

---------------Query---------------
0000 00 1c f0 eb 28 cd 00 16 01 56 5d 66 08 00 45 00 ....(....V]f..E.
0010 00 3b b3 fd 00 00 80 11 04 f6 c0 a8 00 6d c0 a8 .;...........m..
0020 00 01 04 56 00 35 00 27 10 67 33 fa 01 00 00 01 ...V.5.'.g3.....
0030 00 00 00 00 00 00 09 6d 69 63 72 6f 73 6f 66 74 .......microsoft
0040 03 63 6f 6d 00 00 01 00 01 .com.....
Ethernet II
Destination: D-Link_eb:28:cd
Source: Buffalo_56:5d:66
Type: IP (0x0800)
Internet Protocol
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
Total Length: 59
Identification: 0xb3fd (46077)
Flags: 0x00
Fragment offset: 0
Time to live: 128
Protocol: UDP (0x11)
Header checksum: 0x04f6 [correct]
Source: 192.168.0.109 (192.168.0.109)
Destination: 192.168.0.1 (192.168.0.1)
User Datagram Protocol
Source port: nfsd-keepalive (1110)
Destination port: domain (53)
Length: 39
Checksum: 0x1067 [correct]
Domain Name System (query)
Response In: 68
Transaction ID: 0x33fa
Flags: 0x0100 (Standard query)
Questions: 1
Answer RRs: 0
Authority RRs: 0
Additional RRs: 0
Queries
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
---------------Fake Response---------------
0000 00 16 01 56 5d 66 00 1c f0 eb 28 cd 08 00 45 20 ...V]f....(...E
0010 00 4b 02 00 00 00 ff 11 37 c3 c0 a8 00 01 c0 a8 .K......7.......
0020 00 6d 00 35 04 56 00 37 00 00 33 fa 81 80 00 01 .m.5.V.7..3.....
0030 00 01 00 00 00 00 09 6d 69 63 72 6f 73 6f 66 74 .......microsoft
0040 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 .com............
0050 00 00 00 00 04 c0 a8 00 6e ........n
Ethernet II
Destination: Buffalo_56:5d:66
Source: D-Link_eb:28:cd
Type: IP (0x0800)
Internet Protocol
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x20 (DSCP 0x08: Class Selector 1; ECN: 0x00)
Total Length: 75
Identification: 0x0200 (512)
Flags: 0x00
Fragment offset: 0
Time to live: 255
Protocol: UDP (0x11)
Header checksum: 0x37c3 [correct]
Source: 192.168.0.1 (192.168.0.1)
Destination: 192.168.0.109 (192.168.0.109)
User Datagram Protocol
Source port: domain (53)
Destination port: nfsd-keepalive (1110)
Length: 55
Checksum: 0x0000 (none)
Domain Name System (response)
Request In: 60
Time: 0.017950000 seconds
Transaction ID: 0x33fa
Flags: 0x8180 (Standard query response, No error)
Questions: 1
Answer RRs: 1
Authority RRs: 0
Additional RRs: 0
Queries
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Answers
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Time to live: 0 time
Data length: 4
Addr: 192.168.0.110
---------------Real Response---------------
0000 00 16 01 56 5d 66 00 1c f0 eb 28 cd 08 00 45 00 ...V]f....(...E.
0010 00 5b 00 00 40 00 36 11 c2 d3 c0 a8 00 01 c0 a8 .[..@.6.........
0020 00 6d 00 35 04 56 00 47 7d 95 bf 25 81 80 00 01 .m.5.V.G}..%....
0030 00 02 00 00 00 00 09 6d 69 63 72 6f 73 6f 66 74 .......microsoft
0040 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 .com............
0050 00 0b 96 00 04 cf 2e c5 20 c0 0c 00 01 00 01 00 ........ .......
0060 00 0b 96 00 04 cf 2e e8 b6 .........
Ethernet II
Destination: Buffalo_56:5d:66
Source: D-Link_eb:28:cd
Type: IP (0x0800)
Internet Protocol
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
Total Length: 91
Identification: 0x0000 (0)
Flags: 0x04 (Don't Fragment)
Fragment offset: 0
Time to live: 54
Protocol: UDP (0x11)
Header checksum: 0xc2d3 [correct]
Source: 192.168.0.1 (192.168.0.1)
Destination: 192.168.0.109 (192.168.0.109)
User Datagram Protocol
Source port: domain (53)
Destination port: nfsd-keepalive (1110)
Length: 71
Checksum: 0x7d95 [correct]
Domain Name System (response)
Request In: 58
Time: 0.038947000 seconds
Transaction ID: 0xbf25
Flags: 0x8180 (Standard query response, No error)
Questions: 1
Answer RRs: 2
Authority RRs: 0
Additional RRs: 0
Queries
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Answers
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Time to live: 49 minutes, 26 seconds
Data length: 4
Addr: 207.46.197.32
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Time to live: 49 minutes, 26 seconds
Data length: 4
Addr: 207.46.232.182

12 11.068521 192.168.0.109 192.168.0.1 DNS Standard query A bob189.com
13 11.068602 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
14 11.150524 192.168.0.1 192.168.0.109 DNS Standard query response, No such name
15 11.150796 192.168.0.109 192.168.0.1 DNS Standard query A bob189.com.hsd1.mn.comcast.net
16 11.150836 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
17 11.220120 192.168.0.1 192.168.0.109 DNS Standard query response, No such name
4 0.002996 192.168.0.109 192.168.0.1 DNS Standard query A hackthissite.org
5 0.003064 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
8 0.046503 192.168.0.1 192.168.0.109 DNS Standard query response A 207.210.114.39
56 0.700732 192.168.0.109 192.168.0.1 DNS Standard query A www.hackthissite.org
57 0.700793 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
58 0.701830 192.168.0.109 192.168.0.1 DNS Standard query A www.hackthissite.org
59 0.721127 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
76 0.769081 192.168.0.1 192.168.0.109 DNS Standard query response CNAME hackthissite.org A 207.210.114.39
12 11.068521 192.168.0.109 192.168.0.1 DNS Standard query A bob189.com
13 11.068602 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
13 11.069231 192.168.0.1 192.168.0.109 DNS Standard query response A 192.168.0.110
14 11.150524 192.168.0.1 192.168.0.109 DNS Standard query response, No such name

---------------Fake Response---------------
0000 00 16 01 56 5d 66 00 1c f0 eb 28 cd 08 00 45 20 ...V]f....(...E
0010 00 4b 02 00 00 00 ff 11 37 c3 c0 a8 00 01 c0 a8 .K......7.......
0020 00 6d 00 35 04 56 00 37 00 00 33 fa 81 80 00 01 .m.5.V.7..3.....
0030 00 01 00 00 00 00 09 6d 69 63 72 6f 73 6f 66 74 .......microsoft
0040 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 .com............
0050 00 00 00 00 04 c0 a8 00 6e ........n
Queries
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Answers
Name: microsoft.com
Type: A (Host address)
Class: IN (0x0001)
Time to live: 0 time <-------------
Data length: 4
Addr: 192.168.0.110





Users browsing this forum: No registered users and 0 guests