Код: Выделить всё
#tcpdump -npi fxp1 -vv host 172.22.6.148
12:52:29.232011 IP (tos 0x0, ttl 127, id 46607, offset 0, flags [DF], proto TCP (6), length 48) 172.22.6.148.5000 > 172.12.10.12.25: S, cksum 0x3f14 (correct), 1039370678:1039370678(0) win 65535 <mss 1460,nop,nop,sackOK>
12:52:29.232131 IP (tos 0x0, ttl 64, id 63893, offset 0, flags [DF], proto TCP (6), length 48) 172.12.10.12.25 > 172.22.6.148.5000: S, cksum 0x251e (correct), 612365926:612365926(0) ack 1039370679 win 65535 <mss 1460,sackOK,eol>
12:52:29.232373 IP (tos 0x0, ttl 127, id 46608, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.5000 > 172.12.10.12.25: ., cksum 0x50e1 (correct), 1:1(0) ack 1 win 65535
12:52:29.240302 IP (tos 0x0, ttl 64, id 63898, offset 0, flags [DF], proto TCP (6), length 81) 172.12.10.12.25 > 172.22.6.148.5000: P, cksum 0x89e2 (correct), 1:42(41) ack 1 win 65535
12:52:29.241141 IP (tos 0x0, ttl 127, id 46617, offset 0, flags [DF], proto TCP (6), length 54) 172.22.6.148.5000 > 172.12.10.12.25: P, cksum 0x83d7 (correct), 1:15(14) ack 42 win 65494
12:52:29.242042 IP (tos 0x0, ttl 64, id 63899, offset 0, flags [DF], proto TCP (6), length 190) 172.12.10.12.25 > 172.22.6.148.5000: P 42:192(150) ack 15 win 65535
12:52:29.242805 IP (tos 0x0, ttl 127, id 46622, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.5000 > 172.12.10.12.25: F, cksum 0x50d2 (correct), 15:15(0) ack 192 win 65344
12:52:29.242968 IP (tos 0x0, ttl 64, id 63900, offset 0, flags [DF], proto TCP (6), length 40) 172.12.10.12.25 > 172.22.6.148.5000: ., cksum 0x5013 (correct), 192:192(0) ack 16 win 65535
12:52:29.246567 IP (tos 0x0, ttl 64, id 63902, offset 0, flags [DF], proto TCP (6), length 40) 172.12.10.12.25 > 172.22.6.148.5000: F, cksum 0x5012 (correct), 192:192(0) ack 16 win 65535
12:52:29.246912 IP (tos 0x0, ttl 127, id 46623, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.5000 > 172.12.10.12.25: ., cksum 0x50d1 (correct), 16:16(0) ack 193 win 65344
12:52:29.249164 IP (tos 0x0, ttl 127, id 46626, offset 0, flags [DF], proto TCP (6), length 48) 172.22.6.148.1026 > 172.12.10.12.25: S, cksum 0xd307 (correct), 4161424177:4161424177(0) win 65535 <mss 1460,nop,nop,sackOK>
12:52:29.249353 IP (tos 0x0, ttl 64, id 63903, offset 0, flags [DF], proto TCP (6), length 48) 172.12.10.12.25 > 172.22.6.148.1026: S, cksum 0x59df (correct), 2788414436:2788414436(0) ack 4161424178 win 65535 <mss 1460,sackOK,eol>
12:52:29.249596 IP (tos 0x0, ttl 127, id 46627, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.1026 > 172.12.10.12.25: ., cksum 0x85a2 (correct), 1:1(0) ack 1 win 65535
12:52:29.253303 IP (tos 0x0, ttl 64, id 63907, offset 0, flags [DF], proto TCP (6), length 81) 172.12.10.12.25 > 172.22.6.148.1026: P, cksum 0xbea3 (correct), 1:42(41) ack 1 win 65535
12:52:29.254067 IP (tos 0x0, ttl 127, id 46636, offset 0, flags [DF], proto TCP (6), length 54) 172.22.6.148.1026 > 172.12.10.12.25: P, cksum 0xb898 (correct), 1:15(14) ack 42 win 65494
12:52:29.255434 IP (tos 0x0, ttl 64, id 63912, offset 0, flags [DF], proto TCP (6), length 190) 172.12.10.12.25 > 172.22.6.148.1026: P 42:192(150) ack 15 win 65535
12:52:29.256279 IP (tos 0x0, ttl 127, id 46641, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.1026 > 172.12.10.12.25: F, cksum 0x8593 (correct), 15:15(0) ack 192 win 65344
12:52:29.256356 IP (tos 0x0, ttl 64, id 63913, offset 0, flags [DF], proto TCP (6), length 40) 172.12.10.12.25 > 172.22.6.148.1026: ., cksum 0x84d4 (correct), 192:192(0) ack 16 win 65535
12:52:29.256775 IP (tos 0x0, ttl 64, id 63914, offset 0, flags [DF], proto TCP (6), length 40) 172.12.10.12.25 > 172.22.6.148.1026: F, cksum 0x84d3 (correct), 192:192(0) ack 16 win 65535
12:52:29.257019 IP (tos 0x0, ttl 127, id 46642, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.1026 > 172.12.10.12.25: ., cksum 0x8592 (correct), 16:16(0) ack 193 win 65344
12:52:29.271103 IP (tos 0x0, ttl 127, id 46645, offset 0, flags [DF], proto TCP (6), length 48) 172.22.6.148.1028 > 172.12.10.12.25: S, cksum 0x30b9 (correct), 3476428370:3476428370(0) win 65535 <mss 1460,nop,nop,sackOK>
12:52:29.271236 IP (tos 0x0, ttl 64, id 63922, offset 0, flags [DF], proto TCP (6), length 48) 172.12.10.12.25 > 172.22.6.148.1028: S, cksum 0xc809 (correct), 1186800354:1186800354(0) ack 3476428371 win 65535 <mss 1460,sackOK,eol>
12:52:29.271482 IP (tos 0x0, ttl 127, id 46646, offset 0, flags [DF], proto TCP (6), length 40) 172.22.6.148.1028 > 172.12.10.12.25: ., cksum 0xf3cc (correct), 1:1(0) ack 1 win 65535
Че та слишком много обращении с этого хоста по SMTP (десятки обращении в минуту).
Похоже на какой ты брутфорс.
Спасибо.