D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Re: tcpdump




The list benefits from the full discussion, (hence this is CC'd to the
list), it's better to keep the full thread together for everyone to
benefit and contribute.

cc'd back onto the list. (We like to see things as they develop rather than
as a fait accompli)


For the benifit of the list:-

My server sees the incomming ftp request and logs a "FTP session opened",  
Tony sees a login and/or welcome message and when he types in a username all 
goes dead

the tcpdump -vv of the transaction from the server end is as follows :-

Not being a ftp expert I decode as follows

I see the three packet TCP handshake in the first 3 packets (2 from client 1 
from server) (client port 32822) (server port ftp)
I see a UDP handshake with my name server as i look up the client
I probe the auth port twice but see no response
I then try to send data back to the client port 32822 for which i never see a 
reply. My transmissions are repeated quite a few times then it stops/timesout 
etc

If anybody really wants they can have the entire tcpdump but i feel it is 
unnecessary.


Yes so we have a basic handshake, if you do it again i have full protocol
decoding on tcpdump ready to see what is sent where, may be you can do
the same add the -vv option and we can compare notes afterwards

This time I got the 220 welcome message followed by
Name (cornelius ... ):

so I typed 'anonymous' and it all went quiet and I killed it.

weird, ok i am going to post the tcpdump results back to the list as neil W 
suggests, to keep everone informed


Robin Cornelius
---------------------------------------------------
robin@xxxxxxxxxxxxxxxxxxxxx
GPG Key ID: 0x729A79A23B7EE764
http://www.biglumber.com/x/web?qs=0x729A79A23B7EE764

Attachment: pgp00043.pgp
Description: signature


Lynx friendly