Re: icmp: type-#69 (catched that bastard)
On Sun, 15 Sep 2002, Tim Haynes wrote:
> Could you include a complete `tcpdump -X' on one or two of the packets,
> maybe make a series of them available for download in libpcap form so I can
> oogle them in ethereal?
Catched and oogled in ethereal:
,----
| Frame 308 (174 on wire, 96 captured)
| Arrival Time: Sep 15, 2002 16:48:03.440542000
| Time delta from previous packet: 0.771873000 seconds
| Time relative to first packet: 326.037135000 seconds
| Frame Number: 308
| Packet Length: 174 bytes
| Capture Length: 96 bytes
| Ethernet II
| Destination: ff:ff:ff:ff:ff:ff (ff:ff:ff:ff:ff:ff)
| Source: 00:a0:12:0f:32:e2 (00:a0:12:0f:32:e2)
| Type: IP (0x0800)
| Internet Protocol, Src Addr: 62.211.198.163 (62.211.198.163),
| Dst Addr: x.y.z.255 (x.y.z.255)
| Version: 4
| Header length: 20 bytes
| Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
| 0000 00.. = Differentiated Services Codepoint: Default (0x00)
| .... ..0. = ECN-Capable Transport (ECT): 0
| .... ...0 = ECN-CE: 0
| Total Length: 160
| Identification: 0x4e37
| Flags: 0x00
| .0.. = Don't fragment: Not set
| ..0. = More fragments: Not set
| Fragment offset: 0
| Time to live: 111
| Protocol: ICMP (0x01)
| Header checksum: 0x6ffb (correct)
| Source: 62.211.198.163 (62.211.198.163)
| Destination: x.y.z.255 (x.y.z.255)
| Internet Control Message Protocol
| Type: 69 (Unknown ICMP (obsolete or malformed?))
| Code: 0
| Checksum: 0x008c
`----
I don't see anything odd with it, except, of course, for the type.
Cheers,
Cristian
Reply to: