/tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal No. Time Source 1 0.000000 192.168.1.28 A weather.noaa.gov Page 1 Destination 192.168.1.2 Protocol Info DNS Standard query Frame 1 (76 bytes on wire, 76 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.377214000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 76 bytes Capture Length: 76 bytes Protocols in frame: eth:ip:udp:dns Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8 Destination: 00:40:f4:b7:ec:d8 (192.168.1.2) Source: 00:18:f3:a8:0a:8a (192.168.1.28) Type: IP (0x0800) Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16 8.1.2) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 62 Identification: 0x598f (22927) Flags: 0x04 (Don’t Fragment) 0... = Reserved bit: Not set .1.. = Don’t fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0x5db1 (correct) Source: 192.168.1.28 (192.168.1.28) Destination: 192.168.1.2 (192.168.1.2) User Datagram Protocol, Src Port: 32776 (32776), Dst Port: domain (53) Source port: 32776 (32776) Destination port: domain (53) Length: 42 Checksum: 0x1e76 (correct) Domain Name System (query) Transaction ID: 0xe37e Flags: 0x0100 (Standard query) 0... .... .... .... = Response: Message is a query .000 0... .... .... = Opcode: Standard query (0) .... ..0. .... .... = Truncated: Message is not truncated .... ...1 .... .... = Recursion desired: Do query recursively .... .... .0.. .... = Z: reserved (0) .... .... ...0 .... = Non-authenticated data OK: Non-authenticated data is unacceptable Questions: 1 Answer RRs: 0 Authority RRs: 0 Additional RRs: 0 Queries weather.noaa.gov: type A, class IN Name: weather.noaa.gov Type: A (Host address) Class: IN (0x0001) 0000 0010 0020 0030 0040 00 00 01 00 6f 40 3e 02 00 61 f4 59 80 00 61 b7 8f 08 00 03 ec 40 00 00 67 d8 00 35 00 6f 00 40 00 07 76 18 11 2a 77 00 f3 5d 1e 65 00 a8 b1 76 61 01 0a c0 e3 74 00 8a a8 7e 68 01 08 01 01 65 00 1c 00 72 45 c0 00 04 00 a8 01 6e .@............E. .>Y.@.@.]....... .....5.*.v.~.... .......weather.n oaa.gov..... /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal No. Time Source 2 0.000426 192.168.1.28 AAAA weather.noaa.gov Page 2 Destination 192.168.1.2 Protocol Info DNS Standard query Frame 2 (76 bytes on wire, 76 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.377640000 Time delta from previous packet: 0.000426000 seconds Time since reference or first frame: 0.000426000 seconds Frame Number: 2 Packet Length: 76 bytes Capture Length: 76 bytes Protocols in frame: eth:ip:udp:dns Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8 Destination: 00:40:f4:b7:ec:d8 (192.168.1.2) Source: 00:18:f3:a8:0a:8a (192.168.1.28) Type: IP (0x0800) Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16 8.1.2) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 62 Identification: 0x598f (22927) Flags: 0x04 (Don’t Fragment) 0... = Reserved bit: Not set .1.. = Don’t fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0x5db1 (correct) Source: 192.168.1.28 (192.168.1.28) Destination: 192.168.1.2 (192.168.1.2) User Datagram Protocol, Src Port: 32777 (32777), Dst Port: domain (53) Source port: 32777 (32777) Destination port: domain (53) Length: 42 Checksum: 0x62bf (correct) Domain Name System (query) Transaction ID: 0x9f19 Flags: 0x0100 (Standard query) 0... .... .... .... = Response: Message is a query .000 0... .... .... = Opcode: Standard query (0) .... ..0. .... .... = Truncated: Message is not truncated .... ...1 .... .... = Recursion desired: Do query recursively .... .... .0.. .... = Z: reserved (0) .... .... ...0 .... = Non-authenticated data OK: Non-authenticated data is unacceptable Questions: 1 Answer RRs: 0 Authority RRs: 0 Additional RRs: 0 Queries weather.noaa.gov: type AAAA, class IN Name: weather.noaa.gov Type: AAAA (IPv6 address) Class: IN (0x0001) 0000 0010 0020 0030 0040 00 00 01 00 6f 40 3e 02 00 61 f4 59 80 00 61 b7 8f 09 00 03 ec 40 00 00 67 d8 00 35 00 6f 00 40 00 07 76 18 11 2a 77 00 f3 5d 62 65 00 a8 b1 bf 61 1c 0a c0 9f 74 00 8a a8 19 68 01 08 01 01 65 00 1c 00 72 45 c0 00 04 00 a8 01 6e .@............E. .>Y.@.@.]....... .....5.*b....... .......weather.n oaa.gov..... /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal No. Time Source 5 0.001109 192.168.1.2 response A 205.156.51.200 Destination 192.168.1.28 Page 3 Protocol Info DNS Standard query Frame 5 (149 bytes on wire, 149 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.378323000 Time delta from previous packet: 0.000087000 seconds Time since reference or first frame: 0.001109000 seconds Frame Number: 5 Packet Length: 149 bytes Capture Length: 149 bytes Protocols in frame: eth:ip:udp:dns Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a Destination: 00:18:f3:a8:0a:8a (192.168.1.28) Source: 00:40:f4:b7:ec:d8 (192.168.1.2) Type: IP (0x0800) Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168 .1.28) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 135 Identification: 0x2a2a (10794) Flags: 0x04 (Don’t Fragment) 0... = Reserved bit: Not set .1.. = Don’t fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0x8ccd (correct) Source: 192.168.1.2 (192.168.1.2) Destination: 192.168.1.28 (192.168.1.28) User Datagram Protocol, Src Port: domain (53), Dst Port: 32776 (32776) Source port: domain (53) Destination port: 32776 (32776) Length: 115 Checksum: 0x2d31 (correct) Domain Name System (response) Transaction ID: 0xe37e Flags: 0x8180 (Standard query response, No error) 1... .... .... .... = Response: Message is a response .000 0... .... .... = Opcode: Standard query (0) .... .0.. .... .... = Authoritative: Server is not an authority for domain .... ..0. .... .... = Truncated: Message is not truncated .... ...1 .... .... = Recursion desired: Do query recursively .... .... 1... .... = Recursion available: Server can do recursive queries .... .... .0.. .... = Z: reserved (0) .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authentica ted by the server .... .... .... 0000 = Reply code: No error (0) Questions: 1 Answer RRs: 1 Authority RRs: 3 Additional RRs: 0 Queries weather.noaa.gov: type A, class IN Name: weather.noaa.gov Type: A (Host address) Class: IN (0x0001) Answers weather.noaa.gov: type A, class IN, addr 205.156.51.200 Name: weather.noaa.gov Type: A (Host address) Class: IN (0x0001) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 4 Addr: 205.156.51.200 Authoritative nameservers noaa.gov: type NS, class IN, ns NS.noaa.gov Name: noaa.gov Type: NS (Authoritative name server) /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal Page 4 Class: IN (0x0001) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 5 Name server: NS.noaa.gov noaa.gov: type NS, class IN, ns MWRNS.noaa.gov Name: noaa.gov Type: NS (Authoritative name server) Class: IN (0x0001) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 8 Name server: MWRNS.noaa.gov noaa.gov: type NS, class IN, ns NWRNS.noaa.gov Name: noaa.gov Type: NS (Authoritative name server) Class: IN (0x0001) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 8 Name server: NWRNS.noaa.gov 0000 0010 0020 0030 0040 0050 0060 0070 0080 0090 00 00 01 00 6f 00 00 02 14 52 18 87 1c 01 61 01 01 00 c0 4e f3 2a 00 00 61 00 00 01 14 53 a8 2a 35 03 03 00 00 00 00 c0 0a 40 80 00 67 6e 6e 00 02 14 8a 00 08 00 6f 2c 2c 6e 00 00 40 00 07 76 00 00 2c 01 40 11 73 77 00 04 05 00 00 f4 8c 2d 65 00 cd 02 08 00 b7 cd 31 61 01 9c 4e 05 6e ec c0 e3 74 00 33 53 4d 2c d8 a8 7e 68 01 c8 c0 57 00 08 01 81 65 c0 c0 14 52 08 00 02 80 72 0c 14 c0 4e 05 45 c0 00 04 00 00 14 53 4e 00 a8 01 6e 01 02 00 c0 57 .......@......E. ..**@.@......... ...5...s-1.~.... .......weather.n oaa.gov......... ....n,....3..... ....n,...NS..... .....n,...MWRNS. .........n,...NW RNS.. /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal No. Time 6 0.001348 response Source 192.168.1.2 Destination 192.168.1.28 Page 5 Protocol Info DNS Standard query Frame 6 (124 bytes on wire, 124 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.378562000 Time delta from previous packet: 0.000239000 seconds Time since reference or first frame: 0.001348000 seconds Frame Number: 6 Packet Length: 124 bytes Capture Length: 124 bytes Protocols in frame: eth:ip:udp:dns Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a Destination: 00:18:f3:a8:0a:8a (192.168.1.28) Source: 00:40:f4:b7:ec:d8 (192.168.1.2) Type: IP (0x0800) Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168 .1.28) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 110 Identification: 0x2a2b (10795) Flags: 0x04 (Don’t Fragment) 0... = Reserved bit: Not set .1.. = Don’t fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0x8ce5 (correct) Source: 192.168.1.2 (192.168.1.2) Destination: 192.168.1.28 (192.168.1.28) User Datagram Protocol, Src Port: domain (53), Dst Port: 32777 (32777) Source port: domain (53) Destination port: 32777 (32777) Length: 90 Checksum: 0xe754 (correct) Domain Name System (response) Transaction ID: 0x9f19 Flags: 0x8180 (Standard query response, No error) 1... .... .... .... = Response: Message is a response .000 0... .... .... = Opcode: Standard query (0) .... .0.. .... .... = Authoritative: Server is not an authority for domain .... ..0. .... .... = Truncated: Message is not truncated .... ...1 .... .... = Recursion desired: Do query recursively .... .... 1... .... = Recursion available: Server can do recursive queries .... .... .0.. .... = Z: reserved (0) .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authentica ted by the server .... .... .... 0000 = Reply code: No error (0) Questions: 1 Answer RRs: 0 Authority RRs: 1 Additional RRs: 0 Queries weather.noaa.gov: type AAAA, class IN Name: weather.noaa.gov Type: AAAA (IPv6 address) Class: IN (0x0001) Authoritative nameservers noaa.gov: type SOA, class IN, mname NS.noaa.gov Name: noaa.gov Type: SOA (Start of zone of authority) Class: IN (0x0001) Time to live: 2 hours, 20 minutes Data length: 36 Primary name server: NS.noaa.gov Responsible authority’s mailbox: NOC@NOAA.gov Serial number: 2007011901 Refresh interval: 3 hours Retry interval: 1 hour /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal Page 6 Expiration limit: 7 days Minimum TTL: 1 day 0000 0010 0020 0030 0040 0050 0060 0070 00 00 01 00 6f 00 43 00 18 6e 1c 00 61 01 40 00 f3 2a 00 00 61 00 4e 0e a8 2b 35 01 03 00 4f 10 0a 40 80 00 67 20 41 00 8a 00 09 00 6f d0 41 09 00 40 00 07 76 00 c0 3a 40 11 5a 77 00 24 19 80 f4 8c e7 65 00 02 77 00 b7 e5 54 61 1c 4e a0 01 ec c0 9f 74 00 53 92 51 d8 a8 19 68 01 c0 3d 80 08 01 81 65 c0 14 00 00 02 80 72 14 08 00 45 c0 00 04 00 4e 2a 00 a8 01 6e 06 4f 30 .......@......E. .n*+@.@......... ...5...Z.T...... .......weather.n oaa.gov......... .... ..$.NS...NO C@NOAA..w..=..*0 ......:...Q. /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal No. Time Source 7 0.001382 192.168.1.28 AAAA weather.noaa.gov.zuhause.xx Page 7 Destination 192.168.1.2 Protocol Info DNS Standard query Frame 7 (87 bytes on wire, 87 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.378596000 Time delta from previous packet: 0.000034000 seconds Time since reference or first frame: 0.001382000 seconds Frame Number: 7 Packet Length: 87 bytes Capture Length: 87 bytes Protocols in frame: eth:ip:udp:dns Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8 Destination: 00:40:f4:b7:ec:d8 (192.168.1.2) Source: 00:18:f3:a8:0a:8a (192.168.1.28) Type: IP (0x0800) Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16 8.1.2) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 73 Identification: 0x5990 (22928) Flags: 0x04 (Don’t Fragment) 0... = Reserved bit: Not set .1.. = Don’t fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0x5da5 (correct) Source: 192.168.1.28 (192.168.1.28) Destination: 192.168.1.2 (192.168.1.2) User Datagram Protocol, Src Port: 32777 (32777), Dst Port: domain (53) Source port: 32777 (32777) Destination port: domain (53) Length: 53 Checksum: 0x6869 (correct) Domain Name System (query) Transaction ID: 0x46aa Flags: 0x0100 (Standard query) 0... .... .... .... = Response: Message is a query .000 0... .... .... = Opcode: Standard query (0) .... ..0. .... .... = Truncated: Message is not truncated .... ...1 .... .... = Recursion desired: Do query recursively .... .... .0.. .... = Z: reserved (0) .... .... ...0 .... = Non-authenticated data OK: Non-authenticated data is unacceptable Questions: 1 Answer RRs: 0 Authority RRs: 0 Additional RRs: 0 Queries weather.noaa.gov.zuhause.xx: type AAAA, class IN Name: weather.noaa.gov.zuhause.xx Type: AAAA (IPv6 address) Class: IN (0x0001) 0000 0010 0020 0030 0040 0050 00 00 01 00 6f 78 40 49 02 00 61 78 f4 59 80 00 61 00 b7 90 09 00 03 00 ec 40 00 00 67 1c d8 00 35 00 6f 00 00 40 00 07 76 01 18 11 35 77 07 f3 5d 68 65 7a a8 a5 69 61 75 0a c0 46 74 68 8a a8 aa 68 61 08 01 01 65 75 00 1c 00 72 73 45 c0 00 04 65 00 a8 01 6e 02 .@............E. .IY.@.@.]....... .....5.5hiF..... .......weather.n oaa.gov.zuhause. xx..... /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal No. Time Source 8 0.001836 192.168.1.2 response, No such name Destination 192.168.1.28 Page 8 Protocol Info DNS Standard query Frame 8 (135 bytes on wire, 135 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.379050000 Time delta from previous packet: 0.000454000 seconds Time since reference or first frame: 0.001836000 seconds Frame Number: 8 Packet Length: 135 bytes Capture Length: 135 bytes Protocols in frame: eth:ip:udp:dns Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a Destination: 00:18:f3:a8:0a:8a (192.168.1.28) Source: 00:40:f4:b7:ec:d8 (192.168.1.2) Type: IP (0x0800) Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168 .1.28) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 121 Identification: 0x2a2c (10796) Flags: 0x04 (Don’t Fragment) 0... = Reserved bit: Not set .1.. = Don’t fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0x8cd9 (correct) Source: 192.168.1.2 (192.168.1.2) Destination: 192.168.1.28 (192.168.1.28) User Datagram Protocol, Src Port: domain (53), Dst Port: 32777 (32777) Source port: domain (53) Destination port: 32777 (32777) Length: 101 Checksum: 0xaddf (correct) Domain Name System (response) Transaction ID: 0x46aa Flags: 0x8583 (Standard query response, No such name) 1... .... .... .... = Response: Message is a response .000 0... .... .... = Opcode: Standard query (0) .... .1.. .... .... = Authoritative: Server is an authority for domain .... ..0. .... .... = Truncated: Message is not truncated .... ...1 .... .... = Recursion desired: Do query recursively .... .... 1... .... = Recursion available: Server can do recursive queries .... .... .0.. .... = Z: reserved (0) .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authentica ted by the server .... .... .... 0011 = Reply code: No such name (3) Questions: 1 Answer RRs: 0 Authority RRs: 1 Additional RRs: 0 Queries weather.noaa.gov.zuhause.xx: type AAAA, class IN Name: weather.noaa.gov.zuhause.xx Type: AAAA (IPv6 address) Class: IN (0x0001) Authoritative nameservers zuhause.xx: type SOA, class IN, mname server.zuhause.xx Name: zuhause.xx Type: SOA (Start of zone of authority) Class: IN (0x0001) Time to live: 2 hours Data length: 36 Primary name server: server.zuhause.xx Responsible authority’s mailbox: root.zuhause.xx Serial number: 505074262 Refresh interval: 3 hours Retry interval: 1 hour /tmp/dump/dump02_ARP_DNS-weather_SYN_FIN__complete-session - Ethereal Page 9 Expiration limit: 7 days Minimum TTL: 1 day 0000 0010 0020 0030 0040 0050 0060 0070 0080 00 00 01 00 6f 78 20 74 09 18 79 1c 00 61 78 00 c0 3a f3 2a 00 00 61 00 24 1d 80 a8 2c 35 01 03 00 06 1e 00 0a 40 80 00 67 1c 73 1a 01 8a 00 09 00 6f 00 65 d2 51 00 40 00 07 76 01 72 56 80 40 11 65 77 07 c0 76 00 f4 8c ad 65 7a 1d 65 00 b7 d9 df 61 75 00 72 2a ec c0 46 74 68 06 c0 30 d8 a8 aa 68 61 00 1d 00 08 01 85 65 75 01 04 00 00 02 83 72 73 00 72 0e 45 c0 00 04 65 00 6f 10 00 a8 01 6e 02 1c 6f 00 .......@......E. .y*,@.@......... ...5...e..F..... .......weather.n oaa.gov.zuhause. xx.............. .$.server...roo t.....V..*0..... .:...Q.