Guest User

tcpdump

a guest
Mar 15th, 2018
148
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 34.15 KB | None | 0 0
  1. $ tcpdump
  2. tcpdump: data link type PKTAP
  3. tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
  4. listening on pktap, link-type PKTAP (Packet Tap), capture size 65535 bytes
  5. 20:14:33.510111 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 721637724:721637787, ack 499876182, win 4096, options [nop,nop,TS val 2078449154 ecr 180937800], length 63
  6. 20:14:33.648659 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62194: Flags [P.], seq 1:38, ack 63, win 133, options [nop,nop,TS val 180940297 ecr 2078449154], length 37
  7. 20:14:33.648727 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 38, win 4094, options [nop,nop,TS val 2078449292 ecr 180940297], length 0
  8. 20:14:34.034891 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 3268444976:3268445039, ack 1161919858, win 4096, options [nop,nop,TS val 2078449676 ecr 180937928], length 63
  9. 20:14:34.061888 IP 192.168.1.7.50370 > ec2-34-248-149-109.eu-west-1.compute.amazonaws.com.https: Flags [F.], seq 681120847, ack 1322436480, win 4096, options [nop,nop,TS val 2078449702 ecr 2837295800], length 0
  10. 20:14:34.078328 IP ec2-34-248-149-109.eu-west-1.compute.amazonaws.com.https > 192.168.1.7.50370: Flags [P.], seq 1:70, ack 0, win 143, options [nop,nop,TS val 2837310850 ecr 2078389796], length 69
  11. 20:14:34.078361 IP 192.168.1.7.50370 > ec2-34-248-149-109.eu-west-1.compute.amazonaws.com.https: Flags [R], seq 681120847, win 0, length 0
  12. 20:14:34.104817 IP ec2-34-248-149-109.eu-west-1.compute.amazonaws.com.https > 192.168.1.7.50370: Flags [F.], seq 70, ack 1, win 143, options [nop,nop,TS val 2837310857 ecr 2078449702], length 0
  13. 20:14:34.104840 IP 192.168.1.7.50370 > ec2-34-248-149-109.eu-west-1.compute.amazonaws.com.https: Flags [R], seq 681120848, win 0, length 0
  14. 20:14:34.173375 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62199: Flags [P.], seq 1:38, ack 63, win 133, options [nop,nop,TS val 180940428 ecr 2078449676], length 37
  15. 20:14:34.173421 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 38, win 4094, options [nop,nop,TS val 2078449811 ecr 180940428], length 0
  16. 20:14:34.179777 IP 192.168.1.7.50393 > [HOSTNAME FOR PFSENSE BOX].http: Flags [S], seq 1546748068, win 65535, options [mss 8960,nop,wscale 5,nop,nop,TS val 2078449817 ecr 0,sackOK,eol], length 0
  17. 20:14:34.179994 IP [HOSTNAME FOR PFSENSE BOX].http > 192.168.1.7.50393: Flags [S.], seq 2501743975, ack 1546748069, win 65228, options [mss 8960,nop,wscale 7,sackOK,TS val 2958174272 ecr 2078449817], length 0
  18. 20:14:34.180029 IP 192.168.1.7.50393 > [HOSTNAME FOR PFSENSE BOX].http: Flags [.], ack 1, win 8668, options [nop,nop,TS val 2078449817 ecr 2958174272], length 0
  19. 20:14:34.180112 IP 192.168.1.7.50393 > [HOSTNAME FOR PFSENSE BOX].http: Flags [P.], seq 1:109, ack 1, win 8668, options [nop,nop,TS val 2078449817 ecr 2958174272], length 108
  20. 20:14:34.180249 IP [HOSTNAME FOR PFSENSE BOX].http > 192.168.1.7.50393: Flags [.], ack 109, win 559, options [nop,nop,TS val 2958174273 ecr 2078449817], length 0
  21. 20:14:34.237904 LLDP, length 49: switchcf00da
  22. 20:14:34.375412 IP 192.168.1.7.57279 > [HOSTNAME FOR PFSENSE BOX].domain: 40684+ PTR? 109.149.248.34.in-addr.arpa. (45)
  23. 20:14:34.426125 IP [HOSTNAME FOR PFSENSE BOX].domain > 192.168.1.7.57279: 40684 1/5/0 PTR ec2-34-248-149-109.eu-west-1.compute.amazonaws.com. (222)
  24. 20:14:34.584563 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  25. 20:14:34.584597 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
  26. 20:14:36.946675 IP 192.168.1.50.32920 > broadcasthost.ssdp: UDP, length 173
  27. 20:14:36.946678 IP 192.168.1.50.32920 > broadcasthost.ssdp: UDP, length 173
  28. 20:14:37.438095 IP 192.168.1.7.57907 > [HOSTNAME FOR PFSENSE BOX].domain: 13573+ PTR? 255.255.255.255.in-addr.arpa. (46)
  29. 20:14:37.438453 IP [HOSTNAME FOR PFSENSE BOX].domain > 192.168.1.7.57907: 13573* 0/1/0 (105)
  30. 20:14:38.610125 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [P.], seq 2804246929:2804246989, ack 1002628036, win 4096, options [nop,nop,TS val 2078454237 ecr 14300413], length 60
  31. 20:14:38.611220 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [.], ack 1, win 4096, length 0
  32. 20:14:38.734804 IP ec2-52-5-222-132.compute-1.amazonaws.com.https > 192.168.1.7.50166: Flags [P.], seq 1:42, ack 60, win 114, options [nop,nop,TS val 14302956 ecr 2078454237], length 41
  33. 20:14:38.734871 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [.], ack 42, win 4094, options [nop,nop,TS val 2078454361 ecr 14302956], length 0
  34. 20:14:38.735456 IP ec2-52-5-222-132.compute-1.amazonaws.com.https > 192.168.1.7.50166: Flags [.], ack 60, win 114, options [nop,nop,TS val 14302956 ecr 2078454237], length 0
  35. 20:14:39.584832 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  36. 20:14:39.584879 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
  37. 20:14:41.597915 IP li-in-f125.1e100.net.jabber-client > 192.168.1.7.65433: Flags [P.], seq 3372262253:3372262283, ack 534411837, win 784, options [nop,nop,TS val 444621766 ecr 2078420597], length 30
  38. 20:14:41.597975 IP 192.168.1.7.65433 > li-in-f125.1e100.net.jabber-client: Flags [.], ack 30, win 4095, options [nop,nop,TS val 2078457213 ecr 444621766], length 0
  39. 20:14:42.443387 IP 192.168.1.7.61790 > [HOSTNAME FOR PFSENSE BOX].domain: 32543+ PTR? 125.162.233.64.in-addr.arpa. (45)
  40. 20:14:42.686238 IP [HOSTNAME FOR PFSENSE BOX].domain > 192.168.1.7.61790: 32543 1/0/0 PTR li-in-f125.1e100.net. (79)
  41. 20:14:43.322187 IP 192.168.1.7.62180 > ec2-52-2-90-58.compute-1.amazonaws.com.https: Flags [.], ack 1972098423, win 4096, length 0
  42. 20:14:43.446268 IP ec2-52-2-90-58.compute-1.amazonaws.com.https > 192.168.1.7.62180: Flags [.], ack 1, win 303, options [nop,nop,TS val 24586891 ecr 2078438314], length 0
  43. 20:14:43.514832 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 63:126, ack 38, win 4096, options [nop,nop,TS val 2078459127 ecr 180940297], length 63
  44. 20:14:43.668142 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62194: Flags [P.], seq 38:75, ack 126, win 133, options [nop,nop,TS val 180942802 ecr 2078459127], length 37
  45. 20:14:43.668200 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 75, win 4094, options [nop,nop,TS val 2078459280 ecr 180942802], length 0
  46. 20:14:44.030788 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 63:126, ack 38, win 4096, options [nop,nop,TS val 2078459640 ecr 180940428], length 63
  47. 20:14:44.169363 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62199: Flags [P.], seq 38:75, ack 126, win 133, options [nop,nop,TS val 180942927 ecr 2078459640], length 37
  48. 20:14:44.169418 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 75, win 4094, options [nop,nop,TS val 2078459776 ecr 180942927], length 0
  49. 20:14:44.584909 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  50. 20:14:44.584960 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
  51. 20:14:48.741442 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [P.], seq 60:120, ack 42, win 4096, options [nop,nop,TS val 2078464339 ecr 14302956], length 60
  52. 20:14:48.763897 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [.], ack 42, win 4096, length 0
  53. 20:14:48.834143 IP 192.168.1.7.50786 > [HOSTNAME FOR PFSENSE BOX].domain: 39416+ A? www.adobe.com. (31)
  54. 20:14:48.849197 IP [HOSTNAME FOR PFSENSE BOX].domain > 192.168.1.7.50786: 39416 4/0/0 CNAME china-www.adobe.com.edgekey.net., CNAME china-www.adobe.com.edgekey.net.globalredir.akadns.net., CNAME e7933.dscb.akamaiedge.net., A 23.46.122.19 (193)
  55. 20:14:48.866114 IP ec2-52-5-222-132.compute-1.amazonaws.com.https > 192.168.1.7.50166: Flags [P.], seq 42:83, ack 120, win 114, options [nop,nop,TS val 14305489 ecr 2078464339], length 41
  56. 20:14:48.866165 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [.], ack 83, win 4094, options [nop,nop,TS val 2078464463 ecr 14305489], length 0
  57. 20:14:48.888196 IP ec2-52-5-222-132.compute-1.amazonaws.com.https > 192.168.1.7.50166: Flags [.], ack 120, win 114, options [nop,nop,TS val 14305495 ecr 2078464339], length 0
  58. 20:14:49.585135 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  59. 20:14:49.585138 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
  60. 20:14:52.510169 IP 192.168.1.7.62180 > ec2-52-2-90-58.compute-1.amazonaws.com.https: Flags [P.], seq 1:63, ack 1, win 4096, options [nop,nop,TS val 2078468099 ecr 24586891], length 62
  61. 20:14:52.634561 IP ec2-52-2-90-58.compute-1.amazonaws.com.https > 192.168.1.7.62180: Flags [P.], seq 1:57, ack 63, win 303, options [nop,nop,TS val 24589188 ecr 2078468099], length 56
  62. 20:14:52.634624 IP 192.168.1.7.62180 > ec2-52-2-90-58.compute-1.amazonaws.com.https: Flags [.], ack 57, win 4094, options [nop,nop,TS val 2078468223 ecr 24589188], length 0
  63. 20:14:53.514103 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 126:189, ack 75, win 4096, options [nop,nop,TS val 2078469096 ecr 180942802], length 63
  64. 20:14:53.652659 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62194: Flags [P.], seq 75:112, ack 189, win 133, options [nop,nop,TS val 180945298 ecr 2078469096], length 37
  65. 20:14:53.652724 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 112, win 4094, options [nop,nop,TS val 2078469233 ecr 180945298], length 0
  66. 20:14:54.037291 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 126:189, ack 75, win 4096, options [nop,nop,TS val 2078469614 ecr 180942927], length 63
  67. 20:14:54.175919 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62199: Flags [P.], seq 75:112, ack 189, win 133, options [nop,nop,TS val 180945429 ecr 2078469614], length 37
  68. 20:14:54.175974 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 112, win 4094, options [nop,nop,TS val 2078469750 ecr 180945429], length 0
  69. 20:14:54.585246 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  70. 20:14:54.585304 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
  71. 20:14:54.811032 IP 192.168.1.7.65433 > li-in-f125.1e100.net.jabber-client: Flags [P.], seq 1:31, ack 30, win 4096, options [nop,nop,TS val 2078470379 ecr 444621766], length 30
  72. 20:14:54.829326 IP li-in-f125.1e100.net.jabber-client > 192.168.1.7.65433: Flags [.], ack 31, win 784, options [nop,nop,TS val 444634998 ecr 2078470379], length 0
  73. 20:14:57.899663 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 3522774:3522813, ack 422780850, win 4096, options [nop,nop,TS val 2078473462 ecr 344745941], length 39
  74. 20:14:57.899706 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 39:79, ack 1, win 4096, options [nop,nop,TS val 2078473462 ecr 344745941], length 40
  75. 20:14:57.900180 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 1:111, ack 79, win 872, options [nop,nop,TS val 344775826 ecr 2078473462], length 110
  76. 20:14:57.900181 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 111:222, ack 79, win 872, options [nop,nop,TS val 344775826 ecr 2078473462], length 111
  77. 20:14:57.900209 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 111, win 4092, options [nop,nop,TS val 2078473462 ecr 344775826], length 0
  78. 20:14:57.900227 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 222, win 4089, options [nop,nop,TS val 2078473462 ecr 344775826], length 0
  79. 20:14:58.935550 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [P.], seq 120:180, ack 83, win 4096, options [nop,nop,TS val 2078474489 ecr 14305495], length 60
  80. 20:14:58.936666 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [.], ack 83, win 4096, length 0
  81. 20:14:58.979025 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 79:101, ack 222, win 4096, options [nop,nop,TS val 2078474532 ecr 344775826], length 22
  82. 20:14:58.979219 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 101:123, ack 222, win 4096, options [nop,nop,TS val 2078474532 ecr 344775826], length 22
  83. 20:14:58.979415 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 123:218, ack 222, win 4096, options [nop,nop,TS val 2078474532 ecr 344775826], length 95
  84. 20:14:58.979416 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 222:272, ack 123, win 872, options [nop,nop,TS val 344776905 ecr 2078474532], length 50
  85. 20:14:58.979442 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 272, win 4094, options [nop,nop,TS val 2078474532 ecr 344776905], length 0
  86. 20:14:58.979479 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 272:322, ack 123, win 872, options [nop,nop,TS val 344776905 ecr 2078474532], length 50
  87. 20:14:58.979494 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 322, win 4094, options [nop,nop,TS val 2078474532 ecr 344776905], length 0
  88. 20:14:58.979586 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 218:313, ack 322, win 4096, options [nop,nop,TS val 2078474532 ecr 344776905], length 95
  89. 20:14:58.979639 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 322:344, ack 218, win 872, options [nop,nop,TS val 344776906 ecr 2078474532], length 22
  90. 20:14:58.979657 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 344, win 4095, options [nop,nop,TS val 2078474532 ecr 344776906], length 0
  91. 20:14:58.979730 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 344:366, ack 313, win 872, options [nop,nop,TS val 344776906 ecr 2078474532], length 22
  92. 20:14:58.979746 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 366, win 4095, options [nop,nop,TS val 2078474532 ecr 344776906], length 0
  93. 20:14:58.979822 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 313:358, ack 366, win 4096, options [nop,nop,TS val 2078474532 ecr 344776906], length 45
  94. 20:14:58.979885 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 358:403, ack 366, win 4096, options [nop,nop,TS val 2078474532 ecr 344776906], length 45
  95. 20:14:58.988017 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [.], seq 366:1814, ack 403, win 872, options [nop,nop,TS val 344776914 ecr 2078474532], length 1448
  96. 20:14:58.988021 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 1814:1826, ack 403, win 872, options [nop,nop,TS val 344776914 ecr 2078474532], length 12
  97. 20:14:58.988074 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 1826, win 4050, options [nop,nop,TS val 2078474541 ecr 344776914], length 0
  98. 20:14:58.988290 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 403:448, ack 1826, win 4096, options [nop,nop,TS val 2078474541 ecr 344776914], length 45
  99. 20:14:58.995275 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 1826:2762, ack 448, win 872, options [nop,nop,TS val 344776921 ecr 2078474541], length 936
  100. 20:14:58.995310 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2762, win 4066, options [nop,nop,TS val 2078474548 ecr 344776921], length 0
  101. 20:14:58.995361 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2762:2778, ack 448, win 872, options [nop,nop,TS val 344776921 ecr 2078474541], length 16
  102. 20:14:58.995392 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2778, win 4095, options [nop,nop,TS val 2078474548 ecr 344776921], length 0
  103. 20:14:58.995518 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 448:493, ack 2778, win 4096, options [nop,nop,TS val 2078474548 ecr 344776921], length 45
  104. 20:14:58.995740 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2778:2794, ack 493, win 872, options [nop,nop,TS val 344776922 ecr 2078474548], length 16
  105. 20:14:58.995759 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2794, win 4095, options [nop,nop,TS val 2078474548 ecr 344776922], length 0
  106. 20:14:58.996189 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 493:536, ack 2794, win 4096, options [nop,nop,TS val 2078474548 ecr 344776922], length 43
  107. 20:14:58.996222 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 536:635, ack 2794, win 4096, options [nop,nop,TS val 2078474548 ecr 344776922], length 99
  108. 20:14:58.996419 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2794:2814, ack 635, win 872, options [nop,nop,TS val 344776922 ecr 2078474548], length 20
  109. 20:14:58.996449 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2814, win 4095, options [nop,nop,TS val 2078474549 ecr 344776922], length 0
  110. 20:14:58.996471 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2814:2836, ack 635, win 872, options [nop,nop,TS val 344776922 ecr 2078474548], length 22
  111. 20:14:58.996508 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2836, win 4095, options [nop,nop,TS val 2078474549 ecr 344776922], length 0
  112. 20:14:58.996515 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 635:671, ack 2836, win 4096, options [nop,nop,TS val 2078474549 ecr 344776922], length 36
  113. 20:14:58.996599 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 671:770, ack 2836, win 4096, options [nop,nop,TS val 2078474549 ecr 344776922], length 99
  114. 20:14:58.996668 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2836:2880, ack 671, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 44
  115. 20:14:58.996692 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2880, win 4094, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  116. 20:14:58.996747 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 770:790, ack 2880, win 4096, options [nop,nop,TS val 2078474549 ecr 344776923], length 20
  117. 20:14:58.996763 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2880:2902, ack 770, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 22
  118. 20:14:58.996787 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2902, win 4095, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  119. 20:14:58.996872 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 790:895, ack 2902, win 4096, options [nop,nop,TS val 2078474549 ecr 344776923], length 105
  120. 20:14:58.996890 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2902:2918, ack 790, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 16
  121. 20:14:58.996902 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2918, win 4095, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  122. 20:14:58.996935 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 895:938, ack 2918, win 4096, options [nop,nop,TS val 2078474549 ecr 344776923], length 43
  123. 20:14:58.997030 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2918:2940, ack 895, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 22
  124. 20:14:58.997055 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 2940, win 4095, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  125. 20:14:58.997147 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 938:1031, ack 2940, win 4096, options [nop,nop,TS val 2078474549 ecr 344776923], length 93
  126. 20:14:58.997147 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 2940:3068, ack 938, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 128
  127. 20:14:58.997163 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3068, win 4092, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  128. 20:14:58.997241 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1031:1130, ack 3068, win 4096, options [nop,nop,TS val 2078474549 ecr 344776923], length 99
  129. 20:14:58.997304 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3068:3090, ack 1031, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 22
  130. 20:14:58.997327 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3090, win 4095, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  131. 20:14:58.997395 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3090:3112, ack 1130, win 872, options [nop,nop,TS val 344776923 ecr 2078474549], length 22
  132. 20:14:58.997408 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3112, win 4095, options [nop,nop,TS val 2078474549 ecr 344776923], length 0
  133. 20:14:58.997430 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1130:1227, ack 3112, win 4096, options [nop,nop,TS val 2078474549 ecr 344776923], length 97
  134. 20:14:58.997506 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1227:1332, ack 3112, win 4096, options [nop,nop,TS val 2078474550 ecr 344776923], length 105
  135. 20:14:58.997625 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3112:3134, ack 1227, win 872, options [nop,nop,TS val 344776924 ecr 2078474549], length 22
  136. 20:14:58.997654 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3134, win 4095, options [nop,nop,TS val 2078474550 ecr 344776924], length 0
  137. 20:14:58.997661 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3134:3156, ack 1332, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  138. 20:14:58.997688 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3156, win 4095, options [nop,nop,TS val 2078474550 ecr 344776924], length 0
  139. 20:14:58.997751 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1332:1427, ack 3156, win 4096, options [nop,nop,TS val 2078474550 ecr 344776924], length 95
  140. 20:14:58.997782 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1427:1520, ack 3156, win 4096, options [nop,nop,TS val 2078474550 ecr 344776924], length 93
  141. 20:14:58.997937 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3156:3178, ack 1520, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  142. 20:14:58.997957 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3178, win 4095, options [nop,nop,TS val 2078474550 ecr 344776924], length 0
  143. 20:14:58.997964 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3178:3200, ack 1520, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  144. 20:14:58.997979 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3200, win 4095, options [nop,nop,TS val 2078474550 ecr 344776924], length 0
  145. 20:14:58.998067 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1520:1623, ack 3200, win 4096, options [nop,nop,TS val 2078474550 ecr 344776924], length 103
  146. 20:14:58.998088 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1623:1714, ack 3200, win 4096, options [nop,nop,TS val 2078474550 ecr 344776924], length 91
  147. 20:14:58.998229 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3200:3222, ack 1714, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  148. 20:14:58.998255 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3222, win 4095, options [nop,nop,TS val 2078474550 ecr 344776924], length 0
  149. 20:14:58.998262 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3222:3244, ack 1714, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  150. 20:14:58.998273 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3244, win 4095, options [nop,nop,TS val 2078474550 ecr 344776924], length 0
  151. 20:14:58.998362 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1714:1811, ack 3244, win 4096, options [nop,nop,TS val 2078474550 ecr 344776924], length 97
  152. 20:14:58.998384 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1811:1904, ack 3244, win 4096, options [nop,nop,TS val 2078474550 ecr 344776924], length 93
  153. 20:14:58.998533 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3244:3266, ack 1904, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  154. 20:14:58.998557 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3266, win 4095, options [nop,nop,TS val 2078474551 ecr 344776924], length 0
  155. 20:14:58.998564 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3266:3288, ack 1904, win 872, options [nop,nop,TS val 344776924 ecr 2078474550], length 22
  156. 20:14:58.998576 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3288, win 4095, options [nop,nop,TS val 2078474551 ecr 344776924], length 0
  157. 20:14:58.998654 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 1904:2001, ack 3288, win 4096, options [nop,nop,TS val 2078474551 ecr 344776924], length 97
  158. 20:14:58.998674 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2001:2096, ack 3288, win 4096, options [nop,nop,TS val 2078474551 ecr 344776924], length 95
  159. 20:14:58.998816 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3288:3310, ack 2096, win 872, options [nop,nop,TS val 344776925 ecr 2078474551], length 22
  160. 20:14:58.998842 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3310, win 4095, options [nop,nop,TS val 2078474551 ecr 344776925], length 0
  161. 20:14:58.998849 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3310:3332, ack 2096, win 872, options [nop,nop,TS val 344776925 ecr 2078474551], length 22
  162. 20:14:58.998861 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3332, win 4095, options [nop,nop,TS val 2078474551 ecr 344776925], length 0
  163. 20:14:58.998968 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2096:2193, ack 3332, win 4096, options [nop,nop,TS val 2078474551 ecr 344776925], length 97
  164. 20:14:58.998993 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2193:2288, ack 3332, win 4096, options [nop,nop,TS val 2078474551 ecr 344776925], length 95
  165. 20:14:58.999145 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3332:3354, ack 2288, win 872, options [nop,nop,TS val 344776925 ecr 2078474551], length 22
  166. 20:14:58.999148 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3354:3376, ack 2288, win 872, options [nop,nop,TS val 344776925 ecr 2078474551], length 22
  167. 20:14:58.999167 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3354, win 4095, options [nop,nop,TS val 2078474551 ecr 344776925], length 0
  168. 20:14:58.999182 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3376, win 4095, options [nop,nop,TS val 2078474551 ecr 344776925], length 0
  169. 20:14:58.999271 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2288:2389, ack 3376, win 4096, options [nop,nop,TS val 2078474551 ecr 344776925], length 101
  170. 20:14:58.999443 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3376:3398, ack 2389, win 872, options [nop,nop,TS val 344776925 ecr 2078474551], length 22
  171. 20:14:58.999468 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3398, win 4095, options [nop,nop,TS val 2078474551 ecr 344776925], length 0
  172. 20:14:58.999553 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2389:2510, ack 3398, win 4096, options [nop,nop,TS val 2078474552 ecr 344776925], length 121
  173. 20:14:58.999722 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3398:3420, ack 2510, win 872, options [nop,nop,TS val 344776926 ecr 2078474552], length 22
  174. 20:14:58.999746 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3420, win 4095, options [nop,nop,TS val 2078474552 ecr 344776926], length 0
  175. 20:14:58.999833 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2510:2615, ack 3420, win 4096, options [nop,nop,TS val 2078474552 ecr 344776926], length 105
  176. 20:14:59.000004 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3420:3442, ack 2615, win 872, options [nop,nop,TS val 344776926 ecr 2078474552], length 22
  177. 20:14:59.000026 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3442, win 4095, options [nop,nop,TS val 2078474552 ecr 344776926], length 0
  178. 20:14:59.000113 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2615:2718, ack 3442, win 4096, options [nop,nop,TS val 2078474552 ecr 344776926], length 103
  179. 20:14:59.000285 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3442:3464, ack 2718, win 872, options [nop,nop,TS val 344776926 ecr 2078474552], length 22
  180. 20:14:59.000309 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3464, win 4095, options [nop,nop,TS val 2078474552 ecr 344776926], length 0
  181. 20:14:59.000408 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2718:2821, ack 3464, win 4096, options [nop,nop,TS val 2078474552 ecr 344776926], length 103
  182. 20:14:59.000567 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3464:3486, ack 2821, win 872, options [nop,nop,TS val 344776926 ecr 2078474552], length 22
  183. 20:14:59.000580 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3486, win 4095, options [nop,nop,TS val 2078474553 ecr 344776926], length 0
  184. 20:14:59.000654 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2821:2932, ack 3486, win 4096, options [nop,nop,TS val 2078474553 ecr 344776926], length 111
  185. 20:14:59.000827 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3486:3508, ack 2932, win 872, options [nop,nop,TS val 344776927 ecr 2078474553], length 22
  186. 20:14:59.000849 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3508, win 4095, options [nop,nop,TS val 2078474553 ecr 344776927], length 0
  187. 20:14:59.000947 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 2932:3037, ack 3508, win 4096, options [nop,nop,TS val 2078474553 ecr 344776927], length 105
  188. 20:14:59.001116 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3508:3530, ack 3037, win 872, options [nop,nop,TS val 344776927 ecr 2078474553], length 22
  189. 20:14:59.001135 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3530, win 4095, options [nop,nop,TS val 2078474553 ecr 344776927], length 0
  190. 20:14:59.060223 IP ec2-52-5-222-132.compute-1.amazonaws.com.https > 192.168.1.7.50166: Flags [P.], seq 83:124, ack 180, win 114, options [nop,nop,TS val 14308038 ecr 2078474489], length 41
  191. 20:14:59.060280 IP 192.168.1.7.50166 > ec2-52-5-222-132.compute-1.amazonaws.com.https: Flags [.], ack 124, win 4094, options [nop,nop,TS val 2078474612 ecr 14308038], length 0
  192. 20:14:59.060982 IP ec2-52-5-222-132.compute-1.amazonaws.com.https > 192.168.1.7.50166: Flags [.], ack 180, win 114, options [nop,nop,TS val 14308038 ecr 2078474489], length 0
  193. 20:14:59.080559 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [P.], seq 3037:3059, ack 3530, win 4096, options [nop,nop,TS val 2078474632 ecr 344776927], length 22
  194. 20:14:59.081004 IP 192.168.1.50.afpovertcp > 192.168.1.7.62263: Flags [P.], seq 3530:3580, ack 3059, win 872, options [nop,nop,TS val 344777007 ecr 2078474632], length 50
  195. 20:14:59.081046 IP 192.168.1.7.62263 > 192.168.1.50.afpovertcp: Flags [.], ack 3580, win 4094, options [nop,nop,TS val 2078474632 ecr 344777007], length 0
  196. 20:14:59.585487 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  197. 20:14:59.585490 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
  198. 20:14:59.924522 IP 192.168.1.50.netbios-ns > 192.168.1.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
  199. 20:14:59.924525 IP 192.168.1.50.netbios-ns > 192.168.1.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
  200. 20:15:03.177018 IP 192.168.1.7.62180 > ec2-52-2-90-58.compute-1.amazonaws.com.https: Flags [.], ack 57, win 4096, length 0
  201. 20:15:03.301102 IP ec2-52-2-90-58.compute-1.amazonaws.com.https > 192.168.1.7.62180: Flags [.], ack 63, win 303, options [nop,nop,TS val 24591855 ecr 2078468223], length 0
  202. 20:15:03.516327 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 189:252, ack 112, win 4096, options [nop,nop,TS val 2078479059 ecr 180945298], length 63
  203. 20:15:03.654963 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62194: Flags [P.], seq 112:149, ack 252, win 133, options [nop,nop,TS val 180947799 ecr 2078479059], length 37
  204. 20:15:03.655029 IP 192.168.1.7.62194 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 149, win 4094, options [nop,nop,TS val 2078479197 ecr 180947799], length 0
  205. 20:15:04.037345 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [P.], seq 189:252, ack 112, win 4096, options [nop,nop,TS val 2078479578 ecr 180945429], length 63
  206. 20:15:04.061836 IP 192.168.1.7.50392 > ec2-54-77-225-170.eu-west-1.compute.amazonaws.com.https: Flags [F.], seq 22530803, ack 1541007276, win 4096, options [nop,nop,TS val 2078479602 ecr 3524791525], length 0
  207. 20:15:04.106266 IP ec2-54-77-225-170.eu-west-1.compute.amazonaws.com.https > 192.168.1.7.50392: Flags [P.], seq 1:70, ack 1, win 153, options [nop,nop,TS val 3524799618 ecr 2078479602], length 69
  208. 20:15:04.106267 IP ec2-54-77-225-170.eu-west-1.compute.amazonaws.com.https > 192.168.1.7.50392: Flags [F.], seq 70, ack 1, win 153, options [nop,nop,TS val 3524799618 ecr 2078479602], length 0
  209. 20:15:04.106295 IP 192.168.1.7.50392 > ec2-54-77-225-170.eu-west-1.compute.amazonaws.com.https: Flags [R], seq 22530804, win 0, length 0
  210. 20:15:04.106301 IP 192.168.1.7.50392 > ec2-54-77-225-170.eu-west-1.compute.amazonaws.com.https: Flags [R], seq 22530804, win 0, length 0
  211. 20:15:04.182942 IP 192.168.1.7.50393 > [HOSTNAME FOR PFSENSE BOX].http: Flags [F.], seq 109, ack 1, win 8668, options [nop,nop,TS val 2078479722 ecr 2958174273], length 0
  212. 20:15:04.183251 IP [HOSTNAME FOR PFSENSE BOX].http > 192.168.1.7.50393: Flags [.], ack 110, win 560, options [nop,nop,TS val 2958204276 ecr 2078479722], length 0
  213. 20:15:04.183277 IP 192.168.1.7.50393 > [HOSTNAME FOR PFSENSE BOX].http: Flags [.], ack 1, win 8668, options [nop,nop,TS val 2078479722 ecr 2958174273], length 0
  214. 20:15:04.183284 IP [HOSTNAME FOR PFSENSE BOX].http > 192.168.1.7.50393: Flags [F.], seq 4115, ack 110, win 560, options [nop,nop,TS val 2958204276 ecr 2078479722], length 0
  215. 20:15:04.183293 IP 192.168.1.7.50393 > [HOSTNAME FOR PFSENSE BOX].http: Flags [.], ack 1, win 8668, options [nop,nop,TS val 2078479722 ecr 2958174273], length 0
  216. 20:15:04.185182 IP ec2-35-174-22-108.compute-1.amazonaws.com.https > 192.168.1.7.62199: Flags [P.], seq 112:149, ack 252, win 133, options [nop,nop,TS val 180947931 ecr 2078479578], length 37
  217. 20:15:04.185224 IP 192.168.1.7.62199 > ec2-35-174-22-108.compute-1.amazonaws.com.https: Flags [.], ack 149, win 4094, options [nop,nop,TS val 2078479724 ecr 180947931], length 0
  218. 20:15:04.237507 LLDP, length 49: switchcf00da
  219. 20:15:04.585578 IP 192.168.1.50.54917 > 192.168.1.255.32412: UDP, length 21
  220. 20:15:04.585633 IP 192.168.1.50.57664 > 192.168.1.255.32414: UDP, length 21
Add Comment
Please, Sign In to add comment