weblog d’un abbe

20070922

Why some servers don’t respond to default traceroute ?

Filed under: Research — abbe @ 1149

Those servers are esp. endpoint servers and they don’t respond to default traceroute. And following is an example, how to play with traceroute :-D

[wahjava@chatteau ~]$ traceroute -n 66.179.175.2 -p 14
traceroute to 66.179.175.2 (66.179.175.2), 30 hops max, 40 byte packets
 1  * * *
 2  202.56.215.230  40.537 ms  42.393 ms  43.284 ms
 3  122.160.220.154  46.249 ms  47.157 ms  48.846 ms
 4  203.101.83.197  51.690 ms  53.556 ms *
 5  * * *
 6  * 208.192.179.97  310.810 ms  310.912 ms
 7  152.63.22.74  315.907 ms  314.908 ms  315.903 ms
 8  152.63.96.10  364.883 ms  362.836 ms  362.898 ms
 9  152.63.97.21  357.856 ms  357.893 ms  354.899 ms
10  157.130.155.154  359.886 ms  359.891 ms  356.876 ms
11  66.179.168.43  360.877 ms  360.912 ms  357.850 ms
12  66.179.80.100  356.867 ms  355.875 ms  354.879 ms
13  * * *
14  * * *

Following is the tcpdump carried in another terminal:

[wahjava@chatteau ~]$ sudo /usr/sbin/tcpdump -nn -i ppp0 -v host 66.179.175.2
tcpdump: listening on ppp0, link-type LINUX_SLL (Linux cooked), capture size 96 bytes
02:11:00.871835 IP (tos 0x0, ttl 1, id 47558, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34015 > 66.179.175.2.14: UDP, length 40
02:11:00.871921 IP (tos 0x0, ttl 1, id 47559, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34016 > 66.179.175.2.15: UDP, length 40
02:11:00.871994 IP (tos 0x0, ttl 1, id 47560, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34018 > 66.179.175.2.16: UDP, length 40
02:11:00.872061 IP (tos 0x0, ttl 2, id 47561, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34019 > 66.179.175.2.17: UDP, length 40
02:11:00.872127 IP (tos 0x0, ttl 2, id 47562, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34020 > 66.179.175.2.18: UDP, length 40
02:11:00.872197 IP (tos 0x0, ttl 2, id 47563, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34021 > 66.179.175.2.19: UDP, length 40
02:11:00.872264 IP (tos 0x0, ttl 3, id 47564, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34022 > 66.179.175.2.20: UDP, length 40
02:11:00.872330 IP (tos 0x0, ttl 3, id 47565, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34023 > 66.179.175.2.21: UDP, length 40
02:11:00.872698 IP (tos 0x0, ttl 3, id 47566, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34024 > 66.179.175.2.22: UDP, length 40
02:11:00.872843 IP (tos 0x0, ttl 4, id 47567, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34026 > 66.179.175.2.23: UDP, length 40
02:11:00.872951 IP (tos 0x0, ttl 4, id 47568, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34027 > 66.179.175.2.24: UDP, length 40
02:11:00.873056 IP (tos 0x0, ttl 4, id 47569, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34028 > 66.179.175.2.25: UDP, length 40
02:11:00.873171 IP (tos 0x0, ttl 5, id 47570, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34029 > 66.179.175.2.26: UDP, length 40
02:11:00.873274 IP (tos 0x0, ttl 5, id 47571, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34030 > 66.179.175.2.27: UDP, length 40
02:11:00.873375 IP (tos 0x0, ttl 5, id 47572, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34032 > 66.179.175.2.28: UDP, length 40
02:11:00.873475 IP (tos 0x0, ttl 6, id 47573, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34033 > 66.179.175.2.29: UDP, length 40
02:11:00.912717 IP (tos 0x0, ttl 6, id 47574, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34034 > 66.179.175.2.30: UDP, length 40
02:11:00.914575 IP (tos 0x0, ttl 6, id 47575, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34035 > 66.179.175.2.31: UDP, length 40
02:11:00.915559 IP (tos 0x0, ttl 7, id 47576, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34036 > 66.179.175.2.32: UDP, length 40
02:11:00.918565 IP (tos 0x0, ttl 7, id 47577, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34037 > 66.179.175.2.33: UDP, length 40
02:11:00.919570 IP (tos 0x0, ttl 7, id 47578, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34038 > 66.179.175.2.34: UDP, length 40
02:11:00.921593 IP (tos 0x0, ttl 8, id 47579, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34039 > 66.179.175.2.35: UDP, length 40
02:11:00.924600 IP (tos 0x0, ttl 8, id 47580, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34040 > 66.179.175.2.36: UDP, length 40
02:11:00.926559 IP (tos 0x0, ttl 8, id 47581, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34041 > 66.179.175.2.37: UDP, length 40
02:11:01.223638 IP (tos 0x0, ttl 9, id 47582, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34042 > 66.179.175.2.38: UDP, length 40
02:11:01.225552 IP (tos 0x0, ttl 9, id 47583, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34043 > 66.179.175.2.39: UDP, length 40
02:11:01.231527 IP (tos 0x0, ttl 9, id 47584, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34044 > 66.179.175.2.40: UDP, length 40
02:11:01.233527 IP (tos 0x0, ttl 10, id 47585, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34045 > 66.179.175.2.41: UDP, length 40
02:11:01.235531 IP (tos 0x0, ttl 10, id 47586, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34046 > 66.179.175.2.42: UDP, length 40
02:11:01.286555 IP (tos 0x0, ttl 10, id 47587, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34047 > 66.179.175.2.43: UDP, length 40
02:11:01.287527 IP (tos 0x0, ttl 11, id 47588, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34051 > 66.179.175.2.44: UDP, length 40
02:11:01.289517 IP (tos 0x0, ttl 11, id 47589, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34052 > 66.179.175.2.45: UDP, length 40
02:11:01.581593 IP (tos 0x0, ttl 11, id 47590, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34054 > 66.179.175.2.46: UDP, length 40
02:11:01.583518 IP (tos 0x0, ttl 12, id 47591, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34055 > 66.179.175.2.47: UDP, length 40
02:11:01.586485 IP (tos 0x0, ttl 12, id 47592, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34056 > 66.179.175.2.48: UDP, length 40
02:11:01.593467 IP (tos 0x0, ttl 12, id 47593, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34057 > 66.179.175.2.49: UDP, length 40
02:11:01.595476 IP (tos 0x0, ttl 13, id 47594, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34058 > 66.179.175.2.50: UDP, length 40
02:11:01.643496 IP (tos 0x0, ttl 13, id 47595, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34059 > 66.179.175.2.51: UDP, length 40
02:11:01.648460 IP (tos 0x0, ttl 13, id 47596, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34060 > 66.179.175.2.52: UDP, length 40
02:11:01.650479 IP (tos 0x0, ttl 14, id 47597, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34061 > 66.179.175.2.53: 16449 op8 [b2&3=0x4243] [17991a] [17477q] [18505n] [19019au][|domain]
02:11:01.939559 IP (tos 0x0, ttl 14, id 47598, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34062 > 66.179.175.2.54: UDP, length 40
02:11:01.940453 IP (tos 0x0, ttl 14, id 47599, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34063 > 66.179.175.2.55: UDP, length 40
02:11:01.942424 IP (tos 0x0, ttl 15, id 47600, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34064 > 66.179.175.2.56: UDP, length 40
02:11:01.948407 IP (tos 0x0, ttl 15, id 47601, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34065 > 66.179.175.2.57: UDP, length 40
02:11:06.948211 IP (tos 0x0, ttl 15, id 47602, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34066 > 66.179.175.2.58: UDP, length 40
02:11:06.948280 IP (tos 0x0, ttl 16, id 47603, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34067 > 66.179.175.2.59: UDP, length 40
02:11:06.948342 IP (tos 0x0, ttl 16, id 47604, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34068 > 66.179.175.2.60: UDP, length 40
02:11:06.948433 IP (tos 0x0, ttl 16, id 47605, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34069 > 66.179.175.2.61: UDP, length 40
02:11:06.948491 IP (tos 0x0, ttl 17, id 47606, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34070 > 66.179.175.2.62: UDP, length 40
02:11:06.948550 IP (tos 0x0, ttl 17, id 47607, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34071 > 66.179.175.2.63: UDP, length 40
02:11:06.948605 IP (tos 0x0, ttl 17, id 47608, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34072 > 66.179.175.2.64: UDP, length 40
02:11:06.948660 IP (tos 0x0, ttl 18, id 47609, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34073 > 66.179.175.2.65: UDP, length 40
02:11:06.948718 IP (tos 0x0, ttl 18, id 47610, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34074 > 66.179.175.2.66: UDP, length 40
02:11:06.948868 IP (tos 0x0, ttl 18, id 47611, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34075 > 66.179.175.2.67: BOOTP/DHCP, unknown (0x40), length 40, htype 65, hlen 66, hops 67, xid 0x44454647, secs 18505, Flags [none]
          Client-IP 76.77.78.79
          Your-IP 80.81.82.83
          Server-IP 84.85.86.87
          Gateway-IP 88.89.90.91 [|bootp]
02:11:06.948921 IP (tos 0x0, ttl 19, id 47612, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34076 > 66.179.175.2.68: BOOTP/DHCP, unknown (0x40), length 40, htype 65, hlen 66, hops 67, xid 0x44454647, secs 18505, Flags [none]
          Client-IP 76.77.78.79
          Your-IP 80.81.82.83
          Server-IP 84.85.86.87
          Gateway-IP 88.89.90.91 [|bootp]
02:11:06.948975 IP (tos 0x0, ttl 19, id 47613, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34077 > 66.179.175.2.69:  40 tftp-#16449
02:11:06.949024 IP (tos 0x0, ttl 19, id 47614, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34078 > 66.179.175.2.70: UDP, length 40
02:11:06.949075 IP (tos 0x0, ttl 20, id 47615, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34079 > 66.179.175.2.71: UDP, length 40
02:11:06.949129 IP (tos 0x0, ttl 20, id 47616, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34080 > 66.179.175.2.72: UDP, length 40
02:11:11.949668 IP (tos 0x0, ttl 20, id 47617, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34080 > 66.179.175.2.73: UDP, length 40
02:11:11.949734 IP (tos 0x0, ttl 21, id 47618, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34081 > 66.179.175.2.74: UDP, length 40
02:11:11.949785 IP (tos 0x0, ttl 21, id 47619, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34082 > 66.179.175.2.75: UDP, length 40
02:11:11.949844 IP (tos 0x0, ttl 21, id 47620, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34083 > 66.179.175.2.76: UDP, length 40
02:11:11.949900 IP (tos 0x0, ttl 22, id 47621, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34084 > 66.179.175.2.77: UDP, length 40
02:11:11.949958 IP (tos 0x0, ttl 22, id 47622, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34085 > 66.179.175.2.78: UDP, length 40
02:11:11.950013 IP (tos 0x0, ttl 22, id 47623, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34086 > 66.179.175.2.79: UDP, length 40
02:11:11.950069 IP (tos 0x0, ttl 23, id 47624, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34087 > 66.179.175.2.80: UDP, length 40
02:11:11.950126 IP (tos 0x0, ttl 23, id 47625, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34088 > 66.179.175.2.81: UDP, length 40
02:11:11.950186 IP (tos 0x0, ttl 23, id 47626, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34089 > 66.179.175.2.82: UDP, length 40
02:11:11.950247 IP (tos 0x0, ttl 24, id 47627, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34090 > 66.179.175.2.83: UDP, length 40
02:11:11.950400 IP (tos 0x0, ttl 24, id 47628, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34091 > 66.179.175.2.84: UDP, length 40
02:11:11.950456 IP (tos 0x0, ttl 24, id 47629, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34092 > 66.179.175.2.85: UDP, length 40
02:11:11.950505 IP (tos 0x0, ttl 25, id 47630, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34093 > 66.179.175.2.86: UDP, length 40
02:11:11.950555 IP (tos 0x0, ttl 25, id 47631, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34094 > 66.179.175.2.87: UDP, length 40

So, what’s the conclusion of above tcpdump and traceroute ? 66.179.175.2 hasn’t responded to my traceroute. Never mind, we’ll try another traceroute, and this time 66.179.175.2 will respond only in 1st probe.

[wahjava@chatteau ~]$ traceroute -n 66.179.175.2 -p 17
traceroute to 66.179.175.2 (66.179.175.2), 30 hops max, 40 byte packets
 1  * * *
 2  202.56.215.230  39.882 ms  40.784 ms  42.692 ms
 3  122.160.220.154  43.481 ms  45.359 ms  47.219 ms
 4  203.101.83.197  50.046 ms  51.923 ms  53.796 ms
 5  125.21.167.25  102.689 ms  105.521 ms  106.413 ms
 6  208.192.179.97  340.290 ms  307.827 ms  308.873 ms
 7  152.63.22.74  312.893 ms  314.890 ms  314.881 ms
 8  152.63.96.10  363.926 ms  362.923 ms  362.912 ms
 9  152.63.97.21  359.900 ms  356.828 ms  359.930 ms
10  157.130.155.154  362.868 ms  360.801 ms  359.912 ms
11  66.179.168.43  360.906 ms  357.905 ms  359.952 ms
12  66.179.80.100  355.900 ms  356.892 ms  356.881 ms
13  66.179.175.2  367.903 ms * *
14  * * *

Following is the tcpdump carried in another terminal:

[wahjava@chatteau ~]$ sudo /usr/sbin/tcpdump -nn -i ppp0 -v host 66.179.175.2
tcpdump: listening on ppp0, link-type LINUX_SLL (Linux cooked), capture size 96 bytes
02:13:15.743941 IP (tos 0x0, ttl 1, id 47633, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34095 > 66.179.175.2.17: UDP, length 40
02:13:15.744105 IP (tos 0x0, ttl 1, id 47634, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34096 > 66.179.175.2.18: UDP, length 40
02:13:15.744214 IP (tos 0x0, ttl 1, id 47635, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34097 > 66.179.175.2.19: UDP, length 40
02:13:15.744312 IP (tos 0x0, ttl 2, id 47636, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34098 > 66.179.175.2.20: UDP, length 40
02:13:15.744421 IP (tos 0x0, ttl 2, id 47637, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34099 > 66.179.175.2.21: UDP, length 40
02:13:15.744515 IP (tos 0x0, ttl 2, id 47638, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34100 > 66.179.175.2.22: UDP, length 40
02:13:15.744731 IP (tos 0x0, ttl 3, id 47639, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34102 > 66.179.175.2.23: UDP, length 40
02:13:15.744858 IP (tos 0x0, ttl 3, id 47640, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34103 > 66.179.175.2.24: UDP, length 40
02:13:15.744981 IP (tos 0x0, ttl 3, id 47641, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34104 > 66.179.175.2.25: UDP, length 40
02:13:15.745147 IP (tos 0x0, ttl 4, id 47642, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34105 > 66.179.175.2.26: UDP, length 40
02:13:15.745280 IP (tos 0x0, ttl 4, id 47643, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34106 > 66.179.175.2.27: UDP, length 40
02:13:15.745406 IP (tos 0x0, ttl 4, id 47644, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34107 > 66.179.175.2.28: UDP, length 40
02:13:15.745535 IP (tos 0x0, ttl 5, id 47645, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34108 > 66.179.175.2.29: UDP, length 40
02:13:15.745670 IP (tos 0x0, ttl 5, id 47646, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34109 > 66.179.175.2.30: UDP, length 40
02:13:15.745805 IP (tos 0x0, ttl 5, id 47647, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34110 > 66.179.175.2.31: UDP, length 40
02:13:15.745939 IP (tos 0x0, ttl 6, id 47648, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34111 > 66.179.175.2.32: UDP, length 40
02:13:15.784367 IP (tos 0x0, ttl 6, id 47649, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34112 > 66.179.175.2.33: UDP, length 40
02:13:15.785265 IP (tos 0x0, ttl 6, id 47650, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34113 > 66.179.175.2.34: UDP, length 40
02:13:15.787262 IP (tos 0x0, ttl 7, id 47651, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34114 > 66.179.175.2.35: UDP, length 40
02:13:15.788264 IP (tos 0x0, ttl 7, id 47652, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34115 > 66.179.175.2.36: UDP, length 40
02:13:15.790273 IP (tos 0x0, ttl 7, id 47653, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34116 > 66.179.175.2.37: UDP, length 40
02:13:15.792252 IP (tos 0x0, ttl 8, id 47654, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34117 > 66.179.175.2.38: UDP, length 40
02:13:15.795252 IP (tos 0x0, ttl 8, id 47655, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34118 > 66.179.175.2.39: UDP, length 40
02:13:15.797257 IP (tos 0x0, ttl 8, id 47656, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34119 > 66.179.175.2.40: UDP, length 40
02:13:15.799259 IP (tos 0x0, ttl 9, id 47657, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34120 > 66.179.175.2.41: UDP, length 40
02:13:15.848337 IP (tos 0x0, ttl 9, id 47658, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34121 > 66.179.175.2.42: UDP, length 40
02:13:15.851251 IP (tos 0x0, ttl 9, id 47659, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34123 > 66.179.175.2.43: UDP, length 40
02:13:15.852276 IP (tos 0x0, ttl 10, id 47660, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34124 > 66.179.175.2.44: UDP, length 40
02:13:16.086367 IP (tos 0x0, ttl 10, id 47661, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34125 > 66.179.175.2.45: UDP, length 40
02:13:16.092223 IP (tos 0x0, ttl 10, id 47662, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34126 > 66.179.175.2.46: UDP, length 40
02:13:16.094208 IP (tos 0x0, ttl 11, id 47663, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34127 > 66.179.175.2.47: UDP, length 40
02:13:16.100209 IP (tos 0x0, ttl 11, id 47664, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34128 > 66.179.175.2.48: UDP, length 40
02:13:16.103240 IP (tos 0x0, ttl 11, id 47665, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34129 > 66.179.175.2.49: UDP, length 40
02:13:16.105218 IP (tos 0x0, ttl 12, id 47666, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34130 > 66.179.175.2.50: UDP, length 40
02:13:16.156266 IP (tos 0x0, ttl 12, id 47667, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34131 > 66.179.175.2.51: UDP, length 40
02:13:16.158231 IP (tos 0x0, ttl 12, id 47668, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34132 > 66.179.175.2.52: UDP, length 40
02:13:16.159207 IP (tos 0x0, ttl 13, id 47669, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34133 > 66.179.175.2.53: 16449 op8 [b2&3=0x4243] [17991a] [17477q] [18505n] [19019au][|domain]
02:13:16.160223 IP (tos 0x0, ttl 13, id 47670, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34134 > 66.179.175.2.54: UDP, length 40
02:13:16.205227 IP (tos 0x0, ttl 13, id 47671, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34135 > 66.179.175.2.55: UDP, length 40
02:13:16.211274 IP (tos 0x0, ttl 14, id 47672, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34136 > 66.179.175.2.56: UDP, length 40
02:13:16.215203 IP (tos 0x0, ttl 14, id 47673, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34137 > 66.179.175.2.57: UDP, length 40
02:13:16.447325 IP (tos 0x0, ttl 14, id 47674, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34138 > 66.179.175.2.58: UDP, length 40
02:13:16.452203 IP (tos 0x0, ttl 15, id 47675, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34139 > 66.179.175.2.59: UDP, length 40
02:13:16.455167 IP (tos 0x0, ttl 15, id 47676, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34140 > 66.179.175.2.60: UDP, length 40
02:13:16.458164 IP (tos 0x0, ttl 15, id 47677, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34141 > 66.179.175.2.61: UDP, length 40
02:13:16.461168 IP (tos 0x0, ttl 16, id 47678, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34142 > 66.179.175.2.62: UDP, length 40
02:13:16.463297 IP (tos 0x0, ttl 16, id 47679, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34143 > 66.179.175.2.63: UDP, length 40
02:13:16.513277 IP (tos 0x0, ttl 16, id 47680, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34144 > 66.179.175.2.64: UDP, length 40
02:13:16.515174 IP (tos 0x0, ttl 17, id 47681, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34146 > 66.179.175.2.65: UDP, length 40
02:13:16.527091 IP (tos 0x0, ttl 243, id 20007, offset 0, flags [none], proto ICMP (1), length 56) 66.179.175.2 > 122.163.222.43: ICMP time exceeded in-transit, length 36
        IP (tos 0x0, ttl 1, id 47669, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34133 > 66.179.175.2.53: [|domain]
02:13:16.527262 IP (tos 0x0, ttl 17, id 47682, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34147 > 66.179.175.2.66: UDP, length 40
02:13:21.527424 IP (tos 0x0, ttl 17, id 47683, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34148 > 66.179.175.2.67: BOOTP/DHCP, unknown (0x40), length 40, htype 65, hlen 66, hops 67, xid 0x44454647, secs 18505, Flags [none]
          Client-IP 76.77.78.79
          Your-IP 80.81.82.83
          Server-IP 84.85.86.87
          Gateway-IP 88.89.90.91 [|bootp]
02:13:21.527489 IP (tos 0x0, ttl 18, id 47684, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34149 > 66.179.175.2.68: BOOTP/DHCP, unknown (0x40), length 40, htype 65, hlen 66, hops 67, xid 0x44454647, secs 18505, Flags [none]
          Client-IP 76.77.78.79
          Your-IP 80.81.82.83
          Server-IP 84.85.86.87
          Gateway-IP 88.89.90.91 [|bootp]
02:13:21.527546 IP (tos 0x0, ttl 18, id 47685, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34150 > 66.179.175.2.69:  40 tftp-#16449
02:13:21.527592 IP (tos 0x0, ttl 18, id 47686, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34151 > 66.179.175.2.70: UDP, length 40
02:13:21.527645 IP (tos 0x0, ttl 19, id 47687, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34152 > 66.179.175.2.71: UDP, length 40
02:13:21.527707 IP (tos 0x0, ttl 19, id 47688, offset 0, flags [none], proto UDP (17), length 68) 122.163.222.43.34154 > 66.179.175.2.72: UDP, length 40

Now, we’ll try another traceroute, and this time 66.179.175.2 will respond only in 2nd probe.

[wahjava@chatteau ~]$ traceroute -n 66.179.175.2 -p 16
traceroute to 66.179.175.2 (66.179.175.2), 30 hops max, 40 byte packets
 1  * * *
 2  202.56.215.230  42.594 ms  44.456 ms  45.478 ms
 3  122.160.220.154  46.384 ms  49.289 ms  51.242 ms
 4  203.101.83.197  53.193 ms * *
 5  * * *
 6  * 208.192.179.97  307.757 ms  310.900 ms
 7  152.63.22.74  315.820 ms  316.874 ms  316.882 ms
 8  152.63.96.10  364.889 ms  364.894 ms  361.176 ms
 9  152.63.97.21  358.003 ms  356.990 ms  356.841 ms
10  157.130.155.154  358.878 ms  358.878 ms  358.909 ms
11  66.179.168.43  358.493 ms  358.727 ms  356.677 ms
12  66.179.80.100  355.914 ms  355.882 ms  355.835 ms
13  * 66.179.175.2  363.848 ms *
14  * * *

Not pasting tcpdump this time, because you’re not reading those dumps :-P

BtW, 66.179.175.2 is one of the nameserver of webrachna.com, which I was investigating in this post.

About these ads

Leave a Comment »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

The Shocking Blue Green Theme. Create a free website or blog at WordPress.com.

Follow

Get every new post delivered to your Inbox.

%d bloggers like this: