LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-30-2013, 11:05 PM   #1
casperdaghost
Member
 
Registered: Aug 2009
Posts: 349

Rep: Reputation: 16
tcpdump help


I did a tcpdump of my wireless network. I have no idea of where this ip 169.254.1.35 is from- how do i begin to find out the source of this IP?




Code:
casper@casper-laptop:~$ sudo tcpdump -A -n -i wlan1 host 169.254.1.35

tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on wlan1, link-type EN10MB (Ethernet), capture size 96 bytes
22:42:26.081614 IP 169.254.1.35.7500 > 169.254.1.255.7500: isakmp:
E..@sQ..@..=...#.....L.L.,.o.......'.........LH(...#$...........
22:42:26.602482 IP 169.254.1.35.21302 > 255.255.255.255.21302: UDP, length 1133
E...W...@.s....#....S6S6.u.5<HmaNetConfig>
 <MsgFmtRev>3</MsgFmtRev>
 <Msg
22:42:30.689500 IP 169.254.1.35.62905 > 169.254.1.255.5000: UDP, length 12
E..(:d..@..B...#..........k.CMD...............

Last edited by casperdaghost; 04-30-2013 at 11:08 PM.
 
Old 04-30-2013, 11:29 PM   #2
casperdaghost
Member
 
Registered: Aug 2009
Posts: 349

Original Poster
Rep: Reputation: 16
wait...i think this i a link local address used in address assignment when there is no dhcp.

I just don't know why it keeps pinging each other. I guess there is no leasing.
 
Old 05-01-2013, 02:33 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,331
Blog Entries: 55

Rep: Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530Reputation: 3530
Set full payload saving with "-s0" and write the packets to a file with "-w /path/to/file". When done run the saved "/path/to/file" through Wireshark or any other comprehensive network traffic analysis tool and find out what this (XML-like) it's payload is about.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
tcpdump help, please! SFGAirborne Linux - Networking 1 09-14-2010 10:07 PM
tcpdump nawuza Linux - Newbie 1 01-17-2007 12:40 AM
tcpdump lakshminarayan Linux - Security 2 07-21-2006 04:50 AM
tcpdump Tihi Linux - Security 3 06-01-2005 06:54 AM
tcpdump telestudent Linux - Software 1 03-03-2005 11:07 PM


All times are GMT -5. The time now is 06:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration