|
|||||||||||
|
Re: DNS packet analysis.
From: Mark Cooper <mark(at)mhc-online.co.uk>
Date: Wed Dec 11 2002 - 16:47:27 EST Hi V.Jay, There is nothing malicious happening here. Each DNS response comes in two legitimate-looking fragments, for a total of 1480+575=2055 bytes. By "legitimate looking", I mean that the first fragment is always at offset 0 and of 1480bytes, and the second starts at offset 1480. Nothing untowards here. It shows that the MTU of at least part of the path between DNS.server.com and outside.guy.com is 1480 bytes. I understand that this is the default MTU for Win/XP using PPPoE. Hope this helps. Regards, Mark --- Mark Cooper SANS GCIA ----- Original Message ----- From: "larosa, vjay"Received on Wed Dec 11 18:04:49 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT |
||||||||||
|
|||||||||||