connection problems

Pete bubak at frdb1.fri.utc.sk
Thu Mar 13 08:07:00 CET 2003


On Wed, Mar 12, 2003 at 08:17:56PM +0100, Robert ?ezn??ek wrote:
> jak vypada spojeni mezi PC1 a PC2 na ip 192.168.1.1? zkousel jste treba
> tcpdumpem zkontroloval jak se komunikace chova na jednotlivych
> rozhranich? kam az dojede spojeni, kdyz si spustite ssh -v
> 192.168.100.111? kdyz vydrzite hodne dlouho, dojede to nakonec na
> timeout, nebo naskoci prompt? (v tom pripade by byl problem
> pravdepodobne se spetnou resolvaci jmena klienta).
> 
Na 192.168.1.2 pustim ssh -v user at 192.168.100.111
Reading info, Applying options, ssh_connect: needriv 0,
Connecting to 192.168.100.111 [192.168.100.111] port 22
Connection established
identity file /..../ type -1
identity file /..../ type -1
identity file /..../ type -1
....a tu ostane (cakal som 10 minut

trafshow na 192.168.1.1:
trafshow -in sl0
...pri pripojeni sa 192.168.1.2 na 192.168.100.111 (ssh -v...)
192.168.1.2..1032            192.168.100.111..22          tcp          60 12
192.168.100.111..22          192.168.1.2..1032            tcp          60

192.168.1.2..1032            192.168.100.111..22          tcp          60 12
192.168.100.111..22          192.168.1.2..1032            tcp         120

192.168.100.111..22          192.168.1.2..1032            tcp         180 36
...pri odpojeni (ssh -v dostane ctrl+c)
192.168.1.2..1032            192.168.100.111..22          tcp         104 10
192.168.100.111..22          192.168.1.2..1032            tcp          80

trafshow -in xl0
nic, co by sa tykalo connectu zpoza seriaku, len ssh na moj host

tcpdump pri connecte z 192.168.1.2 na 192.168.100.111 (ssh -v...)
tcpdump: listening on sl0
08:09:17.969308 192.168.1.2.1036 > 192.168.100.111.22: S 3617741483:3617741483(0) win 1024 <mss 256,sackOK,timestamp 186977 0,nop,wscale 0> (DF)
08:09:17.969560 192.168.100.111.22 > 192.168.1.2.1036: S 2599252234:2599252234(0) ack 3617741484 win 57344 <mss 512,nop,wscale 0,nop,nop,timestamp 6674904 186977> (DF)
08:09:20.961202 192.168.100.111.22 > 192.168.1.2.1036: S 2599252234:2599252234(0) ack 3617741484 win 57344 <mss 512,nop,wscale 0,nop,nop,timestamp 6675204 186977> (DF)
08:09:26.961318 192.168.100.111.22 > 192.168.1.2.1036: S 2599252234:2599252234(0) ack 3617741484 win 57344 <mss 512,nop,wscale 0,nop,nop,timestamp 6675804 186977> (DF)
08:09:38.961498 192.168.100.111.22 > 192.168.1.2.1036: S 2599252234:2599252234(0) ack 3617741484 win 57344 <mss 512,nop,wscale 0,nop,nop,timestamp 6677004 186977> (DF)

..a pri disconnecte
08:10:27.935847 192.168.1.2.1036 > 192.168.100.111.22: F 1:1(0) ack 1 win 1024 <nop,nop,timestamp 193974 6677004> (DF)
08:10:27.936012 192.168.100.111.22 > 192.168.1.2.1036: R 2599252235:2599252235(0) win 0


tot vse. vopred dakujem za napad/radu
Pete



More information about the Users-l mailing list