This is a preview. You must login to view/edit this pcap.

O 1. 00:04:23:d8:4d:d2 » ff:ff:ff:ff:ff:ff arp Who has 10.0.0.1? Tell 10.0.0.2
O 2. 00:30:48:fb:c5:0e » 00:04:23:d8:4d:d2 arp 10.0.0.1 is at 00:30:48:fb:c5:0e
O 3. 10.0.0.2 » 10.0.0.1 portmap V2 GETPORT Call NFS(100003) V:3 TCP
O 4. 10.0.0.1 » 10.0.0.2 portmap V2 GETPORT Reply (Call In 3) Port:2049
O 5. 10.0.0.2 » 10.0.0.1 portmap V2 GETPORT Call MOUNT(100005) V:3 TCP

Here are some of things that registered users can do with this pcap:

  • Reorder packets
  • Fragment packets
  • Reassemble TCP streams
  • Rewrite TCP streams (over IPv4 and IPv6)
  • Extract embedded HTTP content
  • Convert any packet into a DoS generator