id 2295, offset 0, flags [DF], proto TCP (6), length 59)
  59. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0x81b6 (correct), seq 47:54, ack 220, win 172, options [nop,nop,TS val 1212160 ecr 557653365], length 7: FTP, length: 7
  60. CWD /
  61. 14:25:29.201774 IP (tos 0x0, ttl 63, id 60530, offset 0, flags [DF], proto TCP (6), length 89)
  62. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0xb4f6 (correct), seq 220:257, ack 54, win 510, options [nop,nop,TS val 557653473 ecr 1212160], length 37: FTP, length: 37
  63. 250 Directory successfully changed.
  64. 14:25:29.316128 IP (tos 0x0, ttl 48, id 2296, offset 0, flags [DF], proto TCP (6), length 58)
  65. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0xacf5 (correct), seq 54:60, ack 257, win 172, options [nop,nop,TS val 1212171 ecr 557653473], length 6: FTP, length: 6
  66. FEAT
  67. 14:25:29.316629 IP (tos 0x0, ttl 63, id 60531, offset 0, flags [DF], proto TCP (6), length 67)
  68. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x159a (correct), seq 257:272, ack 60, win 510, options [nop,nop,TS val 557653588 ecr 1212171], length 15: FTP, length: 15
  69. 211-Features:
  70. 14:25:29.316735 IP (tos 0x0, ttl 63, id 60532, offset 0, flags [DF], proto TCP (6), length 117)
  71. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x398c (correct), seq 272:337, ack 60, win 510, options [nop,nop,TS val 557653588 ecr 1212171], length 65: FTP, length: 65
  72. EPRT
  73. EPSV
  74. MDTM
  75. PASV
  76. REST STREAM
  77. SIZE
  78. TVFS
  79. 211 End
  80. 14:25:29.425918 IP (tos 0x0, ttl 48, id 2297, offset 0, flags [DF], proto TCP (6), length 52)
  81. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x40d3 (correct), ack 337, win 172, options [nop,nop,TS val 1212182 ecr 557653588], length 0
  82. 14:25:29.433654 IP (tos 0x0, ttl 48, id 2298, offset 0, flags [DF], proto TCP (6), length 58)
  83. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0x8d0d (correct), seq 60:66, ack 337, win 172, options [nop,nop,TS val 1212182 ecr 557653588], length 6: FTP, length: 6
  84. SYST
  85. 14:25:29.434217 IP (tos 0x0, ttl 63, id 60533, offset 0, flags [DF], proto TCP (6), length 71)
  86. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0xd79a (correct), seq 337:356, ack 66, win 510, options [nop,nop,TS val 557653705 ecr 1212182], length 19: FTP, length: 19
  87. 215 UNIX Type: L8
  88. 14:25:29.566621 IP (tos 0x0, ttl 48, id 2299, offset 0, flags [DF], proto TCP (6), length 58)
  89. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0x8f8a (correct), seq 66:72, ack 356, win 172, options [nop,nop,TS val 1212193 ecr 557653705], length 6: FTP, length: 6
  90. PASV
  91. 14:25:29.567383 IP (tos 0x0, ttl 63, id 60534, offset 0, flags [DF], proto TCP (6), length 100)
  92. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0xeae3 (correct), seq 356:404, ack 72, win 510, options [nop,nop,TS val 557653839 ecr 1212193], length 48: FTP, length: 48
  93. 227 Entering Passive Mode (10,0,0,100,174,97).
  94. 14:25:29.691030 IP (tos 0x0, ttl 48, id 46324, offset 0, flags [DF], proto TCP (6), length 60)
  95. 37.160.207.143.48625 > 192.168.1.138.44641: Flags [S], cksum 0x93cc (correct), seq 1174391771, win 65535, options [mss 1300,sackOK,TS val 1212207 ecr 0,nop,wscale 9], length 0
  96. 14:25:29.691538 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6), length 60)
  97. 192.168.1.138.44641 > 37.160.207.143.48625: Flags [S.], cksum 0xb105 (correct), seq 1494567281, ack 1174391772, win 65160, options [mss 1460,sackOK,TS val 557653963 ecr 1212207,nop,wscale 7], length 0
  98. 14:25:29.729587 IP (tos 0x0, ttl 48, id 2300, offset 0, flags [DF], proto TCP (6), length 52)
  99. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x3f6c (correct), ack 404, win 172, options [nop,nop,TS val 1212211 ecr 557653839], length 0
  100. 14:25:29.811084 IP (tos 0x0, ttl 48, id 46325, offset 0, flags [DF], proto TCP (6), length 52)
  101. 37.160.207.143.48625 > 192.168.1.138.44641: Flags [.], cksum 0xdda2 (correct), ack 1, win 172, options [nop,nop,TS val 1212219 ecr 557653963], length 0
  102. 14:25:29.811661 IP (tos 0x0, ttl 48, id 2301, offset 0, flags [DF], proto TCP (6), length 58)
  103. 37.160.207.143.48616 > 192.168.1.138.21: Flags [P.], cksum 0x92ae (correct), seq 72:78, ack 404, win 172, options [nop,nop,TS val 1212219 ecr 557653839], length 6: FTP, length: 6
  104. LIST
  105. 14:25:29.812588 IP (tos 0x0, ttl 63, id 60535, offset 0, flags [DF], proto TCP (6), length 91)
  106. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x27ca (correct), seq 404:443, ack 78, win 510, options [nop,nop,TS val 557654084 ecr 1212219], length 39: FTP, length: 39
  107. 150 Here comes the directory listing.
  108. 14:25:29.812872 IP (tos 0x8, ttl 63, id 58681, offset 0, flags [DF], proto TCP (6), length 244)
  109. 192.168.1.138.44641 > 37.160.207.143.48625: Flags [P.], cksum 0x9173 (correct), seq 1:193, ack 1, win 510, options [nop,nop,TS val 557654084 ecr 1212219], length 192
  110. 14:25:29.812897 IP (tos 0x8, ttl 63, id 58682, offset 0, flags [DF], proto TCP (6), length 52)
  111. 192.168.1.138.44641 > 37.160.207.143.48625: Flags [F.], cksum 0xdb16 (correct), seq 193, ack 1, win 510, options [nop,nop,TS val 557654084 ecr 1212219], length 0
  112. 14:25:29.917674 IP (tos 0x0, ttl 48, id 46326, offset 0, flags [DF], proto TCP (6), length 52)
  113. 37.160.207.143.48625 > 192.168.1.138.44641: Flags [.], cksum 0xdc5c (correct), ack 193, win 174, options [nop,nop,TS val 1212230 ecr 557654084], length 0
  114. 14:25:29.917679 IP (tos 0x0, ttl 48, id 46327, offset 0, flags [DF], proto TCP (6), length 52)
  115. 37.160.207.143.48625 > 192.168.1.138.44641: Flags [F.], cksum 0xdc59 (correct), seq 1, ack 194, win 174, options [nop,nop,TS val 1212231 ecr 557654084], length 0
  116. 14:25:29.917684 IP (tos 0x0, ttl 48, id 2302, offset 0, flags [DF], proto TCP (6), length 52)
  117. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x3e37 (correct), ack 443, win 172, options [nop,nop,TS val 1212230 ecr 557654084], length 0
  118. 14:25:29.918146 IP (tos 0x8, ttl 63, id 58683, offset 0, flags [DF], proto TCP (6), length 52)
  119. 192.168.1.138.44641 > 37.160.207.143.48625: Flags [.], cksum 0xdaa0 (correct), ack 2, win 510, options [nop,nop,TS val 557654189 ecr 1212231], length 0
  120. 14:25:29.918173 IP (tos 0x0, ttl 63, id 60536, offset 0, flags [DF], proto TCP (6), length 76)
  121. 192.168.1.138.21 > 37.160.207.143.48616: Flags [P.], cksum 0x76e2 (correct), seq 443:467, ack 78, win 510, options [nop,nop,TS val 557654189 ecr 1212230], length 24: FTP, length: 24
  122. 226 Directory send OK.
  123. 14:25:30.032220 IP (tos 0x0, ttl 48, id 2303, offset 0, flags [DF], proto TCP (6), length 52)
  124. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x3dab (correct), ack 467, win 172, options [nop,nop,TS val 1212241 ecr 557654189], length 0
  125. 14:25:35.531012 IP (tos 0x0, ttl 48, id 2304, offset 0, flags [DF], proto TCP (6), length 52)
  126. 37.160.207.143.48616 > 192.168.1.138.21: Flags [F.], cksum 0x3b85 (correct), seq 78, ack 467, win 172, options [nop,nop,TS val 1212790 ecr 557654189], length 0
  127. 14:25:35.531651 IP (tos 0x0, ttl 63, id 60537, offset 0, flags [DF], proto TCP (6), length 52)
  128. 192.168.1.138.21 > 37.160.207.143.48616: Flags [F.], cksum 0x2444 (correct), seq 467, ack 79, win 510, options [nop,nop,TS val 557659803 ecr 1212790], length 0
  129. 14:25:35.679020 IP (tos 0x0, ttl 48, id 2305, offset 0, flags [DF], proto TCP (6), length 52)
  130. 37.160.207.143.48616 > 192.168.1.138.21: Flags [.], cksum 0x2588 (correct), ack 468, win 172, options [nop,nop,TS val 1212804 ecr 557659803], length 0
  131. ^C
  132. 45 packets captured
  133. 113 packets received by filter
  134. 0 packets dropped by kernel
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement