Solved

Deciphering TCPDUMP

Posted on 1998-11-14
1
222 Views
Last Modified: 2013-12-26
Can someone give me a site that breaks down the output of TCPDUMP? Here is a sample output that i cant figure out:

21:52:32.058766 d196-tanna.net.1023 > praise.com.http: S 432195:432211(16) win 10052
21:52:32.228766 d196-tanna.net.1025 > ns1.tanna.net.domain: 39598+ (42)
21:52:32.658766 ns1.tanna.net.domain > d196-tanna.net.1025: 39598* 1/3/3 (203) (DF)
21:52:32.658766 d196-tanna.net.1027 > ns1.tanna.net.domain: 39599+ (46)
21:52:32.918766 ns1.tanna.net.domain > d196-tanna.net.1027: 39599* 1/2/2 (187) (DF)
21:52:32.918766 d196-tanna.net.1028 > ns1.tanna.net.domain: 39600+ (45)
21:52:33.158766 ns1.tanna.net.domain > d196-tanna.net.1028: 39600* 1/2/2 (160) (DF)

I understand the first line in that it is sending a "S"YN request with a ISN (Initial Sequence #) of 432195 and it appears to be sending a data packet of 16 bytes in size with a window size of a little of 10k.  Besides that i have no idea what the rest is saying ie. "DF", "*", "1/2/2", ".", etc...

Is there a site that breaks down this information or is the best way just to play around with it?

Thanks
0
Comment
Question by:aniston
1 Comment
 
LVL 51

Accepted Solution

by:
ahoffmann earned 20 total points
ID: 1294152
looks like an DNS answer, (DF) means don't fragment IP (see man tcpdump)
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Introduction: Ownerdraw of the grid button.  A singleton class implentation and usage. Continuing from the fifth article about sudoku.   Open the project in visual studio. Go to the class view – CGridButton should be visible as a class.  R…
Introduction: Hints for the grid button.  Nested classes, templated collections.  Squash that darned bug! Continuing from the sixth article about sudoku.   Open the project in visual studio. First we will finish with the SUD_SETVALUE messa…
This video will show you how to get GIT to work in Eclipse.   It will walk you through how to install the EGit plugin in eclipse and how to checkout an existing repository.
This video discusses moving either the default database or any database to a new volume.

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now