search for: 5840

Displaying 20 results from an estimated 167 matches for "5840".

Did you mean: 580
2006 Feb 08
0
[Bug 443] New: 2.6 kernel failing in NAT with significant outbound traffic
...pect that the upstream equipment are altering the packets somehow but, as I said, I cannot test further. I am providing summary tcpdump outputs from the various points: seen on client1: 1 0.000000 172.30.32.58 80.140.102.163 TCP 33265 > ftp [SYN] Seq=0 Ack=0 Win=5840 Len=0 MSS=1460 TSV=324137529 TSER=0 WS=2 2 2.999436 172.30.32.58 80.140.102.163 TCP 33265 > ftp [SYN] Seq=0 Ack=0 Win=23360 Len=0 MSS=1460 TSV=324140529 TSER=0 WS=2 3 3.048296 80.140.102.163 172.30.32.58 TCP ftp > 33265 [SYN, ACK] Se...
2005 Mar 02
12
Problem with outgoing Masquerade
....117.196.95... Connected to 216.117.196.95. Escape character is ''^]''. 220 mail.heronforge.net ESMTP Postfix quit 221 Bye Connection closed by foreign host. On eth5 on the firewall I see: 15:25:15.473608 192.168.124.18.36587 > 216.117.196.95.smtp: S 772082250:772082250(0) win 5840 <mss 1460,sackOK,timestamp 645676248 0,nop,wscale 0> (DF) [tos 0x10] 15:25:15.503249 216.117.196.95.smtp > 192.168.124.18.36587: S 1219378846:1219378846(0) ack 772082251 win 5792 <mss 1460,sackOK,timestamp 427958860 645676248,nop,wscale 2> (DF) 15:25:15.503403 192.168.124.18.36587...
2009 Jan 14
1
Transport endpoint is not connected while mounting....
...Here is a TCP dump showing port 7777 is not blocked (I added an exception in IP tables) (Node 0) 13:13:11.711539 IP (tos 0x0, ttl 64, id 18286, offset 0, flags [DF], proto: TCP (6), length: 60) 10.128.7.33.47601 > 10.128.255.3.cbt: S, cksum 0xd272 (correct), 3820380795:3820380795(0) win 5840 <mss 1460,sackOK,timestamp 4294911253 0,nop,wscale 6> 13:13:14.710703 IP (tos 0x0, ttl 64, id 18287, offset 0, flags [DF], proto: TCP (6), length: 60) 10.128.7.33.47601 > 10.128.255.3.cbt: S, cksum 0xc6ba (correct), 3820380795:3820380795(0) win 5840 <mss 1460,sackOK,timestamp 4...
2008 Sep 05
1
Weird TCP problem
...Both of those appear to indicate that the server in the colo facility is receiving the SYN packets. What possible reasons are there that it would not reply with SYN+ACK? -------------- next part -------------- 19:08:43.751579 IP officefw.57948 > remoteserver.ssh: S 3347102294:3347102294(0) win 5840 <mss1460,sackOK,timestamp 2705398041 0,nop,wscale 7> 19:08:46.751136 IP officefw.57948 > remoteserver.ssh: S 3347102294:3347102294(0) win 5840 <mss1460,sackOK,timestamp 2705401041 0,nop,wscale 7> 19:08:52.749305 IP officefw.57948 > remoteserver.ssh: S 3347102294:3347102294(0) win...
2018 May 10
2
Samba, AD and devices compatibility...
...nnections. Unencrypted connections only allow sasl binds with sign or seal. > > Default: ldap server require strong auth = yes So, doing some tests: AD, 'ldap server require strong auth = yes' (default) 8 32.680120 10.5.1.202 -> 10.5.1.25 TCP 74 40253→389 [SYN] Seq=0 Win=5840 Len=0 MSS=1460 SACK_PERM=1 TSval=121046256 TSecr=0 WS=16 9 32.680132 10.5.1.25 -> 10.5.1.202 TCP 74 389→40253 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=361876476 TSecr=121046256 WS=128 10 32.680292 10.5.1.202 -> 10.5.1.25 TCP 66 40253→389 [ACK] Seq=1 Ack...
2004 Nov 22
0
Samba machine wanting to connect to 192.168.192.1
...the bottom of this email is some output from tcpdump. Any ideas? I have looked through the smb.conf and the logs but there is no mention of that ip address. 12:26:48.319216 DevServer1.practical.local.netbios-ssn > 192.168.192.1.3771: S [tcp sum ok] 2917805052:2917805052(0) ack 1513987244 win 5840 <mss 1460,nop,nop,sackOK> (DF) (ttl 64, id 0, len 48) 12:26:53.719201 DevServer1.practical.local.netbios-ssn > 192.168.192.1.3788: S [tcp sum ok] 3001783991:3001783991(0) ack 1839800344 win 5840 <mss 1460,nop,nop,sackOK> (DF) (ttl 64, id 0, len 48) 12:27:04.319217 DevServer1.practica...
2002 May 30
3
eDonkey and Shorewall
Hi everybody! I''m very happy with shorewall, seems to safe my computer well, a little bit to well. But i''m sure it''s a mistake of mine: I can''t get edonkey working! They say that edonkey needs the following ports enabled: 4665 udp in / out 3665,4665,7665,8665 udp out 4661,4662,4666 tcp in thats what i wrote in the rules file: ACCEPT fw net
2002 Nov 08
1
bug on openssh 3.5p1
...root at victim's password: Permission denied, please try again. ......... root at victim's password: Read from remote host 10.12.7.110: Connection reset by peer Connection to victim closed. tcpdump session: 12:17:32.650039 attacker.32804 > victim.22: S 1378959426:1378959426(0) win 5840 12:17:32.650538 victim.22 > attacker.32804: S 671772074:671772074(0) ack 1378959427 win 5792 12:17:32.650627 attacker.32804 > victim.22: . ack 1 win 5840 12:17:32.651741 victim.22 > attacker.32804: P 1:24(23) ack 1 win 5792 12:17:32.652078 attacker.32804 > victim.22: . ac...
2005 Mar 26
1
Very slow wbinfo -u
...556624 172.20.3.131.1077 > 172.20.3.255.137: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST (DF) 21:22:04.826634 172.20.3.131.1077 > 172.20.3.255.137: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST (DF) 21:22:05.098145 172.20.3.131.1200 > 172.20.3.130.389: S 2238976557:2238976557(0) win 5840 <mss 1460,nop,nop,sackOK,nop,wscale 0> (DF) 21:22:05.098373 172.20.3.130.389 > 172.20.3.131.1200: S 925400727:925400727(0) ack 2238976558 win 65535 <mss 1460,nop,wscale 0,nop,nop,sackOK> (DF) 21:22:05.098655 172.20.3.131.1200 > 172.20.3.130.389: . ack 1 win 5840 (DF) 21:22:05.1...
2003 Jun 13
1
rsync error: error in rsync protocol data stream (code 12) at io.c(463)
...ro size (win 0), and client timesout or something and gave the error: <<==cut==>> 17:29:28.265592 box.example.com.rsync > 192.168.1.100.36310: R 1665045802:1665045802(0) win 0 (DF) 17:29:28.266160 192.168.1.100.36310 > box.example.com.rsync: . 102467925:102469373(1448) ack 94 win 5840 <nop,nop,timestamp 1985904015 26099400> (DF) 17:29:28.266212 box.example.com.rsync > 192.168.1.100.36310: R 1665045802:1665045802(0) win 0 (DF) 17:29:28.266770 192.168.1.100.36310 > box.example.com.rsync: . 102469373:102470821(1448) ack 94 win 5840 <nop,nop,timestamp 1985904015 26099...
2018 May 11
0
Samba, AD and devices compatibility...
...allow sasl binds with sign or seal. > > > Default: ldap server require strong auth = yes Correct. > > So, doing some tests: > > AD, 'ldap server require strong auth = yes' (default) > 8 32.680120 10.5.1.202 -> 10.5.1.25 TCP 74 40253→389 [SYN] Seq=0 Win=5840 Len=0 MSS=1460 SACK_PERM=1 TSval=121046256 TSecr=0 WS=16 > 9 32.680132 10.5.1.25 -> 10.5.1.202 TCP 74 389→40253 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=361876476 TSecr=121046256 WS=128 > 10 32.680292 10.5.1.202 -> 10.5.1.25 TCP 66 40253→389 [ACK]...
2010 Dec 17
5
Attack problem
HI, My system been attacked from someone I guess, kindly check the link below How can I stop the ircd attack http://pastebin.com/tbjh5qzP regards ********************************************* No employee or agent is authorized to conclude any binding agreement on behalf of Xplorium with another party by e-mail without express written confirmation by an officer of Xplorium. Any
2004 May 24
0
samba 3 keeps trying to authenticate with the nt4 pdc using port 445
...server, but not from samba server to nt4 pdc. Is there anyway to force samba to do communicate with my pdc using 139????? Thanks in advance, jamie CAPTURE OF DATA BETWEEN SAMBA SERVER AND PDC 2004-05-23 21:55:05.580707 IP OF SAMBA SERVER -> IP OF PDC TCP 32770 > 445 [SYN] Seq=0 Ack=0 Win=5840 Len=0 MSS=1460 TSV=14036 TSER=0 WS=0 2004-05-23 21:55:12.917997 IP OF SAMBA SERVER -> IP OF PDC NBNS Name query NBSTAT CENTRAL<1c> 2004-05-23 21:55:12.919868 IP OF PDC -> IP OF SAMBA SERVER NBNS Name query response NBSTAT 2004-05-23 21:55:12.920274 IP OF SAMBA SERVER -> IP OF PDC TCP...
2018 Mar 14
2
Samba, AD and devices compatibility...
Mandi! Andrew Bartlett via samba In chel di` si favelave... > > This mean that the printer try to auth in LDAP 'plain' (no SSL, no > > TLS), and so samba refuse that? > No, it means that Samba is refusing to accept a NTLM or Kerberos > authenticated connection without SIGN or SEAL negotiated, as an > attacker could take over an unprotected network connection and do
2018 May 11
0
Samba, AD and devices compatibility...
...t;>>> Default: ldap server require strong auth = yes > > Correct. > >> >> So, doing some tests: >> >> AD, 'ldap server require strong auth = yes' (default) >> 8 32.680120 10.5.1.202 -> 10.5.1.25 TCP 74 40253???389 [SYN] Seq=0 Win=5840 Len=0 MSS=1460 SACK_PERM=1 TSval=121046256 TSecr=0 WS=16 >> 9 32.680132 10.5.1.25 -> 10.5.1.202 TCP 74 389???40253 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=361876476 TSecr=121046256 WS=128 >> 10 32.680292 10.5.1.202 -> 10.5.1.25 TCP 66 40253??...
2007 Apr 23
1
Ubuntu feisty: trouble with vmware-player host-guest access...
...rbose output suppressed, use -v or -vv for full protocol decode listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes 17:44:19.144412 IP guest.1153 > host.ssh: F 2625691448:2625691448(0) ack 2930621145 win 64512 17:44:19.144932 IP host.ssh > guest.1153: F 39:39(0) ack 1 win 5840 17:44:19.146412 IP guest.1153 > host.ssh: . ack 1 win 64512 <nop,nop,sack 1 {39:40}> 17:44:29.171327 IP guest.1154 > host.ssh: S 1530035078:1530035078(0) win 64512 <mss 1460,nop,nop,sackOK> 17:44:29.171366 IP host.ssh > guest.1154: S 3017660595:3017660595(0) ack 1530035079 w...
2004 Aug 01
2
more on troubles with dmz www server
Thanks for the tips, Tom. Here is the tcpdump -n output on the dmz computer - this gets repeated several times as the remote computer attempts to connect: 18:11:54.264580 66.113.134.243.55080 > 192.168.2.1.8082: S 3210481212:3210481212(0) win 5840 <mss 1460,sackOK,timestamp 65650966 0,nop,wscale 0> (DF) 18:11:54.264696 192.168.2.1.8082 > 66.113.134.243.55080: S 2765561851:2765561851(0) ack 3210481213 win 16060 <mss 1460,sackOK,timestamp 8845122 65650966,nop,wscale 0> (DF) 18:11:55.336674 192.168.2.1.8082 > 66.113.134.243.5...
2004 Jun 10
1
multiple connections
...owing results. This is listening on eth1 as I try to SSH to the destination from an internal box (using lynx to connect to the same destination results in a web page): tcpdump: listening on eth1 07:13:12.614674 <Static IP>.37662 > <Dest IP>.ssh: S \ 2808907073:2808907073(0) win 5840 <mss1460,sackOK,timestamp \ 611570059 0,nop,wscale 0> (DF) 07:13:12.649772 <Dest IP>.ssh > <Static IP>.37662: S \ 2414052745:2414052745(0) \ ack 2808907074 win 65535 <mss 1400,nop,wscale \ 0,nop,nop,timestamp 2742813 611570059> (DF) 07:13:15.609403 <Sta...
2005 May 11
0
AD authentication almost but not quite
...ord authentication failed error code was NT_STATUS_ACCESS_DENIED (0xc0000022) error messsage was: Access denied Could not authenticate user mf1 with challenge/response Packet trace with ethereal shows... 91.572982 172.16.100.94 -> 172.16.100.202 TCP 1342 > microsoft-ds [SYN] Seq=0 Ack=0 Win=5840 Len=0 MSS=1460 TSV=455514 TSER=0 WS=0 91.573133 172.16.100.202 -> 172.16.100.94 TCP microsoft-ds > 1342 [SYN, ACK] Seq=0 Ack=1 Win=17520 Len=0 MSS=1460 WS=0 TSV=0 TSER=0 91.573177 172.16.100.94 -> 172.16.100.202 TCP 1342 > microsoft-ds [ACK] Seq=1 Ack=1 Win=5840 Len=0 TSV=455514 TSER=...
2006 Apr 09
3
Conntrack, nat and multipath - what is wrong here?
...0.0.0.0/0 Logging/tcpdump from an attempt to connect to port 25 on a remote server: Apr 9 21:55:47 eos mangle/PREROUTING:IN=eth0 OUT= MAC=00:40:f4:6b:6c:c1:00:01:02:1c:6f:29:08:00 SRC=192.168.1.20 DST=3.3.3.228 LEN=60 TOS=0x10 PREC=0x00 TTL=64 ID=41341 DF PROTO=TCP SPT=53218 DPT=25 WINDOW=5840 RES=0x00 SYN URGP=0 Apr 9 21:55:47 eos mangle/MARK6:IN=eth0 OUT= MAC=00:40:f4:6b:6c:c1:00:01:02:1c:6f:29:08:00 SRC=192.168.1.20 DST=3.3.3.228 LEN=60 TOS=0x10 PREC=0x00 TTL=64 ID=41341 DF PROTO=TCP SPT=53218 DPT=25 WINDOW=5840 RES=0x00 SYN URGP=0 Apr 9 21:55:47 eos nat/PREROUTING:IN=eth0 OUT=...