LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-24-2010, 12:40 AM   #1
magodiafano
LQ Newbie
 
Registered: Oct 2010
Posts: 28

Rep: Reputation: 0
An help about this tcpdump


Hi I have a little problem with this tcpdump.
I have to understand how many messages are sent by netspyd when a user logged in to shakti.

I saw that 7 times an user logs into shakti but there are 8 packets on tcpdump.. how can know the number of messages sent by netspyd?

[guest@shakti guest]$ sudo tcpdump ip multicast
Password:
tcpdump: listening on eth0
20:49:19.807880 shakti.1501 > 224.111.111.111.1500: udp 38 (DF) [ttl 1]
20:49:25.827881 shakti.1501 > 224.111.111.111.1500: udp 38 (DF) [ttl 1]
20:49:43.887880 shakti.1501 > 224.111.111.111.1500: udp 41 (DF) [ttl 1]
20:50:01.947882 shakti.1501 > 224.111.111.111.1500: udp 41 (DF) [ttl 1]
20:50:07.967764 shakti.1501 > 224.111.111.111.1500: udp 38 (DF) [ttl 1]
20:50:20.007885 shakti.1501 > 224.111.111.111.1500: udp 38 (DF) [ttl 1]
20:50:26.027772 shakti.1501 > 224.111.111.111.1500: udp 41 (DF) [ttl 1]
20:50:38.067903 shakti.1501 > 224.111.111.111.1500: udp 41 (DF) [ttl 1]

8 packets received by filter
0 packets dropped by kernel

[guest@shakti guest]$ netspyd 224.111.111.111 1500 1
netspyd started :
[local address : shakti:1501]
[multicast group : 224.111.111.111:1500]

== : guest logged on to shakti at 07:50 PM, pid=3472
== : guest logged on to shakti at 08:44 PM, pid=4026
== : guest logged on to shakti at 08:46 PM, pid=4026
== : guest logged on to shakti at 08:49 PM, pid=4114
== : guest logged on to shakti at 08:49 PM, pid=4116
== : guest logged out from shakti at 08:49 PM, pid=4114
== : guest logged out from shakti at 08:49 PM, pid=4116
== : guest logged on to shakti at 08:50 PM, pid=4187
== : guest logged on to shakti at 08:50 PM, pid=4224
== : guest logged out from shakti at 08:50 PM, pid=4224
 
Old 11-24-2010, 03:41 AM   #2
quanta
Member
 
Registered: Aug 2007
Location: Vietnam
Distribution: RedHat based, Debian based, Slackware, Gentoo
Posts: 724

Rep: Reputation: 101Reputation: 101
Try to write the raw packets to a file with -w and open it with Wireshark for more details.
 
Old 11-24-2010, 05:26 AM   #3
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
It appears that his may be a homework assignment. We have a policy against doing other peoples homework. We can help you with particular questions, if the details indicate that you have done your homework, and you have a particular question.

The "last" command would be a better method of determining how many times a user logged in in the past.

Also, the IP address being used is in the Multicasting address space. Please provide more information on what you are doing. Port 1500 indicates "VLSI License Manager".
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
tcpdump? hadimotamedi Linux - Newbie 3 02-20-2010 04:35 AM
tcpdump nawuza Linux - Newbie 1 01-16-2007 11:40 PM
tcpdump lakshminarayan Linux - Security 2 07-21-2006 03:50 AM
tcpdump gbell72 Linux - Security 5 09-18-2003 02:08 PM
tcpdump isbrower Linux - Networking 2 06-11-2001 03:48 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration