ну вот он сниф изнутри фришки на которой фтп сервер.
весь сниф на действия ftp из командной строки, коннект с юзером и паролем и попыткой ls, получением ответа об illegal PORT command. потом команда quit
13:46:04.179519 81.13.45.50.5210 > 213.248.55.231.21: S 2182596728:2182596728(0) win 64512 <mss 1460,nop,nop,sackOK>
13:46:04.179565 213.248.55.231.21 > 81.13.45.50.5210: S 398652594:398652594(0) ack 2182596729 win 57344 <mss 1460> (DF)
13:46:04.186734 81.13.45.50.5210 > 213.248.55.231.21: . ack 1 win 64512
13:46:04.203240 213.248.55.231.3743 > 81.13.45.50.113: S 1492273229:1492273229(0) win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 5192529 0> (DF)
13:46:04.214513 81.13.45.50.113 > 213.248.55.231.3743: R 0:0(0) ack 1492273230 win 0
13:46:04.214802 213.248.55.231.21 > 81.13.45.50.5210: P 1:66(65) ack 1 win 58400 (DF) [tos 0x10]
13:46:04.359588 81.13.45.50.5210 > 213.248.55.231.21: . ack 66 win 64447
13:46:12.543888 81.13.45.50.5210 > 213.248.55.231.21: P 1:15(14) ack 66 win 64447
13:46:12.569418 213.248.55.231.21 > 81.13.45.50.5210: P 66:102(36) ack 15 win 58400 (DF) [tos 0x10]
13:46:12.778867 81.13.45.50.5210 > 213.248.55.231.21: . ack 102 win 64411
13:46:16.146151 81.13.45.50.5210 > 213.248.55.231.21: P 15:29(14) ack 102 win 64411
13:46:16.154945 213.248.55.231.21 > 81.13.45.50.5210: P 102:131(29) ack 29 win 58400 (DF) [tos 0x10]
13:46:16.278750 81.13.45.50.5210 > 213.248.55.231.21: . ack 131 win 64382
13:46:18.150354 81.13.45.50.5210 > 213.248.55.231.21: P 29:54(25) ack 131 win 64382
13:46:18.169973 213.248.55.231.21 > 81.13.45.50.5210: P 131:157(26) ack 54 win 58400 (DF) [tos 0x10]
13:46:18.202775 81.13.45.50.5210 > 213.248.55.231.21: P 54:60(6) ack 157 win 64356
13:46:18.203784 213.248.55.231.21 > 81.13.45.50.5210: P 157:214(57) ack 60 win 58400 (DF) [tos 0x10]
13:46:18.359050 81.13.45.50.5210 > 213.248.55.231.21: . ack 214 win 64299
13:46:21.922783 81.13.45.50.5210 > 213.248.55.231.21: P 60:66(6) ack 214 win 64299
13:46:21.923000 213.248.55.231.21 > 81.13.45.50.5210: P 214:228(14) ack 66 win 58400 (DF) [tos 0x10]
13:46:21.923117 213.248.55.231.21 > 81.13.45.50.5210: F 228:228(0) ack 66 win 58400 (DF) [tos 0x10]
13:46:21.929716 81.13.45.50.5210 > 213.248.55.231.21: . ack 229 win 64285
13:46:21.949651 81.13.45.50.5210 > 213.248.55.231.21: F 66:66(0) ack 229 win 64285
13:46:21.949673 213.248.55.231.21 > 81.13.45.50.5210: . ack 67 win 58400 (DF) [tos 0x10]
А вот результаты снифинга когда коннектился из другого места и нормально отработал фтп сессию.
13:58:49.550458 82.142.136.94.60350 > 213.248.55.231.21: P 29:56(27) ack 131 win 17390
13:58:49.551550 213.248.55.231.21 > 82.142.136.94.60350: P 131:160(29) ack 56 win 58400 (DF) [tos 0x10]
13:58:49.558606 82.142.136.94.60350 > 213.248.55.231.21: P 56:62(6) ack 160 win 17361
13:58:49.559353 213.248.55.231.20 > 82.142.136.94.60430: S 1932215662:1932215662(0) win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 5269063 0> (DF)
13:58:49.565199 82.142.136.94.60430 > 213.248.55.231.20: S 2286755331:2286755331(0) ack 1932215663 win 16384 <mss 1460,nop,wscale 0,nop,nop,timestamp 0 0>
13:58:49.565217 213.248.55.231.20 > 82.142.136.94.60430: . ack 1 win 57920 <nop,nop,timestamp 5269064 0> (DF)
13:58:49.565353 213.248.55.231.21 > 82.142.136.94.60350: P 160:214(54) ack 62 win 58400 (DF) [tos 0x10]
13:58:49.565459 213.248.55.231.20 > 82.142.136.94.60430: P 1:11(10) ack 1 win 57920 <nop,nop,timestamp 5269064 0> (DF)
13:58:49.565518 213.248.55.231.20 > 82.142.136.94.60430: F 11:11(0) ack 1 win 57920 <nop,nop,timestamp 5269064 0> (DF)
13:58:49.573316 82.142.136.94.60430 > 213.248.55.231.20: . ack 12 win 17510 <nop,nop,timestamp 6019479 5269063>
13:58:49.767699 82.142.136.94.60350 > 213.248.55.231.21: . ack 214 win 17307
13:58:50.512772 82.142.136.94.60430 > 213.248.55.231.20: F 1:1(0) ack 12 win 17510 <nop,nop,timestamp 6019488 5269063>
13:58:50.512822 213.248.55.231.20 > 82.142.136.94.60430: . ack 2 win 57920 <nop,nop,timestamp 5269159 6019488> (DF)
13:58:50.513108 213.248.55.231.21 > 82.142.136.94.60350: P 214:238(24) ack 62 win 58400 (DF) [tos 0x10]
13:58:50.673261 82.142.136.94.60350 > 213.248.55.231.21: . ack 238 win 17283
13:58:52.593244 82.142.136.94.60350 > 213.248.55.231.21: P 62:68(6) ack 238 win 17283
13:58:52.593458 213.248.55.231.21 > 82.142.136.94.60350: P 238:252(14) ack 68 win 58400 (DF) [tos 0x10]
13:58:52.593566 213.248.55.231.21 > 82.142.136.94.60350: F 252:252(0) ack 68 win 58400 (DF) [tos 0x10]
13:58:52.615377 82.142.136.94.60350 > 213.248.55.231.21: . ack 253 win 17269
13:58:52.852125 82.142.136.94.60350 > 213.248.55.231.21: F 68:68(0) ack 253 win 17269
13:58:52.852173 213.248.55.231.21 > 82.142.136.94.60350: . ack 69 win 58400 (DF) [tos 0x10]
|