Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- No. Time Source Destination Protocol Length Info
- 2600 30.950722 10.50.2.11 52.220.123.79 TCP 66 64410 → 22 [SYN, ECN, CWR] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
- Frame 2600: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}, id 0
- Interface id: 0 (\Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990})
- Interface name: \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}
- Interface description: Ethernet
- Encapsulation type: Ethernet (1)
- Arrival Time: Jun 10, 2020 11:44:16.379266000 Central Europe Daylight Time
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1591782256.379266000 seconds
- [Time delta from previous captured frame: 0.000220000 seconds]
- [Time delta from previous displayed frame: 0.000000000 seconds]
- [Time since reference or first frame: 30.950722000 seconds]
- Frame Number: 2600
- Frame Length: 66 bytes (528 bits)
- Capture Length: 66 bytes (528 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP SYN/FIN]
- [Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
- Ethernet II, Src: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b), Dst: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Destination: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Address: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Address: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: 10.50.2.11, Dst: 52.220.123.79
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x02 (DSCP: CS0, ECN: ECT(0))
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..10 = Explicit Congestion Notification: ECN-Capable Transport codepoint '10' (2)
- Total Length: 52
- Identification: 0x20c9 (8393)
- Flags: 0x4000, Don't fragment
- 0... .... .... .... = Reserved bit: Not set
- .1.. .... .... .... = Don't fragment: Set
- ..0. .... .... .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0x0000 [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.50.2.11
- Destination: 52.220.123.79
- Transmission Control Protocol, Src Port: 64410, Dst Port: 22, Seq: 0, Len: 0
- Source Port: 64410
- Destination Port: 22
- [Stream index: 44]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Sequence number (raw): 1321280506
- [Next sequence number: 1 (relative sequence number)]
- Acknowledgment number: 0
- Acknowledgment number (raw): 0
- 1000 .... = Header Length: 32 bytes (8)
- Flags: 0x0c2 (SYN, ECN, CWR)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 1... .... = Congestion Window Reduced (CWR): Set
- .... .1.. .... = ECN-Echo: Set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 22]
- [Connection establish request (SYN): server port 22]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ····CE····S·]
- Window size value: 8192
- [Calculated window size: 8192]
- Checksum: 0xbc8e [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), Maximum segment size, No-Operation (NOP), Window scale, No-Operation (NOP), No-Operation (NOP), SACK permitted
- TCP Option - Maximum segment size: 1460 bytes
- Kind: Maximum Segment Size (2)
- Length: 4
- MSS Value: 1460
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - Window scale: 8 (multiply by 256)
- Kind: Window Scale (3)
- Length: 3
- Shift count: 8
- [Multiplier: 256]
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - SACK permitted
- Kind: SACK Permitted (4)
- Length: 2
- [Timestamps]
- [Time since first frame in this TCP stream: 0.000000000 seconds]
- [Time since previous frame in this TCP stream: 0.000000000 seconds]
- No. Time Source Destination Protocol Length Info
- 2647 31.213991 52.220.123.79 10.50.2.11 TCP 66 22 → 64410 [SYN, ACK] Seq=0 Ack=1 Win=26883 Len=0 MSS=1460 SACK_PERM=1 WS=128
- Frame 2647: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}, id 0
- Interface id: 0 (\Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990})
- Interface name: \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}
- Interface description: Ethernet
- Encapsulation type: Ethernet (1)
- Arrival Time: Jun 10, 2020 11:44:16.642535000 Central Europe Daylight Time
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1591782256.642535000 seconds
- [Time delta from previous captured frame: 0.019383000 seconds]
- [Time delta from previous displayed frame: 0.263269000 seconds]
- [Time since reference or first frame: 31.213991000 seconds]
- Frame Number: 2647
- Frame Length: 66 bytes (528 bits)
- Capture Length: 66 bytes (528 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP SYN/FIN]
- [Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
- Ethernet II, Src: D-Link_3d:f2:62 (00:13:46:3d:f2:62), Dst: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Destination: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Address: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Address: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: 52.220.123.79, Dst: 10.50.2.11
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 52
- Identification: 0x0000 (0)
- Flags: 0x0000
- 0... .... .... .... = Reserved bit: Not set
- .0.. .... .... .... = Don't fragment: Not set
- ..0. .... .... .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 232
- Protocol: TCP (6)
- Header checksum: 0x165c [validation disabled]
- [Header checksum status: Unverified]
- Source: 52.220.123.79
- Destination: 10.50.2.11
- Transmission Control Protocol, Src Port: 22, Dst Port: 64410, Seq: 0, Ack: 1, Len: 0
- Source Port: 22
- Destination Port: 64410
- [Stream index: 44]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Sequence number (raw): 267729426
- [Next sequence number: 1 (relative sequence number)]
- Acknowledgment number: 1 (relative ack number)
- Acknowledgment number (raw): 1321280507
- 1000 .... = Header Length: 32 bytes (8)
- Flags: 0x012 (SYN, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port 22]
- [Connection establish acknowledge (SYN+ACK): server port 22]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······A··S·]
- Window size value: 26883
- [Calculated window size: 26883]
- Checksum: 0x9121 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), Maximum segment size, No-Operation (NOP), No-Operation (NOP), SACK permitted, No-Operation (NOP), Window scale
- TCP Option - Maximum segment size: 1460 bytes
- Kind: Maximum Segment Size (2)
- Length: 4
- MSS Value: 1460
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - SACK permitted
- Kind: SACK Permitted (4)
- Length: 2
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - Window scale: 7 (multiply by 128)
- Kind: Window Scale (3)
- Length: 3
- Shift count: 7
- [Multiplier: 128]
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 2600]
- [The RTT to ACK the segment was: 0.263269000 seconds]
- [Timestamps]
- [Time since first frame in this TCP stream: 0.263269000 seconds]
- [Time since previous frame in this TCP stream: 0.263269000 seconds]
- No. Time Source Destination Protocol Length Info
- 2648 31.214009 10.50.2.11 52.220.123.79 TCP 54 64410 → 22 [RST] Seq=1 Win=0 Len=0
- Frame 2648: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}, id 0
- Interface id: 0 (\Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990})
- Interface name: \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}
- Interface description: Ethernet
- Encapsulation type: Ethernet (1)
- Arrival Time: Jun 10, 2020 11:44:16.642553000 Central Europe Daylight Time
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1591782256.642553000 seconds
- [Time delta from previous captured frame: 0.000018000 seconds]
- [Time delta from previous displayed frame: 0.000018000 seconds]
- [Time since reference or first frame: 31.214009000 seconds]
- Frame Number: 2648
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP RST]
- [Coloring Rule String: tcp.flags.reset eq 1]
- Ethernet II, Src: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b), Dst: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Destination: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Address: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Address: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: 10.50.2.11, Dst: 52.220.123.79
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 40
- Identification: 0x20ca (8394)
- Flags: 0x4000, Don't fragment
- 0... .... .... .... = Reserved bit: Not set
- .1.. .... .... .... = Don't fragment: Set
- ..0. .... .... .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0x0000 [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.50.2.11
- Destination: 52.220.123.79
- Transmission Control Protocol, Src Port: 64410, Dst Port: 22, Seq: 1, Len: 0
- Source Port: 64410
- Destination Port: 22
- [Stream index: 44]
- [TCP Segment Len: 0]
- Sequence number: 1 (relative sequence number)
- Sequence number (raw): 1321280507
- [Next sequence number: 1 (relative sequence number)]
- Acknowledgment number: 1321280507
- [Expert Info (Note/Protocol): The acknowledgment number field is nonzero while the ACK flag is not set]
- [The acknowledgment number field is nonzero while the ACK flag is not set]
- [Severity level: Note]
- [Group: Protocol]
- Acknowledgment number (raw): 1321280507
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x004 (RST)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .1.. = Reset: Set
- [Expert Info (Warning/Sequence): Connection reset (RST)]
- [Connection reset (RST)]
- [Severity level: Warning]
- [Group: Sequence]
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·········R··]
- Window size value: 0
- [Calculated window size: 0]
- [Window size scaling factor: 256]
- Checksum: 0xbc82 [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- [Timestamps]
- [Time since first frame in this TCP stream: 0.263287000 seconds]
- [Time since previous frame in this TCP stream: 0.000018000 seconds]
- No. Time Source Destination Protocol Length Info
- 35938 211.569592 10.50.2.11 195.144.107.198 TCP 66 64431 → 22 [SYN, ECN, CWR] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
- Frame 35938: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}, id 0
- Interface id: 0 (\Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990})
- Interface name: \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}
- Interface description: Ethernet
- Encapsulation type: Ethernet (1)
- Arrival Time: Jun 10, 2020 11:47:16.998136000 Central Europe Daylight Time
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1591782436.998136000 seconds
- [Time delta from previous captured frame: 0.000007000 seconds]
- [Time delta from previous displayed frame: 180.355583000 seconds]
- [Time since reference or first frame: 211.569592000 seconds]
- Frame Number: 35938
- Frame Length: 66 bytes (528 bits)
- Capture Length: 66 bytes (528 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP SYN/FIN]
- [Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
- Ethernet II, Src: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b), Dst: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Destination: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Address: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Address: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: 10.50.2.11, Dst: 195.144.107.198
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x02 (DSCP: CS0, ECN: ECT(0))
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..10 = Explicit Congestion Notification: ECN-Capable Transport codepoint '10' (2)
- Total Length: 52
- Identification: 0x0092 (146)
- Flags: 0x4000, Don't fragment
- 0... .... .... .... = Reserved bit: Not set
- .1.. .... .... .... = Don't fragment: Set
- ..0. .... .... .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0x0000 [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.50.2.11
- Destination: 195.144.107.198
- Transmission Control Protocol, Src Port: 64431, Dst Port: 22, Seq: 0, Len: 0
- Source Port: 64431
- Destination Port: 22
- [Stream index: 102]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Sequence number (raw): 3494354065
- [Next sequence number: 1 (relative sequence number)]
- Acknowledgment number: 0
- Acknowledgment number (raw): 0
- 1000 .... = Header Length: 32 bytes (8)
- Flags: 0x0c2 (SYN, ECN, CWR)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 1... .... = Congestion Window Reduced (CWR): Set
- .... .1.. .... = ECN-Echo: Set
- .... ..0. .... = Urgent: Not set
- .... ...0 .... = Acknowledgment: Not set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish request (SYN): server port 22]
- [Connection establish request (SYN): server port 22]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ····CE····S·]
- Window size value: 8192
- [Calculated window size: 8192]
- Checksum: 0x3bba [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), Maximum segment size, No-Operation (NOP), Window scale, No-Operation (NOP), No-Operation (NOP), SACK permitted
- TCP Option - Maximum segment size: 1460 bytes
- Kind: Maximum Segment Size (2)
- Length: 4
- MSS Value: 1460
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - Window scale: 8 (multiply by 256)
- Kind: Window Scale (3)
- Length: 3
- Shift count: 8
- [Multiplier: 256]
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - SACK permitted
- Kind: SACK Permitted (4)
- Length: 2
- [Timestamps]
- [Time since first frame in this TCP stream: 0.000000000 seconds]
- [Time since previous frame in this TCP stream: 0.000000000 seconds]
- No. Time Source Destination Protocol Length Info
- 35983 211.588596 195.144.107.198 10.50.2.11 TCP 66 22 → 64431 [SYN, ACK] Seq=0 Ack=1 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1
- Frame 35983: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}, id 0
- Interface id: 0 (\Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990})
- Interface name: \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}
- Interface description: Ethernet
- Encapsulation type: Ethernet (1)
- Arrival Time: Jun 10, 2020 11:47:17.017140000 Central Europe Daylight Time
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1591782437.017140000 seconds
- [Time delta from previous captured frame: 0.006630000 seconds]
- [Time delta from previous displayed frame: 0.019004000 seconds]
- [Time since reference or first frame: 211.588596000 seconds]
- Frame Number: 35983
- Frame Length: 66 bytes (528 bits)
- Capture Length: 66 bytes (528 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP SYN/FIN]
- [Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
- Ethernet II, Src: D-Link_3d:f2:62 (00:13:46:3d:f2:62), Dst: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Destination: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Address: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Address: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: 195.144.107.198, Dst: 10.50.2.11
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 52
- Identification: 0x5dc3 (24003)
- Flags: 0x0000
- 0... .... .... .... = Reserved bit: Not set
- .0.. .... .... .... = Don't fragment: Not set
- ..0. .... .... .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 118
- Protocol: TCP (6)
- Header checksum: 0xab6d [validation disabled]
- [Header checksum status: Unverified]
- Source: 195.144.107.198
- Destination: 10.50.2.11
- Transmission Control Protocol, Src Port: 22, Dst Port: 64431, Seq: 0, Ack: 1, Len: 0
- Source Port: 22
- Destination Port: 64431
- [Stream index: 102]
- [TCP Segment Len: 0]
- Sequence number: 0 (relative sequence number)
- Sequence number (raw): 2325046377
- [Next sequence number: 1 (relative sequence number)]
- Acknowledgment number: 1 (relative ack number)
- Acknowledgment number (raw): 3494354066
- 1000 .... = Header Length: 32 bytes (8)
- Flags: 0x012 (SYN, ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..1. = Syn: Set
- [Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port 22]
- [Connection establish acknowledge (SYN+ACK): server port 22]
- [Severity level: Chat]
- [Group: Sequence]
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······A··S·]
- Window size value: 8192
- [Calculated window size: 8192]
- Checksum: 0xbbcd [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- Options: (12 bytes), Maximum segment size, No-Operation (NOP), Window scale, No-Operation (NOP), No-Operation (NOP), SACK permitted
- TCP Option - Maximum segment size: 1460 bytes
- Kind: Maximum Segment Size (2)
- Length: 4
- MSS Value: 1460
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - Window scale: 8 (multiply by 256)
- Kind: Window Scale (3)
- Length: 3
- Shift count: 8
- [Multiplier: 256]
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - No-Operation (NOP)
- Kind: No-Operation (1)
- TCP Option - SACK permitted
- Kind: SACK Permitted (4)
- Length: 2
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 35938]
- [The RTT to ACK the segment was: 0.019004000 seconds]
- [iRTT: 0.019034000 seconds]
- [Timestamps]
- [Time since first frame in this TCP stream: 0.019004000 seconds]
- [Time since previous frame in this TCP stream: 0.019004000 seconds]
- No. Time Source Destination Protocol Length Info
- 35984 211.588626 10.50.2.11 195.144.107.198 TCP 54 64431 → 22 [ACK] Seq=1 Ack=1 Win=65536 Len=0
- Frame 35984: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}, id 0
- Interface id: 0 (\Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990})
- Interface name: \Device\NPF_{BFA1D2C4-2876-4CD1-9CD7-AE9AB38E7990}
- Interface description: Ethernet
- Encapsulation type: Ethernet (1)
- Arrival Time: Jun 10, 2020 11:47:17.017170000 Central Europe Daylight Time
- [Time shift for this packet: 0.000000000 seconds]
- Epoch Time: 1591782437.017170000 seconds
- [Time delta from previous captured frame: 0.000030000 seconds]
- [Time delta from previous displayed frame: 0.000030000 seconds]
- [Time since reference or first frame: 211.588626000 seconds]
- Frame Number: 35984
- Frame Length: 54 bytes (432 bits)
- Capture Length: 54 bytes (432 bits)
- [Frame is marked: False]
- [Frame is ignored: False]
- [Protocols in frame: eth:ethertype:ip:tcp]
- [Coloring Rule Name: TCP]
- [Coloring Rule String: tcp]
- Ethernet II, Src: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b), Dst: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Destination: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- Address: D-Link_3d:f2:62 (00:13:46:3d:f2:62)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Source: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- Address: Microsof_b9:f0:1b (00:15:5d:b9:f0:1b)
- .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
- .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
- Type: IPv4 (0x0800)
- Internet Protocol Version 4, Src: 10.50.2.11, Dst: 195.144.107.198
- 0100 .... = Version: 4
- .... 0101 = Header Length: 20 bytes (5)
- Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
- 0000 00.. = Differentiated Services Codepoint: Default (0)
- .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
- Total Length: 40
- Identification: 0x0093 (147)
- Flags: 0x4000, Don't fragment
- 0... .... .... .... = Reserved bit: Not set
- .1.. .... .... .... = Don't fragment: Set
- ..0. .... .... .... = More fragments: Not set
- Fragment offset: 0
- Time to live: 128
- Protocol: TCP (6)
- Header checksum: 0x0000 [validation disabled]
- [Header checksum status: Unverified]
- Source: 10.50.2.11
- Destination: 195.144.107.198
- Transmission Control Protocol, Src Port: 64431, Dst Port: 22, Seq: 1, Ack: 1, Len: 0
- Source Port: 64431
- Destination Port: 22
- [Stream index: 102]
- [TCP Segment Len: 0]
- Sequence number: 1 (relative sequence number)
- Sequence number (raw): 3494354066
- [Next sequence number: 1 (relative sequence number)]
- Acknowledgment number: 1 (relative ack number)
- Acknowledgment number (raw): 2325046378
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x010 (ACK)
- 000. .... .... = Reserved: Not set
- ...0 .... .... = Nonce: Not set
- .... 0... .... = Congestion Window Reduced (CWR): Not set
- .... .0.. .... = ECN-Echo: Not set
- .... ..0. .... = Urgent: Not set
- .... ...1 .... = Acknowledgment: Set
- .... .... 0... = Push: Not set
- .... .... .0.. = Reset: Not set
- .... .... ..0. = Syn: Not set
- .... .... ...0 = Fin: Not set
- [TCP Flags: ·······A····]
- Window size value: 256
- [Calculated window size: 65536]
- [Window size scaling factor: 256]
- Checksum: 0x3bae [unverified]
- [Checksum Status: Unverified]
- Urgent pointer: 0
- [SEQ/ACK analysis]
- [This is an ACK to the segment in frame: 35983]
- [The RTT to ACK the segment was: 0.000030000 seconds]
- [iRTT: 0.019034000 seconds]
- [Timestamps]
- [Time since first frame in this TCP stream: 0.019034000 seconds]
- [Time since previous frame in this TCP stream: 0.000030000 seconds]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement