Исследование процессов в сети при использовании протоколов обмена Telnet и Ftp при помощи программы-анализатора трафика WireShark, страница 3

Клиент подтверждает и отправляет файл:

No.     Time        Source                Destination           Protocol Length Info

   1170 145.454654  10.219.15.197         81.222.215.235        TCP      74     9448 > ftp-data [SYN, ACK] Seq=0 Ack=1 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1 TSval=11336273 TSecr=60511048

Frame 1170: 74 bytes on wire (592 bits), 74 bytes captured (592 bits)

Ethernet II, Src: Giga-Byt_0d:6f:1a (00:1f:d0:0d:6f:1a), Dst: Cadant_36:0a:01 (00:01:5c:36:0a:01)

Internet Protocol Version 4, Src: 10.219.15.197 (10.219.15.197), Dst: 81.222.215.235 (81.222.215.235)

Transmission Control Protocol, Src Port: 9448 (9448), Dst Port: ftp-data (20), Seq: 0, Ack: 1, Len: 0

    Source port: 9448 (9448)

    Destination port: ftp-data (20)

    [Stream index: 29]

    Sequence number: 0    (relative sequence number)

    Acknowledgement number: 1    (relative ack number)

    Header length: 40 bytes

    Flags: 0x12 (SYN, ACK)

        000. .... .... = Reserved: Not set

        ...0 .... .... = Nonce: Not set

        .... 0... .... = Congestion Window Reduced (CWR): Not set

        .... .0.. .... = ECN-Echo: Not set

        .... ..0. .... = Urgent: Not set

        .... ...1 .... = Acknowledgement: Set

        .... .... 0... = Push: Not set

        .... .... .0.. = Reset: Not set

        .... .... ..1. = Syn: Set

        .... .... ...0 = Fin: Not set

    Window size value: 8192

    [Calculated window size: 8192]

    Checksum: 0x4498 [validation disabled]

    Options: (20 bytes)

    [SEQ/ACK analysis]

Сервер подтверждает получение файла (порты 21 и 9441):

No.     Time        Source                Destination           Protocol Length Info

   1173 145.491232  81.222.215.235        10.219.15.197         FTP      76     Response: 150 Ok to send data.

Frame 1173: 76 bytes on wire (608 bits), 76 bytes captured (608 bits)

Ethernet II, Src: Cadant_36:0a:01 (00:01:5c:36:0a:01), Dst: Giga-Byt_0d:6f:1a (00:1f:d0:0d:6f:1a)

Internet Protocol Version 4, Src: 81.222.215.235 (81.222.215.235), Dst: 10.219.15.197 (10.219.15.197)

Transmission Control Protocol, Src Port: ftp (21), Dst Port: 9441 (9441), Seq: 53, Ack: 45, Len: 22

    Source port: ftp (21)

    Destination port: 9441 (9441)

    [Stream index: 25]

    Sequence number: 53    (relative sequence number)

    [Next sequence number: 75    (relative sequence number)]

    Acknowledgement number: 45    (relative ack number)

    Header length: 20 bytes

    Flags: 0x18 (PSH, ACK)

        000. .... .... = Reserved: Not set

        ...0 .... .... = Nonce: Not set

        .... 0... .... = Congestion Window Reduced (CWR): Not set

        .... .0.. .... = ECN-Echo: Not set

        .... ..0. .... = Urgent: Not set

        .... ...1 .... = Acknowledgement: Set

        .... .... 1... = Push: Set

        .... .... .0.. = Reset: Not set

        .... .... ..0. = Syn: Not set

        .... .... ...0 = Fin: Not set

    Window size value: 46

    [Calculated window size: 46]

    [Window size scaling factor: -1 (unknown)]

    Checksum: 0xee98 [validation disabled]

    [SEQ/ACK analysis]

File Transfer Protocol (FTP)

    150 Ok to send data.\r\n

        Response code: File status okay; about to open data connection (150)

        Response arg: Ok to send data.

Далее происходит разрыв соединения между портами 20 и 9448 (флаги FIN и ACK):

No.     Time        Source                Destination           Protocol Length Info

   1174 145.503663  10.219.15.197         81.222.215.235        TCP      66     9448 > ftp-data [FIN, ACK] Seq=1 Ack=1 Win=66560 Len=0 TSval=11336277 TSecr=60511050

Transmission Control Protocol, Src Port: 9448 (9448), Dst Port: ftp-data (20), Seq: 1, Ack: 1, Len: 0

    Source port: 9448 (9448)

    Destination port: ftp-data (20)

No.     Time        Source                Destination           Protocol Length Info

   1175 145.529448  81.222.215.235        10.219.15.197         TCP      66     ftp-data > 9448 [FIN, ACK] Seq=1 Ack=2 Win=5888 Len=0 TSval=60511055 TSecr=11336277

Transmission Control Protocol, Src Port: ftp-data (20), Dst Port: 9448 (9448), Seq: 1, Ack: 2, Len: 0

    Source port: ftp-data (20)

    Destination port: 9448 (9448)