*Sasha* писал(а): ↑08.01.2010 14:18
Когда пытаешься зайти что показывает?
Код: Выделить всё
tcpdump -i eth0 -n -nn -ttt dst port 80
tcpdump -i eth0 -n -nn -ttt dst port 8080
На убунте (128,1)
eth1 - это в инет
tun0 - это в виртуалку
Код: Выделить всё
den@den-desktop:/boot$ sudo tcpdump -i eth1 -n -nn -ttt dst port 80
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
00:00:00.000000 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [S], seq 2638136496, win 5840, options [mss 1460,sackOK,TS val 688167 ecr 0,nop,wscale 7], length 0
00:00:00.069825 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 2285703277, win 46, length 0
00:00:00.000109 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [P.], seq 0:1100, ack 1, win 46, length 1100
00:00:00.219929 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 1461, win 69, length 0
00:00:00.000549 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 2921, win 92, length 0
00:00:00.000077 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 4055, win 115, length 0
00:00:00.071044 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 5515, win 137, length 0
00:00:00.000062 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 6975, win 160, length 0
00:00:00.006468 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 8435, win 183, length 0
00:00:00.000064 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 9895, win 206, length 0
00:00:00.010808 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 11355, win 229, length 0
00:00:00.006310 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 12815, win 251, length 0
00:00:00.046217 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 14275, win 274, length 0
00:00:00.000359 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 15735, win 297, length 0
00:00:00.000037 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 16226, win 320, length 0
00:00:00.658301 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [P.], seq 1100:2292, ack 16226, win 320, length 1192
00:00:00.119636 IP 89.31.115.35.54373 > 88.212.196.101.80: Flags [S], seq 2662328868, win 5840, options [mss 1460,sackOK,TS val 688288 ecr 0,nop,wscale 7], length 0
00:00:00.045737 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 17686, win 343, length 0
00:00:00.000052 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 18750, win 365, length 0
00:00:00.001769 IP 89.31.115.35.38191 > 94.100.178.216.80: Flags [S], seq 2662283353, win 5840, options [mss 1460,sackOK,TS val 688293 ecr 0,nop,wscale 7], length 0
00:00:00.009633 IP 89.31.115.35.54373 > 88.212.196.101.80: Flags [.], ack 3872479849, win 46, options [nop,nop,TS val 688294 ecr 3895788099], length 0
00:00:00.000630 IP 89.31.115.35.54373 > 88.212.196.101.80: Flags [P.], seq 0:638, ack 1, win 46, options [nop,nop,TS val 688294 ecr 3895788099], length 638
00:00:00.045791 IP 89.31.115.35.38191 > 94.100.178.216.80: Flags [.], ack 2450959298, win 5840, length 0
00:00:00.000154 IP 89.31.115.35.38191 > 94.100.178.216.80: Flags [P.], seq 0:882, ack 1, win 5840, length 882
00:00:00.012248 IP 89.31.115.35.54373 > 88.212.196.101.80: Flags [.], ack 464, win 54, options [nop,nop,TS val 688300 ecr 3895788156], length 0
00:00:00.000282 IP 89.31.115.35.54373 > 88.212.196.101.80: Flags [F.], seq 638, ack 465, win 54, options [nop,nop,TS val 688300 ecr 3895788156], length 0
00:00:00.043666 IP 89.31.115.35.38191 > 94.100.178.216.80: Flags [.], ack 214, win 6432, length 0
00:00:00.000295 IP 89.31.115.35.38191 > 94.100.178.216.80: Flags [.], ack 893, win 8136, length 0
00:00:00.000511 IP 89.31.115.35.38191 > 94.100.178.216.80: Flags [F.], seq 882, ack 893, win 8136, length 0
00:01:14.921817 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [.], ack 18751, win 365, length 0
00:00:09.714106 IP 89.31.115.35.42533 > 89.104.102.12.80: Flags [F.], seq 2292, ack 18751, win 365, length 0
Код: Выделить всё
den@den-desktop:/boot$ sudo tcpdump -i tun0 -n -nn -ttt dst port 80
[sudo] password for den:
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tun0, link-type EN10MB (Ethernet), capture size 96 bytes
00:00:00.000000 IP 192.168.128.21.60340 > 130.57.4.24.80: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1559572 ecr 0,nop,wscale 5], length 0
00:00:02.988453 IP 192.168.128.21.60340 > 130.57.4.24.80: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1560322 ecr 0,nop,wscale 5], length 0
00:00:06.002525 IP 192.168.128.21.60340 > 130.57.4.24.80: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1561822 ecr 0,nop,wscale 5], length 0
00:00:12.000023 IP 192.168.128.21.60340 > 130.57.4.24.80: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1564822 ecr 0,nop,wscale 5], length 0
00:00:23.999804 IP 192.168.128.21.60340 > 130.57.4.24.80: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1570822 ecr 0,nop,wscale 5], length 0
00:00:47.997282 IP 192.168.128.21.60340 > 130.57.4.24.80: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1582822 ecr 0,nop,wscale 5], length 0
00:00:14.816071 IP 192.168.128.21.43856 > 74.125.87.100.80: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1586526 ecr 0,nop,wscale 5], length 0
00:00:03.000067 IP 192.168.128.21.43856 > 74.125.87.100.80: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1587276 ecr 0,nop,wscale 5], length 0
00:00:06.000305 IP 192.168.128.21.43856 > 74.125.87.100.80: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1588776 ecr 0,nop,wscale 5], length 0
00:00:11.999601 IP 192.168.128.21.43856 > 74.125.87.100.80: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1591776 ecr 0,nop,wscale 5], length 0
00:00:24.000004 IP 192.168.128.21.43856 > 74.125.87.100.80: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1597776 ecr 0,nop,wscale 5], length 0
00:00:48.000334 IP 192.168.128.21.43856 > 74.125.87.100.80: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1609776 ecr 0,nop,wscale 5], length 0
00:01:36.000142 IP 192.168.128.21.42481 > 74.125.87.101.80: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1633776 ecr 0,nop,wscale 5], length 0
00:00:03.000906 IP 192.168.128.21.42481 > 74.125.87.101.80: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1634526 ecr 0,nop,wscale 5], length 0
00:00:05.999936 IP 192.168.128.21.42481 > 74.125.87.101.80: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1636026 ecr 0,nop,wscale 5], length 0
00:00:12.000071 IP 192.168.128.21.42481 > 74.125.87.101.80: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1639026 ecr 0,nop,wscale 5], length 0
00:00:24.000294 IP 192.168.128.21.42481 > 74.125.87.101.80: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1645026 ecr 0,nop,wscale 5], length 0
Код: Выделить всё
den@den-desktop:/boot$ sudo tcpdump -i tun0 -n -nn -ttt dst port 8080
[sudo] password for den:
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tun0, link-type EN10MB (Ethernet), capture size 96 bytes
00:00:00.000000 IP 192.168.128.1.60340 > 192.168.128.10.8080: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1559572 ecr 0,nop,wscale 5], length 0
00:00:02.988420 IP 192.168.128.1.60340 > 192.168.128.10.8080: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1560322 ecr 0,nop,wscale 5], length 0
00:00:06.002521 IP 192.168.128.1.60340 > 192.168.128.10.8080: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1561822 ecr 0,nop,wscale 5], length 0
00:00:12.000024 IP 192.168.128.1.60340 > 192.168.128.10.8080: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1564822 ecr 0,nop,wscale 5], length 0
00:00:23.999806 IP 192.168.128.1.60340 > 192.168.128.10.8080: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1570822 ecr 0,nop,wscale 5], length 0
00:00:47.997304 IP 192.168.128.1.60340 > 192.168.128.10.8080: Flags [S], seq 655652135, win 5840, options [mss 1460,sackOK,TS val 1582822 ecr 0,nop,wscale 5], length 0
00:00:14.816066 IP 192.168.128.1.43856 > 192.168.128.10.8080: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1586526 ecr 0,nop,wscale 5], length 0
00:00:03.000049 IP 192.168.128.1.43856 > 192.168.128.10.8080: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1587276 ecr 0,nop,wscale 5], length 0
00:00:06.000304 IP 192.168.128.1.43856 > 192.168.128.10.8080: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1588776 ecr 0,nop,wscale 5], length 0
00:00:11.999600 IP 192.168.128.1.43856 > 192.168.128.10.8080: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1591776 ecr 0,nop,wscale 5], length 0
00:00:24.000011 IP 192.168.128.1.43856 > 192.168.128.10.8080: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1597776 ecr 0,nop,wscale 5], length 0
00:00:48.000302 IP 192.168.128.1.43856 > 192.168.128.10.8080: Flags [S], seq 2356585530, win 5840, options [mss 1460,sackOK,TS val 1609776 ecr 0,nop,wscale 5], length 0
00:01:36.000158 IP 192.168.128.1.42481 > 192.168.128.10.8080: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1633776 ecr 0,nop,wscale 5], length 0
00:00:03.000908 IP 192.168.128.1.42481 > 192.168.128.10.8080: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1634526 ecr 0,nop,wscale 5], length 0
00:00:05.999934 IP 192.168.128.1.42481 > 192.168.128.10.8080: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1636026 ecr 0,nop,wscale 5], length 0
00:00:12.000068 IP 192.168.128.1.42481 > 192.168.128.10.8080: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1639026 ecr 0,nop,wscale 5], length 0
00:00:24.000291 IP 192.168.128.1.42481 > 192.168.128.10.8080: Flags [S], seq 1004228672, win 5840, options [mss 1460,sackOK,TS val 1645026 ecr 0,nop,wscale 5], length 0
теперь на сузе с которой я пытаюсь открыть сайт
Код: Выделить всё
suse:~ # tcpdump -i eth0 -n -nn -ttt dst port 80
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
000000 IP 192.168.128.21.60340 > 130.57.4.24.80: S 655652135:655652135(0) win 5840 <mss 1460,sackOK,timestamp 1559572 0,nop,wscale 5>
2. 999366 IP 192.168.128.21.60340 > 130.57.4.24.80: S 655652135:655652135(0) win 5840 <mss 1460,sackOK,timestamp 1560322 0,nop,wscale 5>
6. 002411 IP 192.168.128.21.60340 > 130.57.4.24.80: S 655652135:655652135(0) win 5840 <mss 1460,sackOK,timestamp 1561822 0,nop,wscale 5>
12. 000324 IP 192.168.128.21.60340 > 130.57.4.24.80: S 655652135:655652135(0) win 5840 <mss 1460,sackOK,timestamp 1564822 0,nop,wscale 5>
23. 999737 IP 192.168.128.21.60340 > 130.57.4.24.80: S 655652135:655652135(0) win 5840 <mss 1460,sackOK,timestamp 1570822 0,nop,wscale 5>
47. 997501 IP 192.168.128.21.60340 > 130.57.4.24.80: S 655652135:655652135(0) win 5840 <mss 1460,sackOK,timestamp 1582822 0,nop,wscale 5>
14. 816163 IP 192.168.128.21.43856 > 74.125.87.100.80: S 2356585530:2356585530(0) win 5840 <mss 1460,sackOK,timestamp 1586526 0,nop,wscale 5>
3. 000053 IP 192.168.128.21.43856 > 74.125.87.100.80: S 2356585530:2356585530(0) win 5840 <mss 1460,sackOK,timestamp 1587276 0,nop,wscale 5>
5. 999905 IP 192.168.128.21.43856 > 74.125.87.100.80: S 2356585530:2356585530(0) win 5840 <mss 1460,sackOK,timestamp 1588776 0,nop,wscale 5>
12. 000010 IP 192.168.128.21.43856 > 74.125.87.100.80: S 2356585530:2356585530(0) win 5840 <mss 1460,sackOK,timestamp 1591776 0,nop,wscale 5>
23. 999968 IP 192.168.128.21.43856 > 74.125.87.100.80: S 2356585530:2356585530(0) win 5840 <mss 1460,sackOK,timestamp 1597776 0,nop,wscale 5>
48. 000904 IP 192.168.128.21.43856 > 74.125.87.100.80: S 2356585530:2356585530(0) win 5840 <mss 1460,sackOK,timestamp 1609776 0,nop,wscale 5>
96. 000668 IP 192.168.128.21.42481 > 74.125.87.101.80: S 1004228672:1004228672(0) win 5840 <mss 1460,sackOK,timestamp 1633776 0,nop,wscale 5>
2. 999418 IP 192.168.128.21.42481 > 74.125.87.101.80: S 1004228672:1004228672(0) win 5840 <mss 1460,sackOK,timestamp 1634526 0,nop,wscale 5>
6. 000020 IP 192.168.128.21.42481 > 74.125.87.101.80: S 1004228672:1004228672(0) win 5840 <mss 1460,sackOK,timestamp 1636026 0,nop,wscale 5>
12. 000050 IP 192.168.128.21.42481 > 74.125.87.101.80: S 1004228672:1004228672(0) win 5840 <mss 1460,sackOK,timestamp 1639026 0,nop,wscale 5>
24. 000000 IP 192.168.128.21.42481 > 74.125.87.101.80: S 1004228672:1004228672(0) win 5840 <mss 1460,sackOK,timestamp 1645026 0,nop,wscale 5>