kraken-pcap smtp decoder demo

지금은 UDP 처리기가 빠져서 이 부분 추가되면 낼 예정..
http://krakenapps.org/browser/kraken-pcap/src/main/java/org/krakenapps/pcap
아래는 출력 샘플.. 기본값으로 보이는 것들은 생략할 수 있게 해줘야겠고..

[Packet Num #634]
ethernet {dst: 00-08-9F-4E-BC-E6, src: 00-24-21-B3-43-E9, type: 0x800}
ip {10.0.2.18 > 202.131.27.94 - version: 4, header_length: 20, total_length: 45, id: 9162, fragment_offset: 0, ttl: 65408, header_checksum: 0x00}
--------MIME MESSAGE--------
Subject: 샤인올랏~
Content: javax.mail.internet.MimeMultipart@1a125f0
----------------------------
tcp {10.0.2.18:51238 > 202.131.27.94:25 - P seq: 1248610, ack: 430, window: 63811, urgent: 0}

[Packet Num #635]
ethernet {dst: 00-24-21-B3-43-E9, src: 00-08-9F-4E-BC-E6, type: 0x800}
ip {202.131.27.94 > 10.0.2.18 - version: 4, header_length: 20, total_length: 40, id: 22786, fragment_offset: 0, ttl: 53, header_checksum: 0xFADA}
tcp {202.131.27.94:25 > 10.0.2.18:51238 - . seq: 430, ack: 1248615, window: 32767, urgent: 0}

[Packet Num #636]
ethernet {dst: 00-24-21-B3-43-E9, src: 00-08-9F-4E-BC-E6, type: 0x800}
ip {202.131.27.94 > 10.0.2.18 - version: 4, header_length: 20, total_length: 81, id: 22788, fragment_offset: 0, ttl: 53, header_checksum: 0xFAAF}
tcp {202.131.27.94:25 > 10.0.2.18:51238 - P seq: 430, ack: 1248615, window: 32767, urgent: 0}

[Packet Num #637]
ethernet {dst: 00-24-21-B3-43-E9, src: 00-08-9F-4E-BC-E6, type: 0x800}
ip {202.131.27.94 > 10.0.2.18 - version: 4, header_length: 20, total_length: 81, id: 22790, fragment_offset: 0, ttl: 53, header_checksum: 0xFAAD}
tcp {202.131.27.94:25 > 10.0.2.18:51238 - P seq: 430, ack: 1248615, window: 32767, urgent: 0}

[Packet Num #638]
ethernet {dst: 00-08-9F-4E-BC-E6, src: 00-24-21-B3-43-E9, type: 0x800}
ip {10.0.2.18 > 202.131.27.94 - version: 4, header_length: 20, total_length: 40, id: 9163, fragment_offset: 0, ttl: 65408, header_checksum: 0x00}
tcp {10.0.2.18:51238 > 202.131.27.94:25 - . seq: 1248615, ack: 471, window: 63770, urgent: 0}

[Packet Num #639]
ethernet {dst: 00-08-9F-4E-BC-E6, src: 00-24-21-B3-43-E9, type: 0x800}
ip {10.0.2.18 > 202.131.27.94 - version: 4, header_length: 20, total_length: 46, id: 9166, fragment_offset: 0, ttl: 65408, header_checksum: 0x00}
tcp {10.0.2.18:51238 > 202.131.27.94:25 - P seq: 1248615, ack: 471, window: 63770, urgent: 0}

[Packet Num #640]
ethernet {dst: 00-08-9F-4E-BC-E6, src: 00-24-21-B3-43-E9, type: 0x800}
ip {10.0.2.18 > 202.131.27.94 - version: 4, header_length: 20, total_length: 40, id: 9167, fragment_offset: 0, ttl: 65408, header_checksum: 0x00}
tcp {10.0.2.18:51238 > 202.131.27.94:25 - F seq: 1248621, ack: 471, window: 63770, urgent: 0}

[Packet Num #641]
ethernet {dst: 00-24-21-B3-43-E9, src: 00-08-9F-4E-BC-E6, type: 0x800}
ip {202.131.27.94 > 10.0.2.18 - version: 4, header_length: 20, total_length: 108, id: 22792, fragment_offset: 0, ttl: 53, header_checksum: 0xFA90}
tcp {202.131.27.94:25 > 10.0.2.18:51238 - P seq: 471, ack: 1248621, window: 32767, urgent: 0}

[Packet Num #642]
ethernet {dst: 00-08-9F-4E-BC-E6, src: 00-24-21-B3-43-E9, type: 0x800}
ip {10.0.2.18 > 202.131.27.94 - version: 4, header_length: 20, total_length: 40, id: 9168, fragment_offset: 0, ttl: 65408, header_checksum: 0x00}
Deallocate tx, rx buffer and remove smtp session.
*********************************
Session closed(Reason : RST)
*********************************
tcp {10.0.2.18:51238 > 202.131.27.94:25 - R window: 0, urgent: 0}

[Packet Num #643]
ethernet {dst: 00-24-21-B3-43-E9, src: 00-08-9F-4E-BC-E6, type: 0x800}
ip {202.131.27.94 > 10.0.2.18 - version: 4, header_length: 20, total_length: 40, id: 22794, fragment_offset: 0, ttl: 53, header_checksum: 0xFAD2}
tcp {202.131.27.94:25 > 10.0.2.18:51238 - F window: 32767, urgent: 0}

[Packet Num #644]
ethernet {dst: 00-24-21-B3-43-E9, src: 00-08-9F-4E-BC-E6, type: 0x800}
ip {202.131.27.94 > 10.0.2.18 - version: 4, header_length: 20, total_length: 40, id: 22796, fragment_offset: 0, ttl: 53, header_checksum: 0xFAD0}
tcp {202.131.27.94:25 > 10.0.2.18:51238 - . window: 32767, urgent: 0}


트랙백

이 글과 관련된 글 쓰기 (트랙백 보내기)
TrackbackURL : http://xeraph.com/tb/5168163 [도움말]

덧글

댓글 입력 영역