2.4.5-pre1: Bogus ARP packets containing NFS file data? (2)

From: Frank van Maarseveen (fvm@tasking.nl)
Date: Tue May 15 2001 - 11:47:24 EST


Got the image of 3 interesting packets by letting a modified tcpdump dump
the entire packet buffer in arp_print().

Original tcpdump output:
16:23:17.108993 P 0:60:97:ba:b4:f5 0:0:0:0:0:1 arp 1514: arp-#8192 for proto #1500 (138) hardware #17664 (36)
16:23:17.809024 P 0:60:97:ba:b4:f5 0:0:0:0:0:1 arp 1514: arp-#8192 for proto #1500 (139) hardware #17664 (36)
16:23:17.810256 P 0:60:97:ba:b4:f5 0:0:0:0:0:1 arp 1514: arp-#8377 for proto #1500 (139) hardware #17664 (36)

strings 1.bin:
        espoo
        b0VIM 5.7
        espoo
        ~fvm/ctri/c_flow.c
        3210#"!

strings 2.bin:
        espoo
        b0VIM 5.7
        espoo
        ~fvm/ctri/c_flow.c
        3210#"!

strings 3.bin:

Corresponding packet data attached (note: not suitable for tcpdump -r anymore).

-- 
Frank




- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Tue May 15 2001 - 21:00:42 EST