Solved

Deciphering TCPDUMP

Posted on 1998-11-14
1
229 Views
Last Modified: 2013-12-26
Can someone give me a site that breaks down the output of TCPDUMP? Here is a sample output that i cant figure out:

21:52:32.058766 d196-tanna.net.1023 > praise.com.http: S 432195:432211(16) win 10052
21:52:32.228766 d196-tanna.net.1025 > ns1.tanna.net.domain: 39598+ (42)
21:52:32.658766 ns1.tanna.net.domain > d196-tanna.net.1025: 39598* 1/3/3 (203) (DF)
21:52:32.658766 d196-tanna.net.1027 > ns1.tanna.net.domain: 39599+ (46)
21:52:32.918766 ns1.tanna.net.domain > d196-tanna.net.1027: 39599* 1/2/2 (187) (DF)
21:52:32.918766 d196-tanna.net.1028 > ns1.tanna.net.domain: 39600+ (45)
21:52:33.158766 ns1.tanna.net.domain > d196-tanna.net.1028: 39600* 1/2/2 (160) (DF)

I understand the first line in that it is sending a "S"YN request with a ISN (Initial Sequence #) of 432195 and it appears to be sending a data packet of 16 bytes in size with a window size of a little of 10k.  Besides that i have no idea what the rest is saying ie. "DF", "*", "1/2/2", ".", etc...

Is there a site that breaks down this information or is the best way just to play around with it?

Thanks
0
Comment
Question by:aniston
1 Comment
 
LVL 51

Accepted Solution

by:
ahoffmann earned 20 total points
ID: 1294152
looks like an DNS answer, (DF) means don't fragment IP (see man tcpdump)
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VBA "SendKeys" Syntax for Multiple Keystrokes 7 108
MaxSpan challenge 9 94
Modbus - whats the maximum I can store in one register? 4 79
Line meaning 9 85
Introduction: Load and Save to file, Document-View interaction inside the SDI. Continuing from the second article about sudoku.   Open the project in visual studio. From the class view select CSudokuDoc and double click to open the header …
Exception Handling is in the core of any application that is able to dignify its name. In this article, I'll guide you through the process of writing a DRY (Don't Repeat Yourself) Exception Handling mechanism, using Aspect Oriented Programming.
This video will show you how to get GIT to work in Eclipse.   It will walk you through how to install the EGit plugin in eclipse and how to checkout an existing repository.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now