12.07.2015 Views

download

download

download

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 7There are several tools available to analyse the pcap dump files. The mostpopular application is Wireshark (formerly Ethereal) that is available inports tree at /usr/ports/net/wireshark.A sample tcpdump output on STDOUT taking 10 packets (note -c 10) from bge1interface (note -i bge1) would look like the following:# tcpdump -i bge1 -c 10 -ntcpdump: verbose output suppressed, use -v or -vv for full protocoldecodelistening on bge1, link-type EN10MB (Ethernet), capture size 96 bytes22:02:51.906888 IP 10.0.21.3.22 > 172.16.214.125.2423: P975531592:975531788(196) ack 959264752 win 25622:02:52.145987 IP 172.16.214.125.2423 > 10.0.21.3.22: . ack4294967140 win 857222:02:52.421072 IP 172.16.214.125.2423 > 10.0.21.3.22: . ack4294967244 win 846822:02:52.536168 STP 802.1d, Config, Flags [none], bridge-id8034.00:0e:83:ba:78:00.8026, length 4322:02:52.557813 IP 172.16.214.125.2423 > 10.0.21.3.22: . ack 196 win876022:02:52.906661 IP 10.0.21.3.22 > 172.16.214.125.2423: P 196:344(148)ack 1 win 25622:02:52.906703 IP 10.0.21.3.22 > 172.16.214.125.2423: P 344:668(324)ack 1 win 25622:02:52.906731 IP 10.0.21.3.22 > 172.16.214.125.2423: P 668:800(132)ack 1 win 25622:02:53.633585 IP 172.16.214.125.2423 > 10.0.21.3.22: . ack 668 win828822:02:53.636802 IP 172.16.214.125.2423 > 10.0.21.3.22: P 1:53(52) ack668 win 828810 packets captured12 packets received by filter0 packets dropped by kernelIn the above example, a very short network conversation is shown, that containssome SSH and STP (802.1d) traffic. From the above conversation, the systemadministrator can figure out a SSH session between 10.0.21.3 (the host that capturewas taken from) and 172.16.214.125 (a host that is connected to server via SSH)is ongoing. There is also a network switch that is talking STP on the port that isconnected to the host.[ 127 ]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!