No. Time Source Destination Protocol Info 1 0.000000 192.168.1.28 192.168.1.2 DNS Standard query A weather.noaa.gov



Similar documents
DNS Conformance Test Specification For Client

netkit lab dns Università degli Studi Roma Tre Dipartimento di Informatica e Automazione Computer Networks Research Group Version Author(s)

Domain Name System :49:44 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

The Domain Name System

Local DNS Attack Lab. 1 Lab Overview. 2 Lab Environment. SEED Labs Local DNS Attack Lab 1

Domain Name System (DNS) Fundamentals

Ethereal Lab: DNS PART 1. 1.Run nslookup to obtain the IP address of a Web server in Asia. I performed nslookup for

Motivation. Domain Name System (DNS) Flat Namespace. Hierarchical Namespace

DNS (Domain Name System) is the system & protocol that translates domain names to IP addresses.

Remote DNS Cache Poisoning Attack Lab

Copyright

How do I get to

1 DNS Packet Structure

Teldat Router. DNS Client

Domain Name System (DNS) Session-1: Fundamentals. Ayitey Bulley

How-to: DNS Enumeration

THE DOMAIN NAME SYSTEM DNS

Agenda. Network Services. Domain Names. Domain Name. Domain Names Domain Name System Internationalized Domain Names. Domain Names & DNS

The internetworking solution of the Internet. Single networks. The Internet approach to internetworking. Protocol stacks in the Internet

CSE 127: Computer Security. Network Security. Kirill Levchenko

The Domain Name System

How To Manage Dns On An Elfiq Link Load Balancer (Link Balancer) On A Pcode (Networking) On Ipad Or Ipad (Netware) On Your Ipad On A Ipad At A Pc Or Ipa

DNS: Domain Name System

Mobile IP Network Layer Lesson 02 TCP/IP Suite and IP Protocol

DNS. Some advanced topics. Karst Koymans. (with Niels Sijm) Informatics Institute University of Amsterdam. (version 2.6, 2013/09/19 10:55:30)

HTG XROADS NETWORKS. Network Appliance How To Guide: DNS Delegation. How To Guide

DNS : Domain Name System

Introduction to Analyzer and the ARP protocol

DNS Pharming Attack Lab

How to Add Domains and DNS Records

Understanding DNS (the Domain Name System)

HOST AUTO CONFIGURATION (BOOTP, DHCP)

Technical Support Information Belkin internal use only

Chapter 4 Network Layer

Application and service delivery with the Elfiq idns module

DNS at NLnet Labs. Matthijs Mekking

DNS + DHCP. Michael Tsai 2015/04/27

- Domain Name System -

Lecture 2 CS An example of a middleware service: DNS Domain Name System

Work No. 1 Samba. What is Samba?

Tunnel Client FAQ. Table of Contents. Version 0v5, November 2014 Revised: Kate Lance Author: Karl Auer

IP addressing and forwarding Network layer

Guide to TCP/IP, Third Edition. Chapter 3: Data Link and Network Layer TCP/IP Protocols

DNS. Computer networks - Administration 1DV202. fredag 30 mars 12

Network Layer IPv4. Dr. Sanjay P. Ahuja, Ph.D. Fidelity National Financial Distinguished Professor of CIS. School of Computing, UNF

Motivation. Users can t remember IP addresses. Implemented by library functions & servers. - Need to map symbolic names (

Network Layers. CSC358 - Introduction to Computer Networks

DNS ActiveX Control for Microsoft Windows. Copyright Magneto Software All rights reserved

Use Domain Name System and IP Version 6

Network layer" 1DT066! Distributed Information Systems!! Chapter 4" Network Layer!! goals: "

Network layer: Overview. Network layer functions IP Routing and forwarding

ECE 4321 Computer Networks. Network Programming

Configuring DNS. Finding Feature Information

2 HDE Controller X DNS Server Manual

Introduction to DNS CHAPTER 5. In This Chapter

IPv6 Support in the DNS. Workshop Name Workshop Location, Date

IPv6 Support in the DNS. Workshop Name Workshop Location, Date

Lecture 2-ter. 2. A communication example Managing a HTTP v1.0 connection. G.Bianchi, G.Neglia, V.Mancuso

API of DNS hosting. For DNS-master and Secondary services Table of contents

Table of Contents DNS. How to package DNS messages. Wire? DNS on the wire. Some advanced topics. Encoding of domain names.

Tanenbaum, Computer Networks (extraits) Adaptation par J.Bétréma. DNS The Domain Name System

DNS Resolving using nslookup

Successful DB2 NETLOGON in LAB (Sniffer on LAB HUB)

BELNET: Service Level Description Version (29/7/2009)

Objectives of Lecture. Network Architecture. Protocols. Contents

Introduction to Network Operating Systems

DHCP, ICMP, IPv6. Computer Networking: A Top Down Approach 6 th edition Jim Kurose, Keith Ross Addison-Wesley DHCP. DHCP UDP IP Eth Phy

IPv6 Trace Analysis using Wireshark Nalini Elkins, CEO Inside Products, Inc.

State of the "DNS privacy" project. Stéphane Bortzmeyer AFNIC

Computer Networks: Domain Name System

DNS based Load Balancing with Fault Tolerance

Distributed Network Traffic Monitoring and Analysis using Load Balancing Technology

Application. Transport. Network. Data Link. Physical. Network Layers. Goal

DNSSEC Applying cryptography to the Domain Name System

CS 457 Lecture 19 Global Internet - BGP. Fall 2011

DNS Amplification Attacks. Preliminary release Randal Vaughn and Gadi Evron March 17, 2006

NAST. Documentation. Copyright 2013 DENIC eg. Doc. version: 1.9 Doc. status: Final

The Use of DNS Resource Records

Red Hat system-config-bind BIND (Berkeley Internet Name Domain) DNS ( Domain Name System)

The Domain Name System from a security point of view

Subnetting,Supernetting, VLSM & CIDR

WIZnet S2E (Serial-to-Ethernet) Device s Configuration Tool Programming Guide

Domain Name Servers. Domain Types WWW host names. Internet Names. COMP476 Networked Computer Systems. Domain Name Servers

Dynamic DNS Support for Cisco IOS Software

The Domain Name System

Application Protocols in the TCP/IP Reference Model

Chapter 25 Domain Name System Copyright The McGraw-Hill Companies, Inc. Permission required for reproduction or display.

IPv6 for AT&T Broadband

Computer Networks 1 (Mạng Máy Tính 1) Lectured by: Dr. Phạm Trần Vũ MEng. Nguyễn CaoĐạt

GB ethernet UDP interface in FPGA

Domain Name System (DNS)

Coordinación. The background image of the cover is desgned by GUIDE TO DNS SECURITY 2

CX-Supervisor CX-MODBUS TCP

Managing DNS Server Properties

Computer Networking LAB 2 HTTP

First Hop Redundancy (Layer 3) 1. Network Design First Hop. Agenda. First Hop Redundancy (Layer 3) 2. L102 - First Hop Redundancy

Transcription:

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 1 1 0.000000 192.168.1.28 192.168.1.2 DNS Standard query A weather.noaa.gov Frame 1 (76 bytes on wire, 76 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.377214000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 76 bytes Capture Length: 76 bytes Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8 Destination: 00:40:f4:b7:ec:d8 (192.168.1.2) Source: 00:18:f3:a8:0a:8a (192.168.1.28) Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16 8.1.2) Total Length: 62 Identification: 0x598f (22927) Header checksum: 0x5db1 (correct) Source: 192.168.1.28 (192.168.1.28) Destination: 192.168.1.2 (192.168.1.2) User Datagram Protocol, Src Port: 32776 (32776), Dst Port: domain (53) Source port: 32776 (32776) Destination port: domain (53) Length: 42 Checksum: 0x1e76 (correct) Domain Name System (query) Transaction ID: 0xe37e Flags: 0x0100 (Standard query) 0............ = Response: Message is a query.........0... = Non-authenticated data OK: Non-authenticated data is unacceptable Authority RRs: 0 weather.noaa.gov: type A, class IN Type: A (Host address) 0000 00 40 f4 b7 ec d8 00 18 f3 a8 0a 8a 08 00 45 00.@...E. 0010 00 3e 59 8f 40 00 40 11 5d b1 c0 a8 01 1c c0 a8.>y.@.@.]... 0020 01 02 80 08 00 35 00 2a 1e 76 e3 7e 01 00 00 01...5.*.v.~... 0030 00 00 00 00 00 00 07 77 65 61 74 68 65 72 04 6e...weather.n 0040 6f 61 61 03 67 6f 76 00 00 01 00 01 oaa.gov...

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 2 2 0.000426 192.168.1.28 192.168.1.2 DNS Standard query AAAA weather.noaa.gov Frame 2 (76 bytes on wire, 76 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.377640000 Time delta from previous packet: 0.000426000 seconds Time since reference or first frame: 0.000426000 seconds Frame Number: 2 Packet Length: 76 bytes Capture Length: 76 bytes Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8 Destination: 00:40:f4:b7:ec:d8 (192.168.1.2) Source: 00:18:f3:a8:0a:8a (192.168.1.28) Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16 8.1.2) Total Length: 62 Identification: 0x598f (22927) Header checksum: 0x5db1 (correct) Source: 192.168.1.28 (192.168.1.28) Destination: 192.168.1.2 (192.168.1.2) User Datagram Protocol, Src Port: 32777 (32777), Dst Port: domain (53) Source port: 32777 (32777) Destination port: domain (53) Length: 42 Checksum: 0x62bf (correct) Domain Name System (query) Transaction ID: 0x9f19 Flags: 0x0100 (Standard query) 0............ = Response: Message is a query.........0... = Non-authenticated data OK: Non-authenticated data is unacceptable Authority RRs: 0 weather.noaa.gov: type AAAA, class IN Type: AAAA (IPv6 address) 0000 00 40 f4 b7 ec d8 00 18 f3 a8 0a 8a 08 00 45 00.@...E. 0010 00 3e 59 8f 40 00 40 11 5d b1 c0 a8 01 1c c0 a8.>y.@.@.]... 0020 01 02 80 09 00 35 00 2a 62 bf 9f 19 01 00 00 01...5.*b... 0030 00 00 00 00 00 00 07 77 65 61 74 68 65 72 04 6e...weather.n 0040 6f 61 61 03 67 6f 76 00 00 1c 00 01 oaa.gov...

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 3 5 0.001109 192.168.1.2 192.168.1.28 DNS Standard query response A 205.156.51.200 Frame 5 (149 bytes on wire, 149 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.378323000 Time delta from previous packet: 0.000087000 seconds Time since reference or first frame: 0.001109000 seconds Frame Number: 5 Packet Length: 149 bytes Capture Length: 149 bytes Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a Destination: 00:18:f3:a8:0a:8a (192.168.1.28) Source: 00:40:f4:b7:ec:d8 (192.168.1.2) Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168.1.28) Total Length: 135 Identification: 0x2a2a (10794) Header checksum: 0x8ccd (correct) Source: 192.168.1.2 (192.168.1.2) Destination: 192.168.1.28 (192.168.1.28) User Datagram Protocol, Src Port: domain (53), Dst Port: 32776 (32776) Source port: domain (53) Destination port: 32776 (32776) Length: 115 Checksum: 0x2d31 (correct) Domain Name System (response) Transaction ID: 0xe37e Flags: 0x8180 (Standard query response, No error) 1............ = Response: Message is a response....0........ = Authoritative: Server is not an authority for domain...... 1...... = Recursion available: Server can do recursive queries........0.... = Answer authenticated: Answer/authority portion was not authentica ted by the server......... 0000 = Reply code: No error (0) Answer RRs: 1 Authority RRs: 3 weather.noaa.gov: type A, class IN Type: A (Host address) Answers weather.noaa.gov: type A, class IN, addr 205.156.51.200 Type: A (Host address) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 4 Addr: 205.156.51.200 Authoritative nameservers noaa.gov: type NS, class IN, ns NS.noaa.gov Name: noaa.gov Type: NS (Authoritative name server)

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 4 Time to live: 7 hours, 50 minutes, 4 seconds Data length: 5 Name server: NS.noaa.gov noaa.gov: type NS, class IN, ns MWRNS.noaa.gov Name: noaa.gov Type: NS (Authoritative name server) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 8 Name server: MWRNS.noaa.gov noaa.gov: type NS, class IN, ns NWRNS.noaa.gov Name: noaa.gov Type: NS (Authoritative name server) Time to live: 7 hours, 50 minutes, 4 seconds Data length: 8 Name server: NWRNS.noaa.gov 0000 00 18 f3 a8 0a 8a 00 40 f4 b7 ec d8 08 00 45 00...@...E. 0010 00 87 2a 2a 40 00 40 11 8c cd c0 a8 01 02 c0 a8..**@.@... 0020 01 1c 00 35 80 08 00 73 2d 31 e3 7e 81 80 00 01...5...s-1.~... 0030 00 01 00 03 00 00 07 77 65 61 74 68 65 72 04 6e...weather.n 0040 6f 61 61 03 67 6f 76 00 00 01 00 01 c0 0c 00 01 oaa.gov... 0050 00 01 00 00 6e 2c 00 04 cd 9c 33 c8 c0 14 00 02...n,...3... 0060 00 01 00 00 6e 2c 00 05 02 4e 53 c0 14 c0 14 00...n,...NS... 0070 02 00 01 00 00 6e 2c 00 08 05 4d 57 52 4e 53 c0...n,...mwrns. 0080 14 c0 14 00 02 00 01 00 00 6e 2c 00 08 05 4e 57...n,...NW 0090 52 4e 53 c0 14 RNS..

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 5 6 0.001348 192.168.1.2 192.168.1.28 DNS Standard query response Frame 6 (124 bytes on wire, 124 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.378562000 Time delta from previous packet: 0.000239000 seconds Time since reference or first frame: 0.001348000 seconds Frame Number: 6 Packet Length: 124 bytes Capture Length: 124 bytes Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a Destination: 00:18:f3:a8:0a:8a (192.168.1.28) Source: 00:40:f4:b7:ec:d8 (192.168.1.2) Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168.1.28) Total Length: 110 Identification: 0x2a2b (10795) Header checksum: 0x8ce5 (correct) Source: 192.168.1.2 (192.168.1.2) Destination: 192.168.1.28 (192.168.1.28) User Datagram Protocol, Src Port: domain (53), Dst Port: 32777 (32777) Source port: domain (53) Destination port: 32777 (32777) Length: 90 Checksum: 0xe754 (correct) Domain Name System (response) Transaction ID: 0x9f19 Flags: 0x8180 (Standard query response, No error) 1............ = Response: Message is a response....0........ = Authoritative: Server is not an authority for domain...... 1...... = Recursion available: Server can do recursive queries........0.... = Answer authenticated: Answer/authority portion was not authentica ted by the server......... 0000 = Reply code: No error (0) Authority RRs: 1 weather.noaa.gov: type AAAA, class IN Type: AAAA (IPv6 address) Authoritative nameservers noaa.gov: type SOA, class IN, mname NS.noaa.gov Name: noaa.gov Type: SOA (Start of zone of authority) Time to live: 2 hours, 20 minutes Data length: 36 Primary name server: NS.noaa.gov Responsible authority s mailbox: NOC@NOAA.gov Serial number: 2007011901 Refresh interval: 3 hours Retry interval: 1 hour

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 6 Expiration limit: 7 days Minimum TTL: 1 day 0000 00 18 f3 a8 0a 8a 00 40 f4 b7 ec d8 08 00 45 00...@...E. 0010 00 6e 2a 2b 40 00 40 11 8c e5 c0 a8 01 02 c0 a8.n*+@.@... 0020 01 1c 00 35 80 09 00 5a e7 54 9f 19 81 80 00 01...5...Z.T... 0030 00 00 00 01 00 00 07 77 65 61 74 68 65 72 04 6e...weather.n 0040 6f 61 61 03 67 6f 76 00 00 1c 00 01 c0 14 00 06 oaa.gov... 0050 00 01 00 00 20 d0 00 24 02 4e 53 c0 14 08 4e 4f.....$.NS...NO 0060 43 40 4e 4f 41 41 c0 19 77 a0 92 3d 00 00 2a 30 C@NOAA..w..=..*0 0070 00 00 0e 10 00 09 3a 80 00 01 51 80...:...Q.

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 7 7 0.001382 192.168.1.28 192.168.1.2 DNS Standard query AAAA weather.noaa.gov.zuhause.xx Frame 7 (87 bytes on wire, 87 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.378596000 Time delta from previous packet: 0.000034000 seconds Time since reference or first frame: 0.001382000 seconds Frame Number: 7 Packet Length: 87 bytes Capture Length: 87 bytes Ethernet II, Src: 00:18:f3:a8:0a:8a, Dst: 00:40:f4:b7:ec:d8 Destination: 00:40:f4:b7:ec:d8 (192.168.1.2) Source: 00:18:f3:a8:0a:8a (192.168.1.28) Internet Protocol, Src Addr: 192.168.1.28 (192.168.1.28), Dst Addr: 192.168.1.2 (192.16 8.1.2) Total Length: 73 Identification: 0x5990 (22928) Header checksum: 0x5da5 (correct) Source: 192.168.1.28 (192.168.1.28) Destination: 192.168.1.2 (192.168.1.2) User Datagram Protocol, Src Port: 32777 (32777), Dst Port: domain (53) Source port: 32777 (32777) Destination port: domain (53) Length: 53 Checksum: 0x6869 (correct) Domain Name System (query) Transaction ID: 0x46aa Flags: 0x0100 (Standard query) 0............ = Response: Message is a query.........0... = Non-authenticated data OK: Non-authenticated data is unacceptable Authority RRs: 0 weather.noaa.gov.zuhause.xx: type AAAA, class IN.zuhause.xx Type: AAAA (IPv6 address) 0000 00 40 f4 b7 ec d8 00 18 f3 a8 0a 8a 08 00 45 00.@...E. 0010 00 49 59 90 40 00 40 11 5d a5 c0 a8 01 1c c0 a8.iy.@.@.]... 0020 01 02 80 09 00 35 00 35 68 69 46 aa 01 00 00 01...5.5hiF... 0030 00 00 00 00 00 00 07 77 65 61 74 68 65 72 04 6e...weather.n 0040 6f 61 61 03 67 6f 76 07 7a 75 68 61 75 73 65 02 oaa.gov.zuhause. 0050 78 78 00 00 1c 00 01 xx...

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 8 8 0.001836 192.168.1.2 192.168.1.28 DNS Standard query response, No such name Frame 8 (135 bytes on wire, 135 bytes captured) Arrival Time: Jan 21, 2007 12:24:02.379050000 Time delta from previous packet: 0.000454000 seconds Time since reference or first frame: 0.001836000 seconds Frame Number: 8 Packet Length: 135 bytes Capture Length: 135 bytes Ethernet II, Src: 00:40:f4:b7:ec:d8, Dst: 00:18:f3:a8:0a:8a Destination: 00:18:f3:a8:0a:8a (192.168.1.28) Source: 00:40:f4:b7:ec:d8 (192.168.1.2) Internet Protocol, Src Addr: 192.168.1.2 (192.168.1.2), Dst Addr: 192.168.1.28 (192.168.1.28) Total Length: 121 Identification: 0x2a2c (10796) Header checksum: 0x8cd9 (correct) Source: 192.168.1.2 (192.168.1.2) Destination: 192.168.1.28 (192.168.1.28) User Datagram Protocol, Src Port: domain (53), Dst Port: 32777 (32777) Source port: domain (53) Destination port: 32777 (32777) Length: 101 Checksum: 0xaddf (correct) Domain Name System (response) Transaction ID: 0x46aa Flags: 0x8583 (Standard query response, No such name) 1............ = Response: Message is a response....1........ = Authoritative: Server is an authority for domain...... 1...... = Recursion available: Server can do recursive queries........0.... = Answer authenticated: Answer/authority portion was not authentica ted by the server......... 0011 = Reply code: No such name (3) Authority RRs: 1 weather.noaa.gov.zuhause.xx: type AAAA, class IN.zuhause.xx Type: AAAA (IPv6 address) Authoritative nameservers zuhause.xx: type SOA, class IN, mname server.zuhause.xx Name: zuhause.xx Type: SOA (Start of zone of authority) Time to live: 2 hours Data length: 36 Primary name server: server.zuhause.xx Responsible authority s mailbox: root.zuhause.xx Serial number: 505074262 Refresh interval: 3 hours Retry interval: 1 hour

/tmp/dump/dump02_arp_dns-weather_syn_fin complete-session - Ethereal Page 9 Expiration limit: 7 days Minimum TTL: 1 day 0000 00 18 f3 a8 0a 8a 00 40 f4 b7 ec d8 08 00 45 00...@...E. 0010 00 79 2a 2c 40 00 40 11 8c d9 c0 a8 01 02 c0 a8.y*,@.@... 0020 01 1c 00 35 80 09 00 65 ad df 46 aa 85 83 00 01...5...e..F... 0030 00 00 00 01 00 00 07 77 65 61 74 68 65 72 04 6e...weather.n 0040 6f 61 61 03 67 6f 76 07 7a 75 68 61 75 73 65 02 oaa.gov.zuhause. 0050 78 78 00 00 1c 00 01 c0 1d 00 06 00 01 00 00 1c xx... 0060 20 00 24 06 73 65 72 76 65 72 c0 1d 04 72 6f 6f.$.server...roo 0070 74 c0 1d 1e 1a d2 56 00 00 2a 30 00 00 0e 10 00 t...v..*0... 0080 09 3a 80 00 01 51 80.:...Q.