>> 2050 61.745823 199.203.161.229 212.68.149.5 HTTP POST / HTTP/1.1
>Хорошо бы еще посмотреть HTTP-заголовки этого пакета
>
>> 2051 61.746012 212.68.149.5 199.203.161.229 HTTP HTTP/1.1 100 Continue
>> 2052 61.746042 212.68.149.5 199.203.161.229 HTTP HTTP/1.1 100 Continue
>и этих
POST :
--------------------------------------------------------------------
No. Time Source Destination Protocol Info
2050 61.745823 199.203.161.229 212.68.149.5 HTTP POST / HTTP/1.1
Frame 2050 (321 bytes on wire, 321 bytes captured)
Arrival Time: Apr 27, 2005 11:08:50.027690000
Time delta from previous packet: 0.008305000 seconds
Time since reference or first frame: 61.745823000 seconds
Frame Number: 2050
Packet Length: 321 bytes
Capture Length: 321 bytes
Ethernet II, Src: 00:0c:ce:da:84:8a, Dst: 00:07:e9:f2:d1:b4
Destination: 00:07:e9:f2:d1:b4 (Intel_f2:d1:b4)
Source: 00:0c:ce:da:84:8a (Cisco_da:84:8a)
Type: IP (0x0800)
Internet Protocol, Src Addr: 199.203.161.229 (199.203.161.229), Dst Addr: 212.68.149.5 (212.68.149.5)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 307
Identification: 0x50f0 (20720)
Flags: 0x04 (Don't Fragment)
0... = Reserved bit: Not set
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 122
Protocol: TCP (0x06)
Header checksum: 0xdbd9 (correct)
Source: 199.203.161.229 (199.203.161.229)
Destination: 212.68.149.5 (212.68.149.5)
Transmission Control Protocol, Src Port: 23712 (23712), Dst Port: 80 (80), Seq: 1, Ack: 1, Len: 267
Source port: 23712 (23712)
Destination port: 80 (80)
Sequence number: 1 (relative sequence number)
Next sequence number: 268 (relative sequence number)
Acknowledgement number: 1 (relative ack number)
Header length: 20 bytes
Flags: 0x0018 (PSH, ACK)
0... .... = Congestion Window Reduced (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 1... = Push: Set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Window size: 40960
Checksum: 0x23c0 (correct)
Hypertext Transfer Protocol
POST / HTTP/1.1\r\n
Request Method: POST
Accept: */*\r\n
Accept-Language: en-us\r\n
Content-Type: text/xml\r\n
Accept-Encoding: gzip, deflate\r\n
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)\r\n
Host: www.galor.com\r\n
Content-Length: 385\r\n
Connection: Keep-Alive\r\n
Cache-Control: no-cache\r\n
\r\n
100 CONTINUE:
------------------------------------------------------------------------------
No. Time Source Destination Protocol Info
2051 61.746012 212.68.149.5 199.203.161.229 HTTP HTTP/1.1 100 Continue
Frame 2051 (166 bytes on wire, 166 bytes captured)
Arrival Time: Apr 27, 2005 11:08:50.027879000
Time delta from previous packet: 0.000189000 seconds
Time since reference or first frame: 61.746012000 seconds
Frame Number: 2051
Packet Length: 166 bytes
Capture Length: 166 bytes
Ethernet II, Src: 00:07:e9:f2:d1:b4, Dst: 00:00:0c:07:ac:01
Destination: 00:00:0c:07:ac:01 (All-HSRP-routers_01)
Source: 00:07:e9:f2:d1:b4 (Intel_f2:d1:b4)
Type: IP (0x0800)
Internet Protocol, Src Addr: 212.68.149.5 (212.68.149.5), Dst Addr: 199.203.161.229 (199.203.161.229)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 152
Identification: 0xbfd9 (49113)
Flags: 0x04 (Don't Fragment)
0... = Reserved bit: Not set
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (0x06)
Header checksum: 0x678b (correct)
Source: 212.68.149.5 (212.68.149.5)
Destination: 199.203.161.229 (199.203.161.229)
Transmission Control Protocol, Src Port: 80 (80), Dst Port: 23712 (23712), Seq: 1, Ack: 268, Len: 112
Source port: 80 (80)
Destination port: 23712 (23712)
Sequence number: 1 (relative sequence number)
Next sequence number: 113 (relative sequence number)
Acknowledgement number: 268 (relative ack number)
Header length: 20 bytes
Flags: 0x0018 (PSH, ACK)
0... .... = Congestion Window Reduced (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 1... = Push: Set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Window size: 65268
Checksum: 0x0105 (correct)
SEQ/ACK analysis
This is an ACK to the segment in frame: 2050
The RTT to ACK the segment was: 0.000189000 seconds
Hypertext Transfer Protocol
HTTP/1.1 100 Continue\r\n
Response Code: 100
Server: Microsoft-IIS/5.0\r\n
Date: Wed, 27 Apr 2005 09:08:50 GMT\r\n
X-Powered-By: ASP.NET\r\n
\r\n
В пакетах по 1 байту SEQ растет с инкрементом +1 ( типа 1,2,3 и т.д )
ACK тоже меняется но как то рандомально ( по моему )
Меня смущает что у всех пакетов в 1 байт WINDOW SIZE всегда меньше чем в "хороших" : Window size: 40848
В нормальных он всегда больше 60000