No. Time Source Destination Protocol Info 1 0.000000 192.168.1.28

advertisement
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
No.
Time
Source
1 0.000000
192.168.1.28
A weather.noaa.gov
Page 1
Destination
192.168.1.2
Protocol Info
DNS
Standard query
Frame 1 (76 bytes on wire, 76 bytes captured)
Arrival Time: Jan 21, 2007 12:24:02.377214000
Time delta from previous packet: 0.000000000 seconds
Time since reference or first frame: 0.000000000 seconds
Frame Number: 1
Packet Length: 76 bytes
Capture Length: 76 bytes
Protocols in frame: eth:ip:udp:dns
Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8
Destination: 00:40:f4:b7:ec:d8 (192.168.1.2)
Source: 00:18:f3:a8:0a:8a (192.168.1.28)
Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16
8.1.2)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 62
Identification: 0x598f (22927)
Flags: 0x04 (Don’t Fragment)
0... = Reserved bit: Not set
.1.. = Don’t fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: UDP (0x11)
Header checksum: 0x5db1 (correct)
Source: 192.168.1.28 (192.168.1.28)
Destination: 192.168.1.2 (192.168.1.2)
User Datagram Protocol, Src Port: 32776 (32776), Dst Port: domain (53)
Source port: 32776 (32776)
Destination port: domain (53)
Length: 42
Checksum: 0x1e76 (correct)
Domain Name System (query)
Transaction ID: 0xe37e
Flags: 0x0100 (Standard query)
0... .... .... .... = Response: Message is a query
.000 0... .... .... = Opcode: Standard query (0)
.... ..0. .... .... = Truncated: Message is not truncated
.... ...1 .... .... = Recursion desired: Do query recursively
.... .... .0.. .... = Z: reserved (0)
.... .... ...0 .... = Non-authenticated data OK: Non-authenticated data is unacceptable
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 0
Queries
weather.noaa.gov: type A, class IN
Name: weather.noaa.gov
Type: A (Host address)
Class: IN (0x0001)
0000
0010
0020
0030
0040
00
00
01
00
6f
40
3e
02
00
61
f4
59
80
00
61
b7
8f
08
00
03
ec
40
00
00
67
d8
00
35
00
6f
00
40
00
07
76
18
11
2a
77
00
f3
5d
1e
65
00
a8
b1
76
61
01
0a
c0
e3
74
00
8a
a8
7e
68
01
08
01
01
65
00
1c
00
72
45
c0
00
04
00
a8
01
6e
.@............E.
.>Y.@.@.].......
.....5.*.v.~....
.......weather.n
oaa.gov.....
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
No.
Time
Source
2 0.000426
192.168.1.28
AAAA weather.noaa.gov
Page 2
Destination
192.168.1.2
Protocol Info
DNS
Standard query
Frame 2 (76 bytes on wire, 76 bytes captured)
Arrival Time: Jan 21, 2007 12:24:02.377640000
Time delta from previous packet: 0.000426000 seconds
Time since reference or first frame: 0.000426000 seconds
Frame Number: 2
Packet Length: 76 bytes
Capture Length: 76 bytes
Protocols in frame: eth:ip:udp:dns
Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8
Destination: 00:40:f4:b7:ec:d8 (192.168.1.2)
Source: 00:18:f3:a8:0a:8a (192.168.1.28)
Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16
8.1.2)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 62
Identification: 0x598f (22927)
Flags: 0x04 (Don’t Fragment)
0... = Reserved bit: Not set
.1.. = Don’t fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: UDP (0x11)
Header checksum: 0x5db1 (correct)
Source: 192.168.1.28 (192.168.1.28)
Destination: 192.168.1.2 (192.168.1.2)
User Datagram Protocol, Src Port: 32777 (32777), Dst Port: domain (53)
Source port: 32777 (32777)
Destination port: domain (53)
Length: 42
Checksum: 0x62bf (correct)
Domain Name System (query)
Transaction ID: 0x9f19
Flags: 0x0100 (Standard query)
0... .... .... .... = Response: Message is a query
.000 0... .... .... = Opcode: Standard query (0)
.... ..0. .... .... = Truncated: Message is not truncated
.... ...1 .... .... = Recursion desired: Do query recursively
.... .... .0.. .... = Z: reserved (0)
.... .... ...0 .... = Non-authenticated data OK: Non-authenticated data is unacceptable
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 0
Queries
weather.noaa.gov: type AAAA, class IN
Name: weather.noaa.gov
Type: AAAA (IPv6 address)
Class: IN (0x0001)
0000
0010
0020
0030
0040
00
00
01
00
6f
40
3e
02
00
61
f4
59
80
00
61
b7
8f
09
00
03
ec
40
00
00
67
d8
00
35
00
6f
00
40
00
07
76
18
11
2a
77
00
f3
5d
62
65
00
a8
b1
bf
61
1c
0a
c0
9f
74
00
8a
a8
19
68
01
08
01
01
65
00
1c
00
72
45
c0
00
04
00
a8
01
6e
.@............E.
.>Y.@.@.].......
.....5.*b.......
.......weather.n
oaa.gov.....
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
No.
Time
Source
5 0.001109
192.168.1.2
response A 205.156.51.200
Destination
192.168.1.28
Page 3
Protocol Info
DNS
Standard query
Frame 5 (149 bytes on wire, 149 bytes captured)
Arrival Time: Jan 21, 2007 12:24:02.378323000
Time delta from previous packet: 0.000087000 seconds
Time since reference or first frame: 0.001109000 seconds
Frame Number: 5
Packet Length: 149 bytes
Capture Length: 149 bytes
Protocols in frame: eth:ip:udp:dns
Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a
Destination: 00:18:f3:a8:0a:8a (192.168.1.28)
Source: 00:40:f4:b7:ec:d8 (192.168.1.2)
Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168
.1.28)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 135
Identification: 0x2a2a (10794)
Flags: 0x04 (Don’t Fragment)
0... = Reserved bit: Not set
.1.. = Don’t fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: UDP (0x11)
Header checksum: 0x8ccd (correct)
Source: 192.168.1.2 (192.168.1.2)
Destination: 192.168.1.28 (192.168.1.28)
User Datagram Protocol, Src Port: domain (53), Dst Port: 32776 (32776)
Source port: domain (53)
Destination port: 32776 (32776)
Length: 115
Checksum: 0x2d31 (correct)
Domain Name System (response)
Transaction ID: 0xe37e
Flags: 0x8180 (Standard query response, No error)
1... .... .... .... = Response: Message is a response
.000 0... .... .... = Opcode: Standard query (0)
.... .0.. .... .... = Authoritative: Server is not an authority for domain
.... ..0. .... .... = Truncated: Message is not truncated
.... ...1 .... .... = Recursion desired: Do query recursively
.... .... 1... .... = Recursion available: Server can do recursive queries
.... .... .0.. .... = Z: reserved (0)
.... .... ..0. .... = Answer authenticated: Answer/authority portion was not authentica
ted by the server
.... .... .... 0000 = Reply code: No error (0)
Questions: 1
Answer RRs: 1
Authority RRs: 3
Additional RRs: 0
Queries
weather.noaa.gov: type A, class IN
Name: weather.noaa.gov
Type: A (Host address)
Class: IN (0x0001)
Answers
weather.noaa.gov: type A, class IN, addr 205.156.51.200
Name: weather.noaa.gov
Type: A (Host address)
Class: IN (0x0001)
Time to live: 7 hours, 50 minutes, 4 seconds
Data length: 4
Addr: 205.156.51.200
Authoritative nameservers
noaa.gov: type NS, class IN, ns NS.noaa.gov
Name: noaa.gov
Type: NS (Authoritative name server)
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
Page 4
Class: IN (0x0001)
Time to live: 7 hours, 50 minutes, 4 seconds
Data length: 5
Name server: NS.noaa.gov
noaa.gov: type NS, class IN, ns MWRNS.noaa.gov
Name: noaa.gov
Type: NS (Authoritative name server)
Class: IN (0x0001)
Time to live: 7 hours, 50 minutes, 4 seconds
Data length: 8
Name server: MWRNS.noaa.gov
noaa.gov: type NS, class IN, ns NWRNS.noaa.gov
Name: noaa.gov
Type: NS (Authoritative name server)
Class: IN (0x0001)
Time to live: 7 hours, 50 minutes, 4 seconds
Data length: 8
Name server: NWRNS.noaa.gov
0000
0010
0020
0030
0040
0050
0060
0070
0080
0090
00
00
01
00
6f
00
00
02
14
52
18
87
1c
01
61
01
01
00
c0
4e
f3
2a
00
00
61
00
00
01
14
53
a8
2a
35
03
03
00
00
00
00
c0
0a
40
80
00
67
6e
6e
00
02
14
8a
00
08
00
6f
2c
2c
6e
00
00
40
00
07
76
00
00
2c
01
40
11
73
77
00
04
05
00
00
f4
8c
2d
65
00
cd
02
08
00
b7
cd
31
61
01
9c
4e
05
6e
ec
c0
e3
74
00
33
53
4d
2c
d8
a8
7e
68
01
c8
c0
57
00
08
01
81
65
c0
c0
14
52
08
00
02
80
72
0c
14
c0
4e
05
45
c0
00
04
00
00
14
53
4e
00
a8
01
6e
01
02
00
c0
57
.......@......E.
..**@.@.........
...5...s-1.~....
.......weather.n
oaa.gov.........
....n,....3.....
....n,...NS.....
.....n,...MWRNS.
.........n,...NW
RNS..
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
No.
Time
6 0.001348
response
Source
192.168.1.2
Destination
192.168.1.28
Page 5
Protocol Info
DNS
Standard query
Frame 6 (124 bytes on wire, 124 bytes captured)
Arrival Time: Jan 21, 2007 12:24:02.378562000
Time delta from previous packet: 0.000239000 seconds
Time since reference or first frame: 0.001348000 seconds
Frame Number: 6
Packet Length: 124 bytes
Capture Length: 124 bytes
Protocols in frame: eth:ip:udp:dns
Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a
Destination: 00:18:f3:a8:0a:8a (192.168.1.28)
Source: 00:40:f4:b7:ec:d8 (192.168.1.2)
Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168
.1.28)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 110
Identification: 0x2a2b (10795)
Flags: 0x04 (Don’t Fragment)
0... = Reserved bit: Not set
.1.. = Don’t fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: UDP (0x11)
Header checksum: 0x8ce5 (correct)
Source: 192.168.1.2 (192.168.1.2)
Destination: 192.168.1.28 (192.168.1.28)
User Datagram Protocol, Src Port: domain (53), Dst Port: 32777 (32777)
Source port: domain (53)
Destination port: 32777 (32777)
Length: 90
Checksum: 0xe754 (correct)
Domain Name System (response)
Transaction ID: 0x9f19
Flags: 0x8180 (Standard query response, No error)
1... .... .... .... = Response: Message is a response
.000 0... .... .... = Opcode: Standard query (0)
.... .0.. .... .... = Authoritative: Server is not an authority for domain
.... ..0. .... .... = Truncated: Message is not truncated
.... ...1 .... .... = Recursion desired: Do query recursively
.... .... 1... .... = Recursion available: Server can do recursive queries
.... .... .0.. .... = Z: reserved (0)
.... .... ..0. .... = Answer authenticated: Answer/authority portion was not authentica
ted by the server
.... .... .... 0000 = Reply code: No error (0)
Questions: 1
Answer RRs: 0
Authority RRs: 1
Additional RRs: 0
Queries
weather.noaa.gov: type AAAA, class IN
Name: weather.noaa.gov
Type: AAAA (IPv6 address)
Class: IN (0x0001)
Authoritative nameservers
noaa.gov: type SOA, class IN, mname NS.noaa.gov
Name: noaa.gov
Type: SOA (Start of zone of authority)
Class: IN (0x0001)
Time to live: 2 hours, 20 minutes
Data length: 36
Primary name server: NS.noaa.gov
Responsible authority’s mailbox: NOC@NOAA.gov
Serial number: 2007011901
Refresh interval: 3 hours
Retry interval: 1 hour
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
Page 6
Expiration limit: 7 days
Minimum TTL: 1 day
0000
0010
0020
0030
0040
0050
0060
0070
00
00
01
00
6f
00
43
00
18
6e
1c
00
61
01
40
00
f3
2a
00
00
61
00
4e
0e
a8
2b
35
01
03
00
4f
10
0a
40
80
00
67
20
41
00
8a
00
09
00
6f
d0
41
09
00
40
00
07
76
00
c0
3a
40
11
5a
77
00
24
19
80
f4
8c
e7
65
00
02
77
00
b7
e5
54
61
1c
4e
a0
01
ec
c0
9f
74
00
53
92
51
d8
a8
19
68
01
c0
3d
80
08
01
81
65
c0
14
00
00
02
80
72
14
08
00
45
c0
00
04
00
4e
2a
00
a8
01
6e
06
4f
30
.......@......E.
.n*+@.@.........
...5...Z.T......
.......weather.n
oaa.gov.........
.... ..$.NS...NO
C@NOAA..w..=..*0
......:...Q.
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
No.
Time
Source
7 0.001382
192.168.1.28
AAAA weather.noaa.gov.zuhause.xx
Page 7
Destination
192.168.1.2
Protocol Info
DNS
Standard query
Frame 7 (87 bytes on wire, 87 bytes captured)
Arrival Time: Jan 21, 2007 12:24:02.378596000
Time delta from previous packet: 0.000034000 seconds
Time since reference or first frame: 0.001382000 seconds
Frame Number: 7
Packet Length: 87 bytes
Capture Length: 87 bytes
Protocols in frame: eth:ip:udp:dns
Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8
Destination: 00:40:f4:b7:ec:d8 (192.168.1.2)
Source: 00:18:f3:a8:0a:8a (192.168.1.28)
Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16
8.1.2)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 73
Identification: 0x5990 (22928)
Flags: 0x04 (Don’t Fragment)
0... = Reserved bit: Not set
.1.. = Don’t fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: UDP (0x11)
Header checksum: 0x5da5 (correct)
Source: 192.168.1.28 (192.168.1.28)
Destination: 192.168.1.2 (192.168.1.2)
User Datagram Protocol, Src Port: 32777 (32777), Dst Port: domain (53)
Source port: 32777 (32777)
Destination port: domain (53)
Length: 53
Checksum: 0x6869 (correct)
Domain Name System (query)
Transaction ID: 0x46aa
Flags: 0x0100 (Standard query)
0... .... .... .... = Response: Message is a query
.000 0... .... .... = Opcode: Standard query (0)
.... ..0. .... .... = Truncated: Message is not truncated
.... ...1 .... .... = Recursion desired: Do query recursively
.... .... .0.. .... = Z: reserved (0)
.... .... ...0 .... = Non-authenticated data OK: Non-authenticated data is unacceptable
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 0
Queries
weather.noaa.gov.zuhause.xx: type AAAA, class IN
Name: weather.noaa.gov.zuhause.xx
Type: AAAA (IPv6 address)
Class: IN (0x0001)
0000
0010
0020
0030
0040
0050
00
00
01
00
6f
78
40
49
02
00
61
78
f4
59
80
00
61
00
b7
90
09
00
03
00
ec
40
00
00
67
1c
d8
00
35
00
6f
00
00
40
00
07
76
01
18
11
35
77
07
f3
5d
68
65
7a
a8
a5
69
61
75
0a
c0
46
74
68
8a
a8
aa
68
61
08
01
01
65
75
00
1c
00
72
73
45
c0
00
04
65
00
a8
01
6e
02
.@............E.
.IY.@.@.].......
.....5.5hiF.....
.......weather.n
oaa.gov.zuhause.
xx.....
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
No.
Time
Source
8 0.001836
192.168.1.2
response, No such name
Destination
192.168.1.28
Page 8
Protocol Info
DNS
Standard query
Frame 8 (135 bytes on wire, 135 bytes captured)
Arrival Time: Jan 21, 2007 12:24:02.379050000
Time delta from previous packet: 0.000454000 seconds
Time since reference or first frame: 0.001836000 seconds
Frame Number: 8
Packet Length: 135 bytes
Capture Length: 135 bytes
Protocols in frame: eth:ip:udp:dns
Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a
Destination: 00:18:f3:a8:0a:8a (192.168.1.28)
Source: 00:40:f4:b7:ec:d8 (192.168.1.2)
Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168
.1.28)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 121
Identification: 0x2a2c (10796)
Flags: 0x04 (Don’t Fragment)
0... = Reserved bit: Not set
.1.. = Don’t fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 64
Protocol: UDP (0x11)
Header checksum: 0x8cd9 (correct)
Source: 192.168.1.2 (192.168.1.2)
Destination: 192.168.1.28 (192.168.1.28)
User Datagram Protocol, Src Port: domain (53), Dst Port: 32777 (32777)
Source port: domain (53)
Destination port: 32777 (32777)
Length: 101
Checksum: 0xaddf (correct)
Domain Name System (response)
Transaction ID: 0x46aa
Flags: 0x8583 (Standard query response, No such name)
1... .... .... .... = Response: Message is a response
.000 0... .... .... = Opcode: Standard query (0)
.... .1.. .... .... = Authoritative: Server is an authority for domain
.... ..0. .... .... = Truncated: Message is not truncated
.... ...1 .... .... = Recursion desired: Do query recursively
.... .... 1... .... = Recursion available: Server can do recursive queries
.... .... .0.. .... = Z: reserved (0)
.... .... ..0. .... = Answer authenticated: Answer/authority portion was not authentica
ted by the server
.... .... .... 0011 = Reply code: No such name (3)
Questions: 1
Answer RRs: 0
Authority RRs: 1
Additional RRs: 0
Queries
weather.noaa.gov.zuhause.xx: type AAAA, class IN
Name: weather.noaa.gov.zuhause.xx
Type: AAAA (IPv6 address)
Class: IN (0x0001)
Authoritative nameservers
zuhause.xx: type SOA, class IN, mname server.zuhause.xx
Name: zuhause.xx
Type: SOA (Start of zone of authority)
Class: IN (0x0001)
Time to live: 2 hours
Data length: 36
Primary name server: server.zuhause.xx
Responsible authority’s mailbox: root.zuhause.xx
Serial number: 505074262
Refresh interval: 3 hours
Retry interval: 1 hour
/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal
Page 9
Expiration limit: 7 days
Minimum TTL: 1 day
0000
0010
0020
0030
0040
0050
0060
0070
0080
00
00
01
00
6f
78
20
74
09
18
79
1c
00
61
78
00
c0
3a
f3
2a
00
00
61
00
24
1d
80
a8
2c
35
01
03
00
06
1e
00
0a
40
80
00
67
1c
73
1a
01
8a
00
09
00
6f
00
65
d2
51
00
40
00
07
76
01
72
56
80
40
11
65
77
07
c0
76
00
f4
8c
ad
65
7a
1d
65
00
b7
d9
df
61
75
00
72
2a
ec
c0
46
74
68
06
c0
30
d8
a8
aa
68
61
00
1d
00
08
01
85
65
75
01
04
00
00
02
83
72
73
00
72
0e
45
c0
00
04
65
00
6f
10
00
a8
01
6e
02
1c
6f
00
.......@......E.
.y*,@.@.........
...5...e..F.....
.......weather.n
oaa.gov.zuhause.
xx..............
.$.server...roo
t.....V..*0.....
.:...Q.
Download