sorry for the late answere, i was some days off.
I downloaded the sorce from the site, and rebuild all jar's:
But no change: the hostname of the localsystem is still wrong.
My question: is the name really wrong, or is the name maybe decoded ?
So I added the complete wireshark logging. Please check pkt. 40 to 41 from the login.
My idea: the transfer of the clsid goes wrong, because changig user or password gives diffents results.
Using a wrong clsid seems the same results.
So: can you check the answeres from the systems in the logging file ?
Thanks a a lot.
******************************************
No. Time Source Destination Protocol Length Info
34 3.525424000 172.16.0.83 172.16.0.41 TCP 62 compaq-wcp > epmap [SYN] Seq=0 Win=65535 Len=0 MSS=1460 SACK_PERM=1
Frame 34: 62 bytes on wire (496 bits), 62 bytes captured (496 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.195915000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.195915000 seconds
[Time delta from previous captured frame: 0.025570000 seconds]
[Time delta from previous displayed frame: 0.000000000 seconds]
[Time since reference or first frame: 3.525424000 seconds]
Frame Number: 34
Frame Length: 62 bytes (496 bits)
Capture Length: 62 bytes (496 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 48
Identification: 0xcabe (51902)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd76c [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 0, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 0 (relative sequence number)
Header length: 28 bytes
Flags: 0x002 (SYN)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...0 .... = Acknowledgment: Not set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish request (SYN): server port epmap]
[Message: Connection establish request (SYN): server port epmap]
[Severity level: Chat]
[Group: Sequence]
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
Checksum: 0x2199 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (8 bytes), Maximum segment size, No-Operation (NOP), No-Operation (NOP), SACK permitted
Maximum segment size: 1460 bytes
Kind: MSS size (2)
Length: 4
MSS Value: 1460
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
TCP SACK Permitted Option: True
Kind: SACK Permission (4)
Length: 2
No. Time Source Destination Protocol Length Info
35 3.525545000 172.16.0.41 172.16.0.83 TCP 62 epmap > compaq-wcp [SYN, ACK] Seq=0 Ack=1 Win=64240 Len=0 MSS=1460 SACK_PERM=1
Frame 35: 62 bytes on wire (496 bits), 62 bytes captured (496 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.196036000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.196036000 seconds
[Time delta from previous captured frame: 0.000121000 seconds]
[Time delta from previous displayed frame: 0.000121000 seconds]
[Time since reference or first frame: 3.525545000 seconds]
Frame Number: 35
Frame Length: 62 bytes (496 bits)
Capture Length: 62 bytes (496 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 48
Identification: 0x9a4e (39502)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x07dd [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 0, Ack: 1, Len: 0
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 0 (relative sequence number)
Acknowledgment number: 1 (relative ack number)
Header length: 28 bytes
Flags: 0x012 (SYN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port epmap]
[Message: Connection establish acknowledge (SYN+ACK): server port epmap]
[Severity level: Chat]
[Group: Sequence]
.... .... ...0 = Fin: Not set
Window size value: 64240
[Calculated window size: 64240]
Checksum: 0x9891 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (8 bytes), Maximum segment size, No-Operation (NOP), No-Operation (NOP), SACK permitted
Maximum segment size: 1460 bytes
Kind: MSS size (2)
Length: 4
MSS Value: 1460
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
TCP SACK Permitted Option: True
Kind: SACK Permission (4)
Length: 2
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 34]
[The RTT to ACK the segment was: 0.000121000 seconds]
No. Time Source Destination Protocol Length Info
36 3.525571000 172.16.0.83 172.16.0.41 TCP 54 compaq-wcp > epmap [ACK] Seq=1 Ack=1 Win=65535 Len=0
Frame 36: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.196062000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.196062000 seconds
[Time delta from previous captured frame: 0.000026000 seconds]
[Time delta from previous displayed frame: 0.000026000 seconds]
[Time since reference or first frame: 3.525571000 seconds]
Frame Number: 36
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcabf (51903)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd773 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 1, Ack: 1, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 1 (relative sequence number)
Acknowledgment number: 1 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xc046 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 35]
[The RTT to ACK the segment was: 0.000026000 seconds]
No. Time Source Destination Protocol Length Info
40 3.653906000 172.16.0.83 172.16.0.41 DCERPC 185 Bind: call_id: 0 Fragment: Single, 1 context items: IOXIDResolver V0.0 (32bit NDR), NTLMSSP_NEGOTIATE
Frame 40: 185 bytes on wire (1480 bits), 185 bytes captured (1480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.324397000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.324397000 seconds
[Time delta from previous captured frame: 0.043107000 seconds]
[Time delta from previous displayed frame: 0.128335000 seconds]
[Time since reference or first frame: 3.653906000 seconds]
Frame Number: 40
Frame Length: 185 bytes (1480 bits)
Capture Length: 185 bytes (1480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 171
Identification: 0xcac0 (51904)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd6ef [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 1, Ack: 1, Len: 131
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 1 (relative sequence number)
[Next sequence number: 132 (relative sequence number)]
Acknowledgment number: 1 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xa2cb [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[Bytes in flight: 131]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Bind, Fragment: Single, FragLen: 131, Call: 0
Version: 5
Version (minor): 0
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 131
Auth Length: 51
Call ID: 0
Max Xmit Frag: 4280
Max Recv Frag: 4280
Assoc Group: 0x00000000
Num Ctx Items: 1
Ctx Item[1]: ID:0
Context ID: 0
Num Trans Items: 1
Abstract Syntax: IOXIDResolver V0.0
Interface: IOXIDResolver UUID: 99fcfec4-5260-101b-bbcb-00aa0021347a
Interface Ver: 0
Interface Ver Minor: 0
Transfer Syntax[1]: 32bit NDR V2
Transport Syntax: 32bit NDR UUID:8a885d04-1ceb-11c9-9fe8-08002b104860
ver: 2
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 0
Auth Rsrvd: 0
Auth Context ID: 1
NTLM Secure Service Provider
NTLMSSP identifier: NTLMSSP
NTLM Message Type: NTLMSSP_NEGOTIATE (0x00000001)
Flags: 0xa008b207
1... .... .... .... .... .... .... .... = Negotiate 56: Set
.0.. .... .... .... .... .... .... .... = Negotiate Key Exchange: Not set
..1. .... .... .... .... .... .... .... = Negotiate 128: Set
...0 .... .... .... .... .... .... .... = Negotiate 0x10000000: Not set
.... 0... .... .... .... .... .... .... = Negotiate 0x08000000: Not set
.... .0.. .... .... .... .... .... .... = Negotiate 0x04000000: Not set
.... ..0. .... .... .... .... .... .... = Negotiate Version: Not set
.... ...0 .... .... .... .... .... .... = Negotiate 0x01000000: Not set
.... .... 0... .... .... .... .... .... = Negotiate Target Info: Not set
.... .... .0.. .... .... .... .... .... = Request Non-NT Session: Not set
.... .... ..0. .... .... .... .... .... = Negotiate 0x00200000: Not set
.... .... ...0 .... .... .... .... .... = Negotiate Identify: Not set
.... .... .... 1... .... .... .... .... = Negotiate Extended Security: Set
.... .... .... .0.. .... .... .... .... = Target Type Share: Not set
.... .... .... ..0. .... .... .... .... = Target Type Server: Not set
.... .... .... ...0 .... .... .... .... = Target Type Domain: Not set
.... .... .... .... 1... .... .... .... = Negotiate Always Sign: Set
.... .... .... .... .0.. .... .... .... = Negotiate 0x00004000: Not set
.... .... .... .... ..1. .... .... .... = Negotiate OEM Workstation Supplied: Set
.... .... .... .... ...1 .... .... .... = Negotiate OEM Domain Supplied: Set
.... .... .... .... .... 0... .... .... = Negotiate 0x00000800: Not set
.... .... .... .... .... .0.. .... .... = Negotiate NT Only: Not set
.... .... .... .... .... ..1. .... .... = Negotiate NTLM key: Set
.... .... .... .... .... ...0 .... .... = Negotiate 0x00000100: Not set
.... .... .... .... .... .... 0... .... = Negotiate Lan Manager Key: Not set
.... .... .... .... .... .... .0.. .... = Negotiate Datagram: Not set
.... .... .... .... .... .... ..0. .... = Negotiate Seal: Not set
.... .... .... .... .... .... ...0 .... = Negotiate Sign: Not set
.... .... .... .... .... .... .... 0... = Request 0x00000008: Not set
.... .... .... .... .... .... .... .1.. = Request Target: Set
.... .... .... .... .... .... .... ..1. = Negotiate OEM: Set
.... .... .... .... .... .... .... ...1 = Negotiate UNICODE: Set
Calling workstation domain: SG5.TKN
Length: 7
Maxlen: 7
Offset: 32
Calling workstation name: JCIFS0_83_27
Length: 12
Maxlen: 12
Offset: 39
No. Time Source Destination Protocol Length Info
41 3.654408000 172.16.0.41 172.16.0.83 DCERPC 260 Bind_ack: call_id: 0 Fragment: Single, max_xmit: 4280 max_recv: 4280, 1 results: Acceptance, NTLMSSP_CHALLENGE
Frame 41: 260 bytes on wire (2080 bits), 260 bytes captured (2080 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.324899000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.324899000 seconds
[Time delta from previous captured frame: 0.000502000 seconds]
[Time delta from previous displayed frame: 0.000502000 seconds]
[Time since reference or first frame: 3.654408000 seconds]
Frame Number: 41
Frame Length: 260 bytes (2080 bits)
Capture Length: 260 bytes (2080 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 246
Identification: 0x9a56 (39510)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x070f [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 1, Ack: 132, Len: 206
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 1 (relative sequence number)
[Next sequence number: 207 (relative sequence number)]
Acknowledgment number: 132 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 64109
[Calculated window size: 64109]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x29ad [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 40]
[The RTT to ACK the segment was: 0.000502000 seconds]
[Bytes in flight: 206]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Bind_ack, Fragment: Single, FragLen: 206, Call: 0
Version: 5
Version (minor): 0
Packet type: Bind_ack (12)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 206
Auth Length: 138
Call ID: 0
Max Xmit Frag: 4280
Max Recv Frag: 4280
Assoc Group: 0x0000e938
Scndry Addr len: 4
Scndry Addr: 135
Num results: 1
Context ID[1]
Ack result: Acceptance (0)
Transfer Syntax: 32bit NDR
Syntax ver: 2
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 0
Auth Rsrvd: 0
Auth Context ID: 1
NTLM Secure Service Provider
NTLMSSP identifier: NTLMSSP
NTLM Message Type: NTLMSSP_CHALLENGE (0x00000002)
Target Name: SG5
Length: 6
Maxlen: 6
Offset: 48
NTLM Server Challenge: 8ad05491d36aca2f
Reserved: 0000000000000000
Target Info
Length: 84
Maxlen: 84
Offset: 54
Attribute: NetBIOS domain name: SG5
Target Info Item Type: NetBIOS domain name (0x0002)
Target Info Item Length: 6
NetBIOS Domain Name: SG5
Attribute: NetBIOS computer name: AA01CS1
Target Info Item Type: NetBIOS computer name (0x0001)
Target Info Item Length: 14
NetBIOS Computer Name: AA01CS1
Attribute: DNS domain name: SG5.TKN
Target Info Item Type: DNS domain name (0x0004)
Target Info Item Length: 14
DNS Domain Name: SG5.TKN
Attribute: DNS computer name: AA01CS1.SG5.TKN
Target Info Item Type: DNS computer name (0x0003)
Target Info Item Length: 30
DNS Computer Name: AA01CS1.SG5.TKN
Attribute: End of list
Target Info Item Type: End of list (0x0000)
Target Info Item Length: 0
No. Time Source Destination Protocol Length Info
43 3.850310000 172.16.0.83 172.16.0.41 TCP 54 compaq-wcp > epmap [ACK] Seq=132 Ack=207 Win=65329 Len=0
Frame 43: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.520801000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.520801000 seconds
[Time delta from previous captured frame: 0.002966000 seconds]
[Time delta from previous displayed frame: 0.195902000 seconds]
[Time since reference or first frame: 3.850310000 seconds]
Frame Number: 43
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcac1 (51905)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd771 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 132, Ack: 207, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 132 (relative sequence number)
Acknowledgment number: 207 (relative ack number)
Header length: 20 bytes
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65329
[Calculated window size: 65329]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xbfc3 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 41]
[The RTT to ACK the segment was: 0.195902000 seconds]
No. Time Source Destination Protocol Length Info
44 4.102775000 172.16.0.83 172.16.0.41 DCERPC 258 AUTH3: call_id: 0 Fragment: Single, NTLMSSP_AUTH, User: SG5.TKN\Administrator
Frame 44: 258 bytes on wire (2064 bits), 258 bytes captured (2064 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.773266000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.773266000 seconds
[Time delta from previous captured frame: 0.252465000 seconds]
[Time delta from previous displayed frame: 0.252465000 seconds]
[Time since reference or first frame: 4.102775000 seconds]
Frame Number: 44
Frame Length: 258 bytes (2064 bits)
Capture Length: 258 bytes (2064 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 244
Identification: 0xcac2 (51906)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd6a4 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 132, Ack: 207, Len: 204
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 132 (relative sequence number)
[Next sequence number: 336 (relative sequence number)]
Acknowledgment number: 207 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65329
[Calculated window size: 65329]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xa044 [validation disabled]
Lan Manager Response: 80dfd9fdf14e5e9b00000000000000000000000000000000
Length: 24
Maxlen: 24
Offset: 64
NTLM Client Challenge: 80dfd9fdf14e5e9b
NTLM Response: daf7856c9691da5b60c100c4c3cc5eb505508d57684c2d6a
Length: 24
Maxlen: 24
Offset: 88
Domain name: SG5.TKN
Length: 14
Maxlen: 14
Offset: 112
User name: Administrator
Length: 26
Maxlen: 26
Offset: 126
No. Time Source Destination Protocol Length Info
46 4.244934000 172.16.0.41 172.16.0.83 TCP 60 epmap > compaq-wcp [ACK] Seq=207 Ack=336 Win=63905 Len=0
Frame 46: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.915425000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.915425000 seconds
[Time delta from previous captured frame: 0.029164000 seconds]
[Time delta from previous displayed frame: 0.142159000 seconds]
[Time since reference or first frame: 4.244934000 seconds]
Frame Number: 46
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Padding: 020405b40101
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0x9a83 (39555)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x07b0 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 207, Ack: 336, Len: 0
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 207 (relative sequence number)
Acknowledgment number: 336 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63905
[Calculated window size: 63905]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xc487 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 44]
[The RTT to ACK the segment was: 0.142159000 seconds]
No. Time Source Destination Protocol Length Info
47 4.245015000 172.16.0.83 172.16.0.41 DCERPC 126 Alter_context: call_id: 1 Fragment: Single, 1 context items: REMACT V0.0 (32bit NDR)
Frame 47: 126 bytes on wire (1008 bits), 126 bytes captured (1008 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.915506000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.915506000 seconds
[Time delta from previous captured frame: 0.000081000 seconds]
[Time delta from previous displayed frame: 0.000081000 seconds]
[Time since reference or first frame: 4.245015000 seconds]
Frame Number: 47
Frame Length: 126 bytes (1008 bits)
Capture Length: 126 bytes (1008 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 112
Identification: 0xcac3 (51907)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd727 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 336, Ack: 207, Len: 72
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 336 (relative sequence number)
[Next sequence number: 408 (relative sequence number)]
Acknowledgment number: 207 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65329
[Calculated window size: 65329]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x8565 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[Bytes in flight: 72]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Alter_context, Fragment: Single, FragLen: 72, Call: 1
Version: 5
Version (minor): 0
Packet type: Alter_context (14)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 72
Auth Length: 0
Call ID: 1
Max Xmit Frag: 4280
Max Recv Frag: 4280
Assoc Group: 0x0000e938
Num Ctx Items: 1
Ctx Item[1]: ID:1
Context ID: 1
Num Trans Items: 1
Abstract Syntax: REMACT V0.0
Interface: REMACT UUID: 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57
Interface Ver: 0
Interface Ver Minor: 0
Transfer Syntax[1]: 32bit NDR V2
Transport Syntax: 32bit NDR UUID:8a885d04-1ceb-11c9-9fe8-08002b104860
ver: 2
No. Time Source Destination Protocol Length Info
48 4.245178000 172.16.0.41 172.16.0.83 DCERPC 110 Alter_context_resp: call_id: 1 Fragment: Single, max_xmit: 4280 max_recv: 4280, 1 results: Acceptance
Frame 48: 110 bytes on wire (880 bits), 110 bytes captured (880 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:04.915669000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764664.915669000 seconds
[Time delta from previous captured frame: 0.000163000 seconds]
[Time delta from previous displayed frame: 0.000163000 seconds]
[Time since reference or first frame: 4.245178000 seconds]
Frame Number: 48
Frame Length: 110 bytes (880 bits)
Capture Length: 110 bytes (880 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 96
Identification: 0x9a84 (39556)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x0777 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 207, Ack: 408, Len: 56
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 207 (relative sequence number)
[Next sequence number: 263 (relative sequence number)]
Acknowledgment number: 408 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63833
[Calculated window size: 63833]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x5aca [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 47]
[The RTT to ACK the segment was: 0.000163000 seconds]
[Bytes in flight: 56]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Alter_context_resp, Fragment: Single, FragLen: 56, Call: 1
Version: 5
Version (minor): 0
Packet type: Alter_context_resp (15)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 56
Auth Length: 0
Call ID: 1
Max Xmit Frag: 4280
Max Recv Frag: 4280
Assoc Group: 0x0000e938
Scndry Addr len: 0
Num results: 1
Context ID[1]
Ack result: Acceptance (0)
Transfer Syntax: 32bit NDR
Syntax ver: 2
No. Time Source Destination Protocol Length Info
49 4.353248000 172.16.0.83 172.16.0.41 TCP 54 compaq-wcp > epmap [ACK] Seq=408 Ack=263 Win=65273 Len=0
Frame 49: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.023739000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.023739000 seconds
[Time delta from previous captured frame: 0.108070000 seconds]
[Time delta from previous displayed frame: 0.108070000 seconds]
[Time since reference or first frame: 4.353248000 seconds]
Frame Number: 49
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcac4 (51908)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd76e [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 408, Ack: 263, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 408 (relative sequence number)
Acknowledgment number: 263 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65273
[Calculated window size: 65273]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xbeaf [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 48]
[The RTT to ACK the segment was: 0.108070000 seconds]
No. Time Source Destination Protocol Length Info
52 4.486804000 172.16.0.83 172.16.0.41 REMACT 206 RemoteActivation request CLSID=??? IID[1]=IUnknown IID[2]=IDispatch[Long frame (10 bytes)]
Frame 52: 206 bytes on wire (1648 bits), 206 bytes captured (1648 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.157295000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.157295000 seconds
[Time delta from previous captured frame: 0.081374000 seconds]
[Time delta from previous displayed frame: 0.133556000 seconds]
[Time since reference or first frame: 4.486804000 seconds]
Frame Number: 52
Frame Length: 206 bytes (1648 bits)
Capture Length: 206 bytes (1648 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 192
Identification: 0xcac5 (51909)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd6d5 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 408, Ack: 263, Len: 152
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 408 (relative sequence number)
[Next sequence number: 560 (relative sequence number)]
Acknowledgment number: 263 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65273
[Calculated window size: 65273]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x0b2a [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[Bytes in flight: 152]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Request, Fragment: Single, FragLen: 152, Call: 2 Ctx: 1, [Resp: #53]
Version: 5
Version (minor): 0
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 152
Auth Length: 0
Call ID: 2
Alloc hint: 128
Context ID: 1
Opnum: 0
[Response in frame: 53]
DCOM IRemoteActivation, RemoteActivation
Operation: RemoteActivation (0)
[Response in frame: 53]
DCOM, ORPCThis, V5.2, Causality ID: 0a3c0500-c6c4-a011-887b-9f165c087753
VersionMajor: 5
VersionMinor: 2
Flags: INFO_NULL (0x00000000)
Reserved: 0x00000000
Causality ID: 0a3c0500-c6c4-a011-887b-9f165c087753
CLSID: 68aec2ca-93cd-11d1-94e1-0020afc84400
ClientImplLevel: 3
Mode: 0
Interfaces: 2
IID[1]: IUnknown (00000000-0000-0000-c000-000000000046)
IID[2]: IDispatch (00020400-0000-0000-c000-000000000046)
RequestedProtSeqs: 1
ProtSeqs: NCACN_IP_TCP (7)
[Long frame (10 bytes)]
No. Time Source Destination Protocol Length Info
53 4.488787000 172.16.0.41 172.16.0.83 REMACT 710 RemoteActivation response S_OK[1] E_NOINTERFACE[2] -> S_OK
Frame 53: 710 bytes on wire (5680 bits), 710 bytes captured (5680 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.159278000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.159278000 seconds
[Time delta from previous captured frame: 0.001983000 seconds]
[Time delta from previous displayed frame: 0.001983000 seconds]
[Time since reference or first frame: 4.488787000 seconds]
Frame Number: 53
Frame Length: 710 bytes (5680 bits)
Capture Length: 710 bytes (5680 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
[Coloring Rule Name: DCERPC]
[Coloring Rule String: dcerpc]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 696
Identification: 0x9a96 (39574)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x050d [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 263, Ack: 560, Len: 656
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 263 (relative sequence number)
[Next sequence number: 919 (relative sequence number)]
Acknowledgment number: 560 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63681
[Calculated window size: 63681]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x258d [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 52]
[The RTT to ACK the segment was: 0.001983000 seconds]
[Bytes in flight: 656]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Response, Fragment: Single, FragLen: 656, Call: 2 Ctx: 1, [Req: #52]
Version: 5
Version (minor): 0
Packet type: Response (2)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 656
Auth Length: 16
Call ID: 2
Alloc hint: 608
Context ID: 1
Cancel count: 0
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 0
Auth Rsrvd: 0
Auth Context ID: 1
Opnum: 0
[Request in frame: 52]
[Time from request: 0.001983000 seconds]
NTLMSSP Verifier
Version Number: 1
Verifier Body: 000000000000000000000000
DCOM IRemoteActivation, RemoteActivation
Operation: RemoteActivation (0)
[Request in frame: 52]
DCOM, ORPCThat
Flags: INFO_LOCAL (0x00000001)
OXID: 0x3e0ebd51000001ab
OxidBindings: STRINGBINDINGs=3, SECURITYBINDINGs=5
NumEntries: 159
SecurityOffset: 62
StringBinding[1]: TowerId=NCACN_IP_TCP, NetworkAddr="AA01CS1.SG5.TKN[2056]"
TowerId: NCACN_IP_TCP (0x0007)
NetworkAddr: AA01CS1.SG5.TKN[2056]
StringBinding[2]: TowerId=NCACN_IP_TCP, NetworkAddr="172.16.4.41[2056]"
TowerId: NCACN_IP_TCP (0x0007)
NetworkAddr: 172.16.4.41[2056]
StringBinding[3]: TowerId=NCACN_IP_TCP, NetworkAddr="172.16.0.41[2056]"
TowerId: NCACN_IP_TCP (0x0007)
NetworkAddr: 172.16.0.41[2056]
SecurityBinding[1]: AuthnSvc=0x000a, AuthzSvc=0xffff, PrincName="NT AUTHORITY\SYSTEM"
AuthnSvc: RPC_C_AUTH_WINNT (0x000a)
AuthzSvc: Default (0xffff)
PrincName: NT AUTHORITY\SYSTEM
SecurityBinding[2]: AuthnSvc=0x0010, AuthzSvc=0xffff, PrincName="SG5\AA01CS1$"
AuthnSvc: RPC_C_AUTHN_GSS_KERBEROS (0x0010)
AuthzSvc: Default (0xffff)
PrincName: SG5\AA01CS1$
SecurityBinding[3]: AuthnSvc=0x0009, AuthzSvc=0xffff, PrincName="SG5\AA01CS1$"
AuthnSvc: RPC_C_AUTHN_GSS_NEGOTIATE (0x0009)
AuthzSvc: Default (0xffff)
PrincName: SG5\AA01CS1$
SecurityBinding[4]: AuthnSvc=0x0011, AuthzSvc=0xffff, PrincName="NT AUTHORITY\SYSTEM"
AuthnSvc: RPC_C_AUTHN_MSN (0x0011)
AuthzSvc: Default (0xffff)
PrincName: NT AUTHORITY\SYSTEM
SecurityBinding[5]: AuthnSvc=0x0012, AuthzSvc=0xffff, PrincName="NT AUTHORITY\SYSTEM"
AuthnSvc: RPC_C_AUTHN_DPA (0x0012)
AuthzSvc: Default (0xffff)
PrincName: NT AUTHORITY\SYSTEM
IPID: 0000ac03-04e4-05a8-b902-67d5d342cb6c
AuthnHint: 4
VersionMajor: 5
VersionMinor: 6
HResult: S_OK (0x00000000)
InterfaceData
CntData: 194
OBJREF
Signature: MEOW (0x574f454d)
Flags: OBJREF_STANDARD (0x00000001)
IID: IUnknown (00000000-0000-0000-c000-000000000046)
STDOBJREF: PublicRefs=5 IPID=00019422-04e4-05a8-a9c8-b5a439c204f8
Flags: SORF_NULL (0x00000000)
PublicRefs: 0x00000005
OXID: 0x3e0ebd51000001ab
OID: 0x3f0418a600005909
IPID: 00019422-04e4-05a8-a9c8-b5a439c204f8
ResolverAddress: STRINGBINDINGs=3, SECURITYBINDINGs=6
NumEntries: 63
SecurityOffset: 44
StringBinding[1]: TowerId=NCACN_IP_TCP, NetworkAddr="AA01CS1.SG5.TKN"
TowerId: NCACN_IP_TCP (0x0007)
NetworkAddr: AA01CS1.SG5.TKN
StringBinding[2]: TowerId=NCACN_IP_TCP, NetworkAddr="172.16.4.41"
TowerId: NCACN_IP_TCP (0x0007)
NetworkAddr: 172.16.4.41
StringBinding[3]: TowerId=NCACN_IP_TCP, NetworkAddr="172.16.0.41"
TowerId: NCACN_IP_TCP (0x0007)
NetworkAddr: 172.16.0.41
[Expert Info (Note/Undecoded): DUALSTRINGARRAY: multiple IP's 172.16.4.41 172.16.0.41]
[Message: DUALSTRINGARRAY: multiple IP's 172.16.4.41 172.16.0.41]
[Severity level: Note]
[Group: Undecoded]
SecurityBinding[1]: AuthnSvc=0x0009, AuthzSvc=0xffff, PrincName=""
AuthnSvc: RPC_C_AUTHN_GSS_NEGOTIATE (0x0009)
AuthzSvc: Default (0xffff)
PrincName:
SecurityBinding[2]: AuthnSvc=0x0010, AuthzSvc=0xffff, PrincName=""
AuthnSvc: RPC_C_AUTHN_GSS_KERBEROS (0x0010)
AuthzSvc: Default (0xffff)
PrincName:
SecurityBinding[3]: AuthnSvc=0x000a, AuthzSvc=0xffff, PrincName=""
AuthnSvc: RPC_C_AUTH_WINNT (0x000a)
AuthzSvc: Default (0xffff)
PrincName:
SecurityBinding[4]: AuthnSvc=0x000e, AuthzSvc=0xffff, PrincName=""
AuthnSvc: RPC_C_AUTHN_GSS_SCHANNEL (0x000e)
AuthzSvc: Default (0xffff)
PrincName:
SecurityBinding[5]: AuthnSvc=0x0011, AuthzSvc=0xffff, PrincName=""
AuthnSvc: RPC_C_AUTHN_MSN (0x0011)
AuthzSvc: Default (0xffff)
PrincName:
SecurityBinding[6]: AuthnSvc=0x0012, AuthzSvc=0xffff, PrincName=""
AuthnSvc: RPC_C_AUTHN_DPA (0x0012)
AuthzSvc: Default (0xffff)
PrincName:
HResult[1]: S_OK (0x00000000)
HResult[2]: E_NOINTERFACE (0x80004002)
[Expert Info (Note/Response): Hresult: E_NOINTERFACE]
[Message: Hresult: E_NOINTERFACE]
[Severity level: Note]
[Group: Response]
HResult: S_OK (0x00000000)
No. Time Source Destination Protocol Length Info
57 4.655010000 172.16.0.83 172.16.0.41 TCP 54 compaq-wcp > epmap [ACK] Seq=560 Ack=919 Win=64617 Len=0
Frame 57: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.325501000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.325501000 seconds
[Time delta from previous captured frame: 0.064850000 seconds]
[Time delta from previous displayed frame: 0.166223000 seconds]
[Time since reference or first frame: 4.655010000 seconds]
Frame Number: 57
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcac6 (51910)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd76c [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 560, Ack: 919, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 560 (relative sequence number)
Acknowledgment number: 919 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 64617
[Calculated window size: 64617]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xbe17 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 53]
[The RTT to ACK the segment was: 0.166223000 seconds]
No. Time Source Destination Protocol Length Info
58 4.667943000 172.16.0.83 172.16.0.41 TCP 54 compaq-wcp > epmap [FIN, ACK] Seq=560 Ack=919 Win=64617 Len=0
Frame 58: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.338434000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.338434000 seconds
[Time delta from previous captured frame: 0.012933000 seconds]
[Time delta from previous displayed frame: 0.012933000 seconds]
[Time since reference or first frame: 4.667943000 seconds]
Frame Number: 58
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP SYN/FIN]
[Coloring Rule String: tcp.flags & 0x02 || tcp.flags.fin == 1]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcac7 (51911)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd76b [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 560, Ack: 919, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 560 (relative sequence number)
Acknowledgment number: 919 (relative ack number)
Header length: 20 bytes
Flags: 0x011 (FIN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 64617
[Calculated window size: 64617]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xbe16 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
No. Time Source Destination Protocol Length Info
59 4.668065000 172.16.0.41 172.16.0.83 TCP 60 epmap > compaq-wcp [ACK] Seq=919 Ack=561 Win=63681 Len=0
Frame 59: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.338556000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.338556000 seconds
[Time delta from previous captured frame: 0.000122000 seconds]
[Time delta from previous displayed frame: 0.000122000 seconds]
[Time since reference or first frame: 4.668065000 seconds]
Frame Number: 59
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
[Coloring Rule Name: TCP]
[Coloring Rule String: tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Padding: 020405b40101
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0x9aa4 (39588)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x078f [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 919, Ack: 561, Len: 0
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 919 (relative sequence number)
Acknowledgment number: 561 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63681
[Calculated window size: 63681]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xc1be [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 58]
[The RTT to ACK the segment was: 0.000122000 seconds]
No. Time Source Destination Protocol Length Info
60 4.668109000 172.16.0.41 172.16.0.83 TCP 60 epmap > compaq-wcp [FIN, ACK] Seq=919 Ack=561 Win=63681 Len=0
Frame 60: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.338600000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.338600000 seconds
[Time delta from previous captured frame: 0.000044000 seconds]
[Time delta from previous displayed frame: 0.000044000 seconds]
[Time since reference or first frame: 4.668109000 seconds]
Frame Number: 60
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Padding: 020405b40101
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0x9aa5 (39589)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x078e [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: epmap (135), Dst Port: compaq-wcp (2555), Seq: 919, Ack: 561, Len: 0
Source port: epmap (135)
Destination port: compaq-wcp (2555)
[Stream index: 0]
Sequence number: 919 (relative sequence number)
Acknowledgment number: 561 (relative ack number)
Header length: 20 bytes
Flags: 0x011 (FIN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 63681
[Calculated window size: 63681]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xc1bd [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
No. Time Source Destination Protocol Length Info
61 4.668122000 172.16.0.83 172.16.0.41 TCP 54 compaq-wcp > epmap [ACK] Seq=561 Ack=920 Win=64617 Len=0
Frame 61: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.338613000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.338613000 seconds
[Time delta from previous captured frame: 0.000013000 seconds]
[Time delta from previous displayed frame: 0.000013000 seconds]
[Time since reference or first frame: 4.668122000 seconds]
Frame Number: 61
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcac8 (51912)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd76a [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: compaq-wcp (2555), Dst Port: epmap (135), Seq: 561, Ack: 920, Len: 0
Source port: compaq-wcp (2555)
Destination port: epmap (135)
[Stream index: 0]
Sequence number: 561 (relative sequence number)
Acknowledgment number: 920 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 64617
[Calculated window size: 64617]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xbe15 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 60]
[The RTT to ACK the segment was: 0.000013000 seconds]
No. Time Source Destination Protocol Length Info
62 4.700189000 172.16.0.83 172.16.0.41 TCP 62 nicetec-nmsvc > omnisky [SYN] Seq=0 Win=65535 Len=0 MSS=1460 SACK_PERM=1
Frame 62: 62 bytes on wire (496 bits), 62 bytes captured (496 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.370680000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.370680000 seconds
[Time delta from previous captured frame: 0.032067000 seconds]
[Time delta from previous displayed frame: 0.032067000 seconds]
[Time since reference or first frame: 4.700189000 seconds]
Frame Number: 62
Frame Length: 62 bytes (496 bits)
Capture Length: 62 bytes (496 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 48
Identification: 0xcac9 (51913)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd761 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 0, Len: 0
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 0 (relative sequence number)
Header length: 28 bytes
Flags: 0x002 (SYN)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...0 .... = Acknowledgment: Not set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish request (SYN): server port omnisky]
[Message: Connection establish request (SYN): server port omnisky]
[Severity level: Chat]
[Group: Sequence]
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
Checksum: 0xded1 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (8 bytes), Maximum segment size, No-Operation (NOP), No-Operation (NOP), SACK permitted
Maximum segment size: 1460 bytes
Kind: MSS size (2)
Length: 4
MSS Value: 1460
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
TCP SACK Permitted Option: True
Kind: SACK Permission (4)
Length: 2
No. Time Source Destination Protocol Length Info
63 4.700314000 172.16.0.41 172.16.0.83 TCP 62 omnisky > nicetec-nmsvc [SYN, ACK] Seq=0 Ack=1 Win=64240 Len=0 MSS=1460 SACK_PERM=1
Frame 63: 62 bytes on wire (496 bits), 62 bytes captured (496 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.370805000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.370805000 seconds
[Time delta from previous captured frame: 0.000125000 seconds]
[Time delta from previous displayed frame: 0.000125000 seconds]
[Time since reference or first frame: 4.700314000 seconds]
Frame Number: 63
Frame Length: 62 bytes (496 bits)
Capture Length: 62 bytes (496 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 48
Identification: 0x9aaa (39594)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x0781 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 0, Ack: 1, Len: 0
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 0 (relative sequence number)
Acknowledgment number: 1 (relative ack number)
Header length: 28 bytes
Flags: 0x012 (SYN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..1. = Syn: Set
[Expert Info (Chat/Sequence): Connection establish acknowledge (SYN+ACK): server port omnisky]
[Message: Connection establish acknowledge (SYN+ACK): server port omnisky]
[Severity level: Chat]
[Group: Sequence]
.... .... ...0 = Fin: Not set
Window size value: 64240
[Calculated window size: 64240]
Checksum: 0x040e [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (8 bytes), Maximum segment size, No-Operation (NOP), No-Operation (NOP), SACK permitted
Maximum segment size: 1460 bytes
Kind: MSS size (2)
Length: 4
MSS Value: 1460
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
No-Operation (NOP)
Type: 1
0... .... = Copy on fragmentation: No
.00. .... = Class: Control (0)
...0 0001 = Number: No-Operation (NOP) (1)
TCP SACK Permitted Option: True
Kind: SACK Permission (4)
Length: 2
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 62]
[The RTT to ACK the segment was: 0.000125000 seconds]
No. Time Source Destination Protocol Length Info
64 4.700341000 172.16.0.83 172.16.0.41 TCP 54 nicetec-nmsvc > omnisky [ACK] Seq=1 Ack=1 Win=65535 Len=0
Frame 64: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.370832000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.370832000 seconds
[Time delta from previous captured frame: 0.000027000 seconds]
[Time delta from previous displayed frame: 0.000027000 seconds]
[Time since reference or first frame: 4.700341000 seconds]
Frame Number: 64
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcaca (51914)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd768 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 1, Ack: 1, Len: 0
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 1 (relative sequence number)
Acknowledgment number: 1 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x2bc3 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 63]
[The RTT to ACK the segment was: 0.000027000 seconds]
No. Time Source Destination Protocol Length Info
65 4.702552000 172.16.0.83 172.16.0.41 DCERPC 185 Bind: call_id: 0 Fragment: Single, 1 context items: IRemUnknown2 V0.0 (32bit NDR), NTLMSSP_NEGOTIATE
Frame 65: 185 bytes on wire (1480 bits), 185 bytes captured (1480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.373043000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.373043000 seconds
[Time delta from previous captured frame: 0.002211000 seconds]
[Time delta from previous displayed frame: 0.002211000 seconds]
[Time since reference or first frame: 4.702552000 seconds]
Frame Number: 65
Frame Length: 185 bytes (1480 bits)
Capture Length: 185 bytes (1480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 171
Identification: 0xcacb (51915)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd6e4 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 1, Ack: 1, Len: 131
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 1 (relative sequence number)
[Next sequence number: 132 (relative sequence number)]
Acknowledgment number: 1 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65535
[Calculated window size: 65535]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x380c [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[Bytes in flight: 131]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Bind, Fragment: Single, FragLen: 131, Call: 0
Version: 5
Version (minor): 0
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 131
Auth Length: 51
Call ID: 0
Max Xmit Frag: 4280
Max Recv Frag: 4280
Assoc Group: 0x00000000
Num Ctx Items: 1
Ctx Item[1]: ID:0
Context ID: 0
Num Trans Items: 1
Abstract Syntax: IRemUnknown2 V0.0
Interface: IRemUnknown2 UUID: 00000143-0000-0000-c000-000000000046
Interface Ver: 0
Interface Ver Minor: 0
Transfer Syntax[1]: 32bit NDR V2
Transport Syntax: 32bit NDR UUID:8a885d04-1ceb-11c9-9fe8-08002b104860
ver: 2
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 0
Auth Rsrvd: 0
NTLM Secure Service Provider
NTLMSSP identifier: NTLMSSP
NTLM Message Type: NTLMSSP_NEGOTIATE (0x00000001)
Flags: 0xa008b207
1... .... .... .... .... .... .... .... = Negotiate 56: Set
.0.. .... .... .... .... .... .... .... = Negotiate Key Exchange: Not set
..1. .... .... .... .... .... .... .... = Negotiate 128: Set
...0 .... .... .... .... .... .... .... = Negotiate 0x10000000: Not set
.... 0... .... .... .... .... .... .... = Negotiate 0x08000000: Not set
.... .0.. .... .... .... .... .... .... = Negotiate 0x04000000: Not set
.... ..0. .... .... .... .... .... .... = Negotiate Version: Not set
.... ...0 .... .... .... .... .... .... = Negotiate 0x01000000: Not set
.... .... 0... .... .... .... .... .... = Negotiate Target Info: Not set
.... .... .0.. .... .... .... .... .... = Request Non-NT Session: Not set
.... .... ..0. .... .... .... .... .... = Negotiate 0x00200000: Not set
.... .... ...0 .... .... .... .... .... = Negotiate Identify: Not set
.... .... .... 1... .... .... .... .... = Negotiate Extended Security: Set
.... .... .... .0.. .... .... .... .... = Target Type Share: Not set
.... .... .... ..0. .... .... .... .... = Target Type Server: Not set
.... .... .... ...0 .... .... .... .... = Target Type Domain: Not set
.... .... .... .... 1... .... .... .... = Negotiate Always Sign: Set
.... .... .... .... .0.. .... .... .... = Negotiate 0x00004000: Not set
.... .... .... .... ..1. .... .... .... = Negotiate OEM Workstation Supplied: Set
.... .... .... .... ...1 .... .... .... = Negotiate OEM Domain Supplied: Set
.... .... .... .... .... 0... .... .... = Negotiate 0x00000800: Not set
.... .... .... .... .... .0.. .... .... = Negotiate NT Only: Not set
.... .... .... .... .... ..1. .... .... = Negotiate NTLM key: Set
.... .... .... .... .... ...0 .... .... = Negotiate 0x00000100: Not set
.... .... .... .... .... .... 0... .... = Negotiate Lan Manager Key: Not set
.... .... .... .... .... .... .0.. .... = Negotiate Datagram: Not set
.... .... .... .... .... .... ..0. .... = Negotiate Seal: Not set
.... .... .... .... .... .... ...0 .... = Negotiate Sign: Not set
.... .... .... .... .... .... .... 0... = Request 0x00000008: Not set
.... .... .... .... .... .... .... .1.. = Request Target: Set
.... .... .... .... .... .... .... ..1. = Negotiate OEM: Set
.... .... .... .... .... .... .... ...1 = Negotiate UNICODE: Set
Calling workstation domain: SG5.TKN
Length: 7
Maxlen: 7
Offset: 32
Calling workstation name: JCIFS0_83_27
Length: 12
Maxlen: 12
Offset: 39
No. Time Source Destination Protocol Length Info
66 4.702913000 172.16.0.41 172.16.0.83 DCERPC 260 Bind_ack: call_id: 0 Fragment: Single, max_xmit: 4280 max_recv: 4280, 1 results: Acceptance, NTLMSSP_CHALLENGE
Frame 66: 260 bytes on wire (2080 bits), 260 bytes captured (2080 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.373404000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.373404000 seconds
[Time delta from previous captured frame: 0.000361000 seconds]
[Time delta from previous displayed frame: 0.000361000 seconds]
[Time since reference or first frame: 4.702913000 seconds]
Frame Number: 66
Frame Length: 260 bytes (2080 bits)
Capture Length: 260 bytes (2080 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 246
Identification: 0x9aab (39595)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x06ba [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 1, Ack: 132, Len: 206
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 1 (relative sequence number)
[Next sequence number: 207 (relative sequence number)]
Acknowledgment number: 132 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 64109
[Calculated window size: 64109]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x464a [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 65]
[The RTT to ACK the segment was: 0.000361000 seconds]
[Bytes in flight: 206]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Bind_ack, Fragment: Single, FragLen: 206, Call: 0
Version: 5
Version (minor): 0
Packet type: Bind_ack (12)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 206
Auth Length: 138
Call ID: 0
Max Xmit Frag: 4280
Max Recv Frag: 4280
Assoc Group: 0x000123c2
Scndry Addr len: 5
Scndry Addr: 2056
Num results: 1
Context ID[1]
Ack result: Acceptance (0)
Transfer Syntax: 32bit NDR
Syntax ver: 2
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 0
Auth Rsrvd: 0
NTLM Secure Service Provider
NTLMSSP identifier: NTLMSSP
NTLM Message Type: NTLMSSP_CHALLENGE (0x00000002)
Target Name: SG5
Length: 6
Maxlen: 6
Offset: 48
NTLM Server Challenge: 383f8c84bf6cba3d
Reserved: 0000000000000000
Target Info
Length: 84
Maxlen: 84
Offset: 54
Attribute: NetBIOS domain name: SG5
Target Info Item Type: NetBIOS domain name (0x0002)
Target Info Item Length: 6
NetBIOS Domain Name: SG5
Attribute: NetBIOS computer name: AA01CS1
Target Info Item Type: NetBIOS computer name (0x0001)
Target Info Item Length: 14
NetBIOS Computer Name: AA01CS1
Attribute: DNS domain name: SG5.TKN
Target Info Item Type: DNS domain name (0x0004)
Target Info Item Length: 14
DNS Domain Name: SG5.TKN
Attribute: DNS computer name: AA01CS1.SG5.TKN
Target Info Item Type: DNS computer name (0x0003)
Target Info Item Length: 30
DNS Computer Name: AA01CS1.SG5.TKN
Attribute: End of list
Target Info Item Type: End of list (0x0000)
Target Info Item Length: 0
No. Time Source Destination Protocol Length Info
67 4.709714000 172.16.0.83 172.16.0.41 DCERPC 258 AUTH3: call_id: 0 Fragment: Single, NTLMSSP_AUTH, User: SG5.TKN\Administrator
Frame 67: 258 bytes on wire (2064 bits), 258 bytes captured (2064 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.380205000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.380205000 seconds
[Time delta from previous captured frame: 0.006801000 seconds]
[Time delta from previous displayed frame: 0.006801000 seconds]
[Time since reference or first frame: 4.709714000 seconds]
Frame Number: 67
Frame Length: 258 bytes (2064 bits)
Capture Length: 258 bytes (2064 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 244
Identification: 0xcacc (51916)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd69a [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 132, Ack: 207, Len: 204
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 132 (relative sequence number)
[Next sequence number: 336 (relative sequence number)]
Acknowledgment number: 207 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65329
[Calculated window size: 65329]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x89ff [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 66]
[The RTT to ACK the segment was: 0.006801000 seconds]
NTLM Secure Service Provider
NTLMSSP identifier: NTLMSSP
NTLM Message Type: NTLMSSP_AUTH (0x00000003)
Lan Manager Response: dadb9f77eb4f119500000000000000000000000000000000
Length: 24
Maxlen: 24
Offset: 64
NTLM Client Challenge: dadb9f77eb4f1195
NTLM Response: 4571fa79a8a3257d4e631267dc63b3907fe9552e493114f4
Length: 24
Maxlen: 24
Offset: 88
Domain name: SG5.TKN
Length: 14
Maxlen: 14
Offset: 112
User name: Administrator
Length: 26
Maxlen: 26
Offset: 126
No. Time Source Destination Protocol Length Info
69 4.848411000 172.16.0.41 172.16.0.83 TCP 60 omnisky > nicetec-nmsvc [ACK] Seq=207 Ack=336 Win=63905 Len=0
Frame 69: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.518902000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.518902000 seconds
[Time delta from previous captured frame: 0.001092000 seconds]
[Time delta from previous displayed frame: 0.138697000 seconds]
[Time since reference or first frame: 4.848411000 seconds]
Frame Number: 69
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Padding: 020405b40101
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0x9ab8 (39608)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x077b [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 207, Ack: 336, Len: 0
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 207 (relative sequence number)
Acknowledgment number: 336 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63905
[Calculated window size: 63905]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x3004 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 67]
[The RTT to ACK the segment was: 0.138697000 seconds]
No. Time Source Destination Protocol Length Info
70 4.848485000 172.16.0.83 172.16.0.41 IRemUnknown2 174 RemAddRef request
Frame 70: 174 bytes on wire (1392 bits), 174 bytes captured (1392 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.518976000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.518976000 seconds
[Time delta from previous captured frame: 0.000074000 seconds]
[Time delta from previous displayed frame: 0.000074000 seconds]
[Time since reference or first frame: 4.848485000 seconds]
Frame Number: 70
Frame Length: 174 bytes (1392 bits)
Capture Length: 174 bytes (1392 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 160
Identification: 0xcacd (51917)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd6ed [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 336, Ack: 207, Len: 120
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 336 (relative sequence number)
[Next sequence number: 456 (relative sequence number)]
Acknowledgment number: 207 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65329
[Calculated window size: 65329]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x8cf3 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[Bytes in flight: 120]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Request, Fragment: Single, FragLen: 120, Call: 1 Ctx: 0, [Resp: #71]
Version: 5
Version (minor): 0
Packet type: Request (0)
Packet Flags: 0x83
1... .... = Object: Set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 120
Auth Length: 0
Call ID: 1
Alloc hint: 80
Context ID: 0
Opnum: 4
Object UUID: 0000ac03-04e4-05a8-b902-67d5d342cb6c
[Response in frame: 71]
IRemUnknown2, RemAddRef
Operation: RemAddRef (4)
[Response in frame: 71]
Stub data (80 bytes)
No. Time Source Destination Protocol Length Info
71 4.850448000 172.16.0.41 172.16.0.83 IRemUnknown2 134 RemAddRef response
Frame 71: 134 bytes on wire (1072 bits), 134 bytes captured (1072 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.520939000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.520939000 seconds
[Time delta from previous captured frame: 0.001963000 seconds]
[Time delta from previous displayed frame: 0.001963000 seconds]
[Time since reference or first frame: 4.850448000 seconds]
Frame Number: 71
Frame Length: 134 bytes (1072 bits)
Capture Length: 134 bytes (1072 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 120
Identification: 0x9ab9 (39609)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x072a [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 207, Ack: 456, Len: 80
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 207 (relative sequence number)
[Next sequence number: 287 (relative sequence number)]
Acknowledgment number: 456 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63785
[Calculated window size: 63785]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0xaaee [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 70]
[The RTT to ACK the segment was: 0.001963000 seconds]
[Bytes in flight: 80]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Response, Fragment: Single, FragLen: 80, Call: 1 Ctx: 0, [Req: #70]
Version: 5
Version (minor): 0
Packet type: Response (2)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 80
Auth Length: 16
Call ID: 1
Alloc hint: 20
Context ID: 0
Cancel count: 0
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 12
Auth Rsrvd: 0
Auth Context ID: 2
Opnum: 4
[Object UUID: 0000ac03-04e4-05a8-b902-67d5d342cb6c]
[Request in frame: 70]
[Time from request: 0.001963000 seconds]
NTLMSSP Verifier
Version Number: 1
Verifier Body: 000000000000000000000000
IRemUnknown2, RemAddRef
Operation: RemAddRef (4)
[Request in frame: 70]
Stub data (20 bytes)
Auth Padding (12 bytes)
No. Time Source Destination Protocol Length Info
72 4.881006000 172.16.0.83 172.16.0.41 IRemUnknown2 174 RemRelease request Cnt=1 Refs=10-0[Long frame (16 bytes)]
Frame 72: 174 bytes on wire (1392 bits), 174 bytes captured (1392 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.551497000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.551497000 seconds
[Time delta from previous captured frame: 0.030558000 seconds]
[Time delta from previous displayed frame: 0.030558000 seconds]
[Time since reference or first frame: 4.881006000 seconds]
Frame Number: 72
Frame Length: 174 bytes (1392 bits)
Capture Length: 174 bytes (1392 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 160
Identification: 0xcace (51918)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd6ec [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 456, Ack: 287, Len: 120
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 456 (relative sequence number)
[Next sequence number: 576 (relative sequence number)]
Acknowledgment number: 287 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65249
[Calculated window size: 65249]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x8597 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 71]
[The RTT to ACK the segment was: 0.030558000 seconds]
[Bytes in flight: 120]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Request, Fragment: Single, FragLen: 120, Call: 2 Ctx: 0, [Resp: #73]
Version: 5
Version (minor): 0
Packet type: Request (0)
Packet Flags: 0x83
1... .... = Object: Set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 120
Auth Length: 0
Call ID: 2
Alloc hint: 80
Context ID: 0
Opnum: 5
Object UUID: 0000ac03-04e4-05a8-b902-67d5d342cb6c
[Response in frame: 73]
IRemUnknown2, RemRelease
Operation: RemRelease (5)
[Response in frame: 73]
DCOM, ORPCThis, V5.2, Causality ID: 0a3c0500-ccc4-9013-887d-9f165c087753
VersionMajor: 5
VersionMinor: 2
Flags: INFO_NULL (0x00000000)
Reserved: 0x00000000
Causality ID: 0a3c0500-ccc4-9013-887d-9f165c087753
[Object UUID/IPID: 0000ac03-04e4-05a8-b902-67d5d342cb6c]
InterfaceRefs: 1
RemInterfaceRef[1]: IPID=00019422-04e4-05a8-a9c8-b5a439c204f8, PublicRefs=10, PrivateRefs=0
IPID: 00019422-04e4-05a8-a9c8-b5a439c204f8
PublicRefs: 10
PrivateRefs: 0
[Long frame (16 bytes)]
No. Time Source Destination Protocol Length Info
73 4.881746000 172.16.0.41 172.16.0.83 IRemUnknown2 118 RemRelease response -> S_OK
Frame 73: 118 bytes on wire (944 bits), 118 bytes captured (944 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.552237000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.552237000 seconds
[Time delta from previous captured frame: 0.000740000 seconds]
[Time delta from previous displayed frame: 0.000740000 seconds]
[Time since reference or first frame: 4.881746000 seconds]
Frame Number: 73
Frame Length: 118 bytes (944 bits)
Capture Length: 118 bytes (944 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp:dcerpc]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 104
Identification: 0x9abc (39612)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x0737 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 287, Ack: 576, Len: 64
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 287 (relative sequence number)
[Next sequence number: 351 (relative sequence number)]
Acknowledgment number: 576 (relative ack number)
Header length: 20 bytes
Flags: 0x018 (PSH, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 1... = Push: Set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63665
[Calculated window size: 63665]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x9ce6 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 72]
[The RTT to ACK the segment was: 0.000740000 seconds]
[Bytes in flight: 64]
Distributed Computing Environment / Remote Procedure Call (DCE/RPC) Response, Fragment: Single, FragLen: 64, Call: 2 Ctx: 0, [Req: #72]
Version: 5
Version (minor): 0
Packet type: Response (2)
Packet Flags: 0x03
0... .... = Object: Not set
.0.. .... = Maybe: Not set
..0. .... = Did Not Execute: Not set
...0 .... = Multiplex: Not set
.... 0... = Reserved: Not set
.... .0.. = Cancel Pending: Not set
.... ..1. = Last Frag: Set
.... ...1 = First Frag: Set
Data Representation: 10000000
Byte order: Little-endian (1)
Character: ASCII (0)
Floating-point: IEEE (0)
Frag Length: 64
Auth Length: 16
Call ID: 2
Alloc hint: 12
Context ID: 0
Cancel count: 0
Auth type: NTLMSSP (10)
Auth level: Connect (2)
Auth pad len: 4
Auth Rsrvd: 0
Auth Context ID: 2
Opnum: 5
[Object UUID: 0000ac03-04e4-05a8-b902-67d5d342cb6c]
[Request in frame: 72]
[Time from request: 0.000740000 seconds]
NTLMSSP Verifier
Version Number: 1
Verifier Body: 000000000000000000000000
IRemUnknown2, RemRelease
Operation: RemRelease (5)
[Request in frame: 72]
DCOM, ORPCThat
Flags: INFO_NULL (0x00000000)
[Object UUID/IPID: 0000ac03-04e4-05a8-b902-67d5d342cb6c]
HResult: S_OK (0x00000000)
Auth Padding (4 bytes)
No. Time Source Destination Protocol Length Info
74 4.886561000 172.16.0.83 172.16.0.41 TCP 54 nicetec-nmsvc > omnisky [FIN, ACK] Seq=576 Ack=351 Win=65185 Len=0
Frame 74: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.557052000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.557052000 seconds
[Time delta from previous captured frame: 0.004815000 seconds]
[Time delta from previous displayed frame: 0.004815000 seconds]
[Time since reference or first frame: 4.886561000 seconds]
Frame Number: 74
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcacf (51919)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd763 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 576, Ack: 351, Len: 0
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 576 (relative sequence number)
Acknowledgment number: 351 (relative ack number)
Header length: 20 bytes
Flags: 0x011 (FIN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 65185
[Calculated window size: 65185]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x2983 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 73]
[The RTT to ACK the segment was: 0.004815000 seconds]
No. Time Source Destination Protocol Length Info
75 4.886681000 172.16.0.41 172.16.0.83 TCP 60 omnisky > nicetec-nmsvc [ACK] Seq=351 Ack=577 Win=63665 Len=0
Frame 75: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.557172000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.557172000 seconds
[Time delta from previous captured frame: 0.000120000 seconds]
[Time delta from previous displayed frame: 0.000120000 seconds]
[Time since reference or first frame: 4.886681000 seconds]
Frame Number: 75
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Padding: 020405b40101
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0x9abd (39613)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x0776 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 351, Ack: 577, Len: 0
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 351 (relative sequence number)
Acknowledgment number: 577 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 63665
[Calculated window size: 63665]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x2f73 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 74]
[The RTT to ACK the segment was: 0.000120000 seconds]
No. Time Source Destination Protocol Length Info
76 4.886713000 172.16.0.41 172.16.0.83 TCP 60 omnisky > nicetec-nmsvc [FIN, ACK] Seq=351 Ack=577 Win=63665 Len=0
Frame 76: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.557204000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.557204000 seconds
[Time delta from previous captured frame: 0.000032000 seconds]
[Time delta from previous displayed frame: 0.000032000 seconds]
[Time since reference or first frame: 4.886713000 seconds]
Frame Number: 76
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee), Dst: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Destination: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Padding: 020405b40101
Internet Protocol Version 4, Src: 172.16.0.41 (172.16.0.41), Dst: 172.16.0.83 (172.16.0.83)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0x9abe (39614)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0x0775 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.41 (172.16.0.41)
Destination: 172.16.0.83 (172.16.0.83)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: omnisky (2056), Dst Port: nicetec-nmsvc (2556), Seq: 351, Ack: 577, Len: 0
Source port: omnisky (2056)
Destination port: nicetec-nmsvc (2556)
[Stream index: 1]
Sequence number: 351 (relative sequence number)
Acknowledgment number: 577 (relative ack number)
Header length: 20 bytes
Flags: 0x011 (FIN, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...1 = Fin: Set
[Expert Info (Chat/Sequence): Connection finish (FIN)]
[Message: Connection finish (FIN)]
[Severity level: Chat]
[Group: Sequence]
Window size value: 63665
[Calculated window size: 63665]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x2f72 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
No. Time Source Destination Protocol Length Info
77 4.886725000 172.16.0.83 172.16.0.41 TCP 54 nicetec-nmsvc > omnisky [ACK] Seq=577 Ack=352 Win=65185 Len=0
Frame 77: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface 0
Interface id: 0
WTAP_ENCAP: 1
Arrival Time: Jul 2, 2013 13:31:05.557216000 Westeuropäische Sommerzeit
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1372764665.557216000 seconds
[Time delta from previous captured frame: 0.000012000 seconds]
[Time delta from previous displayed frame: 0.000012000 seconds]
[Time since reference or first frame: 4.886725000 seconds]
Frame Number: 77
Frame Length: 54 bytes (432 bits)
Capture Length: 54 bytes (432 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:tcp]
Ethernet II, Src: Asiarock_34:82:68 (00:0b:6a:34:82:68), Dst: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Destination: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
Address: Hewlett-_3c:e8:ee (00:0b:cd:3c:e8:ee)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Asiarock_34:82:68 (00:0b:6a:34:82:68)
Address: Asiarock_34:82:68 (00:0b:6a:34:82:68)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: 172.16.0.83 (172.16.0.83), Dst: 172.16.0.41 (172.16.0.41)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 40
Identification: 0xcad0 (51920)
Flags: 0x02 (Don't Fragment)
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 128
Protocol: TCP (6)
Header checksum: 0xd762 [correct]
[Good: True]
[Bad: False]
Source: 172.16.0.83 (172.16.0.83)
Destination: 172.16.0.41 (172.16.0.41)
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: nicetec-nmsvc (2556), Dst Port: omnisky (2056), Seq: 577, Ack: 352, Len: 0
Source port: nicetec-nmsvc (2556)
Destination port: omnisky (2056)
[Stream index: 1]
Sequence number: 577 (relative sequence number)
Acknowledgment number: 352 (relative ack number)
Header length: 20 bytes
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
Window size value: 65185
[Calculated window size: 65185]
[Window size scaling factor: -2 (no window scaling used)]
Checksum: 0x2982 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 76]
[The RTT to ACK the segment was: 0.000012000 seconds]
******************************************
Date: Fri, 21 Jun 2013 18:24:50 +0200