|

楼主 |
发表于 2006-1-20 08:21:04
|
显示全部楼层
使用TCPDUMP工具抓包,发现下面的情况,哪位帮忙分析一下。
07:53:19.838335 IP (tos 0x0, ttl 64, id 13, offset 0, flags [DF], length: 69) 221.218.162.110.1024 > dialdns.bta.net.cn.domain: [udp sum ok] 25218+% [1au] AAAA? www.sina.com. (41)
07:53:19.848080 IP (tos 0x0, ttl 249, id 28187, offset 0, flags [DF], length: 205) dialdns.bta.net.cn.domain > 221.218.162.110.1024: 25218 4/1/1 www.sina.com. CNAME[|domain]
07:53:19.859466 IP (tos 0x0, ttl 64, id 14, offset 0, flags [DF], length: 74) 221.218.162.110.1024 > dialdns.bta.net.cn.domain: [udp sum ok] 12609+% [1au] AAAA? libra.sina.com.cn. (46)
07:53:19.868676 IP (tos 0x0, ttl 249, id 4827, offset 0, flags [DF], length: 121) dialdns.bta.net.cn.domain > 221.218.162.110.1024: 12609 0/1/1 (93)
07:53:19.870750 IP (tos 0x0, ttl 64, id 15, offset 0, flags [DF], length: 74) 221.218.162.110.1024 > dialdns.bta.net.cn.domain: [udp sum ok] 13384+% [1au] A? libra.sina.com.cn. (46)
07:53:19.879992 IP (tos 0x0, ttl 249, id 53747, offset 0, flags [DF], length: 90) dialdns.bta.net.cn.domain > 221.218.162.110.1024: 13384 1/0/1 libra.sina.com.cn. A 202.108.33.32 (62)
07:53:20.070321 IP (tos 0x0, ttl 64, id 27242, offset 0, flags [DF], length: 60) 221.218.162.110.1051 > 202.108.33.32.www: S [tcp sum ok] 3760618258:3760618258(0) win 5808 <mss 1452,sackOK,timestamp 201080 0,nop,wscale 0>
07:53:20.078066 IP (tos 0x0, ttl 249, id 14063, offset 0, flags [none], length: 44) 202.108.33.32.www > 221.218.162.110.1051: S [tcp sum ok] 3574093499:3574093499(0) ack 3760618259 win 8190 <mss 1452>
07:53:20.078176 IP (tos 0x0, ttl 64, id 27243, offset 0, flags [DF], length: 40) 221.218.162.110.1051 > 202.108.33.32.www: . [tcp sum ok] ack 1 win 5808
07:53:20.080241 IP (tos 0x0, ttl 64, id 27244, offset 0, flags [DF], length: 1492) 221.218.162.110.1051 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:20.080337 IP (tos 0x0, ttl 64, id 27245, offset 0, flags [DF], length: 1156) 221.218.162.110.1051 > 202.108.33.32.www: P 1453:2569(1116) ack 1 win 5808
07:53:23.079749 IP (tos 0x0, ttl 64, id 27246, offset 0, flags [DF], length: 1492) 221.218.162.110.1051 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:29.078831 IP (tos 0x0, ttl 64, id 27247, offset 0, flags [DF], length: 1492) 221.218.162.110.1051 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:32.996367 IP (tos 0x0, ttl 64, id 27248, offset 0, flags [DF], length: 40) 221.218.162.110.1051 > 202.108.33.32.www: F [tcp sum ok] 2569:2569(0) ack 1 win 5808
07:53:39.104405 IP (tos 0x0, ttl 110, id 2834, offset 0, flags [none], length: 90) c-67-162-42-130.hsd1.il.comcast.net.22829 > 221.218.162.110.27576: UDP, length: 62
07:53:41.077023 IP (tos 0x0, ttl 64, id 27249, offset 0, flags [DF], length: 1492) 221.218.162.110.1051 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:41.219782 IP (tos 0x0, ttl 64, id 16, offset 0, flags [DF], length: 73) 221.218.162.110.1024 > dialdns.bta.net.cn.domain: [udp sum ok] 39460+% [1au] AAAA? news.sina.com.cn. (45)
07:53:41.229382 IP (tos 0x0, ttl 249, id 53748, offset 0, flags [DF], length: 162) dialdns.bta.net.cn.domain > 221.218.162.110.1024: 39460 2/1/1 news.sina.com.cn. CNAME[|domain]
07:53:41.239081 IP (tos 0x0, ttl 64, id 64785, offset 0, flags [DF], length: 60) 221.218.162.110.1052 > 202.108.33.32.www: S [tcp sum ok] 3778713917:3778713917(0) win 5808 <mss 1452,sackOK,timestamp 222252 0,nop,wscale 0>
07:53:41.247025 IP (tos 0x0, ttl 249, id 40216, offset 0, flags [none], length: 44) 202.108.33.32.www > 221.218.162.110.1052: S [tcp sum ok] 1755010236:1755010236(0) ack 3778713918 win 8190 <mss 1452>
07:53:41.247126 IP (tos 0x0, ttl 64, id 64786, offset 0, flags [DF], length: 40) 221.218.162.110.1052 > 202.108.33.32.www: . [tcp sum ok] ack 1 win 5808
07:53:41.249020 IP (tos 0x0, ttl 64, id 64787, offset 0, flags [DF], length: 1492) 221.218.162.110.1052 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:41.249117 IP (tos 0x0, ttl 64, id 64788, offset 0, flags [DF], length: 1156) 221.218.162.110.1052 > 202.108.33.32.www: P 1453:2569(1116) ack 1 win 5808
07:53:44.248533 IP (tos 0x0, ttl 64, id 64789, offset 0, flags [DF], length: 1492) 221.218.162.110.1052 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:48.022247 IP (tos 0x0, ttl 108, id 20050, offset 0, flags [DF], length: 48) user-69-73-126-240.knology.net.1826 > 221.218.162.110.radmin-port: S [tcp sum ok] 1821724890:1821724890(0) win 16384 <mss 1460,nop,nop,sackOK>
07:53:50.247616 IP (tos 0x0, ttl 64, id 64790, offset 0, flags [DF], length: 1492) 221.218.162.110.1052 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:53:54.614162 IP (tos 0x0, ttl 113, id 55906, offset 0, flags [none], length: 126) 222.172.138.3.10900 > 221.218.162.110.27576: UDP, length: 98
07:54:02.245796 IP (tos 0x0, ttl 64, id 64791, offset 0, flags [DF], length: 1492) 221.218.162.110.1052 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:54:04.797456 IP (tos 0x0, ttl 104, id 24402, offset 0, flags [none], length: 90) 84.242.156.166.7512 > 221.218.162.110.17270: UDP, length: 62
07:54:05.073360 IP (tos 0x0, ttl 64, id 27250, offset 0, flags [DF], length: 1492) 221.218.162.110.1051 > 202.108.33.32.www: . 1:1453(1452) ack 1 win 5808
07:54:05.362333 IP (tos 0x0, ttl 64, id 64792, offset 0, flags [DF], length: 40) 221.218.162.110.1052 > 202.108.33.32.www: F [tcp sum ok] 2569:2569(0) ack 1 win 5808
m |
|