CS Personal
// cloudshark.org
Guest upload is turned off
Log In
Protocol Decode of
frame 145
from
ymsg01.pcapng
Follow HTTP
Follow TCP
Download as .txt
Frame 145: 1514 bytes on wire (12112 bits), 1514 bytes captured (12112 bits) on interface \Device\NPF_{580D61DC-5016-4CDF-A7BE-4DDED8B991D2}, id 0
Interface id: 0 (\Device\NPF_{580D61DC-5016-4CDF-A7BE-4DDED8B991D2})
Interface name: \Device\NPF_{580D61DC-5016-4CDF-A7BE-4DDED8B991D2}
Encapsulation type: Ethernet (1)
Arrival Time: Nov 24, 2013 02:22:04.615485000 UTC
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1385259724.615485000 seconds
[Time delta from previous captured frame: 0.001749000 seconds]
[Time delta from previous displayed frame: 0.001749000 seconds]
[Time since reference or first frame: 15.565932000 seconds]
Frame Number: 145
Frame Length: 1514 bytes (12112 bits)
Capture Length: 1514 bytes (12112 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ethertype:ip:tcp:http:data]
Ethernet II, Src: Cisco-Li_32:a7:0a (58:6d:8f:32:a7:0a), Dst: Wistron_28:aa:0a (5c:ff:35:28:aa:0a)
Destination: Wistron_28:aa:0a (5c:ff:35:28:aa:0a)
Address: Wistron_28:aa:0a (5c:ff:35:28:aa:0a)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Source: Cisco-Li_32:a7:0a (58:6d:8f:32:a7:0a)
Address: Cisco-Li_32:a7:0a (58:6d:8f:32:a7:0a)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IPv4 (0x0800)
Internet Protocol Version 4, Src: 173.194.25.184, Dst: 192.168.1.144
0100 .... = Version: 4
.... 0101 = Header Length: 20 bytes (5)
Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT)
0000 00.. = Differentiated Services Codepoint: Default (0)
.... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0)
Total Length: 1500
Identification: 0x1f3b (7995)
Flags: 0x40, Don't fragment
0... .... = Reserved bit: Not set
.1.. .... = Don't fragment: Set
..0. .... = More fragments: Not set
...0 0000 0000 0000 = Fragment Offset: 0
Time to Live: 54
Protocol: TCP (6)
Header Checksum: 0x962e [validation disabled]
[Header checksum status: Unverified]
Source Address: 173.194.25.184
Destination Address: 192.168.1.144
[Source GeoIP: US, ASN 15169, GOOGLE]
[Source GeoIP Country: United States]
[Source or Destination GeoIP Country: United States]
[Source GeoIP ISO Two Letter Country Code: US]
[Source or Destination GeoIP ISO Two Letter Country Code: US]
[Source GeoIP AS Number: 15169]
[Source or Destination GeoIP AS Number: 15169]
[Source GeoIP AS Organization: GOOGLE]
[Source or Destination GeoIP AS Organization: GOOGLE]
[Source GeoIP Latitude: 37.751]
[Source or Destination GeoIP Latitude: 37.751]
[Source GeoIP Longitude: -97.822]
[Source or Destination GeoIP Longitude: -97.822]
Transmission Control Protocol, Src Port: 80, Dst Port: 40822, Seq: 89547, Ack: 560, Len: 1460
Source Port: 80
Destination Port: 40822
[Stream index: 2]
[Conversation completeness: Complete, WITH_DATA (63)]
[TCP Segment Len: 1460]
Sequence Number: 89547 (relative sequence number)
Sequence Number (raw): 4056910686
[Next Sequence Number: 91007 (relative sequence number)]
Acknowledgment Number: 560 (relative ack number)
Acknowledgment number (raw): 836031677
0101 .... = Header Length: 20 bytes (5)
Flags: 0x010 (ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .0.. = Reset: Not set
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······A····]
Window: 246
[Calculated window size: 15744]
[Window size scaling factor: 64]
Checksum: 0x7d74 [unverified]
[Checksum Status: Unverified]
Urgent Pointer: 0
[Timestamps]
[Time since first frame in this TCP stream: 0.350516000 seconds]
[Time since previous frame in this TCP stream: 0.001749000 seconds]
[SEQ/ACK analysis]
[iRTT: 0.062390000 seconds]
[Bytes in flight: 27740]
[Bytes sent since last PSH flag: 26280]
TCP payload (1460 bytes)
Hypertext Transfer Protocol
$���3�&���x^�S&��r9ſE��V��Y��[�%��f<�|\006z.\b�z\177Ĕ�*�U:����C��c��Ȫ�9��|�K�U��T\033�\f�x\037��}BzJ<V\016��e��b6c\r
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
[truncated]�+��b��d��)�\036Uá�6��\033Mx\003�A�\�\u05CB�N\033\v�͡\000��^ҡ�#Eo�����,m\033Vuݟ�c̖U|��$�J\032\000j�\016�\022nv���ݫ�\027.��\a�\023K�\032���
[Expert Info (Warning/Undecoded): Trailing stray characters]
[Trailing stray characters]
[Severity level: Warning]
[Group: Undecoded]
[Expert Info (Warning/Protocol): Illegal characters found in header name]
[Illegal characters found in header name]
[Severity level: Warning]
[Group: Protocol]
File Data: 1209 bytes
Data (1209 bytes)
Data: bad86817c8c692411d6c3b83d455eccb9886f58dbd47bb53f4d36628d7b9d7b17795588b…
[Length: 1209]