2008年6月9日 星期一

TCP header digging

00 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Source Port Destination Port
Sequence Number
Acknowledgment Number
Data Offset reserved ECN Control Bits Window
Checksum Urgent Pointer
Options and padding :::
Data :::


Data Offset means the tcp header size (the total tcp header size is 4 * data offset value)

Example:
11:33:36.528451 IP (tos 0x0, ttl 119, id 7521, offset 0, flags [DF], proto TCP (6), length 52) 220.135.29.14.20715 > 140.113.28.230.ssh: S, cksum 0xff17 (correct), 2213150055:2213150055(0) win 64240
0x0000: 4500 0034 1d61 4000 7706 4376 dc87 1d0e E..4.a@.w.Cv....
0x0010: 8c71 1ce6 50eb 0016 83e9 fd67 0000 0000 .q..P......g....
0x0020: 8002 faf0 ff17 0000 0204 0584 0103 0300 ................
0x0030: 0101 0402

沒有留言: