OK, habe mal txpdump laufen lassen; während obige Requests im Log erscheinen spuckte tcpdump folgendes aus:
[root@laber-land pierre]# tcpdump -i lo
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on lo, link-type EN10MB (Ethernet), capture size 96 bytes
20:40:36.033865 IP laber-land.de.40492 > laber-land.de.www: S 1188544929:1188544929(0) win 32792 <mss 16396,sackOK,timestamp 63450748 0,nop,wscale 2>
20:40:36.033945 IP laber-land.de.www > laber-land.de.40492: S 1191876554:1191876554(0) ack 1188544930 win 32768 <mss 16396,sackOK,timestamp 63450748 63450748,nop,wscale 2>
20:40:36.035088 IP laber-land.de.40492 > laber-land.de.www: . ack 1 win 8198 <nop,nop,timestamp 63450748 63450748>
20:40:39.631321 IP laber-land.de.www > laber-land.de.40492: S 1191876554:1191876554(0) ack 1188544930 win 32768 <mss 16396,sackOK,timestamp 63451648 63450748,nop,wscale 2>
20:40:39.631389 IP laber-land.de.40492 > laber-land.de.www: . ack 1 win 8198 <nop,nop,timestamp 63451648 63451648,nop,nop,sack 1 {0:1}>
20:40:45.631373 IP laber-land.de.www > laber-land.de.40492: S 1191876554:1191876554(0) ack 1188544930 win 32768 <mss 16396,sackOK,timestamp 63453148 63451648,nop,wscale 2>
20:40:45.631445 IP laber-land.de.40492 > laber-land.de.www: . ack 1 win 8198 <nop,nop,timestamp 63453148 63453148,nop,nop,sack 1 {0:1}>
20:40:53.108342 IP laber-land.de.40492 > laber-land.de.www: P 1:6(5) ack 1 win 8198 <nop,nop,timestamp 63455017 63453148>
20:40:53.108429 IP laber-land.de.www > laber-land.de.40492: . ack 6 win 8192 <nop,nop,timestamp 63455017 63455017>
20:40:53.834228 IP laber-land.de.40492 > laber-land.de.www: P 6:8(2) ack 1 win 8198 <nop,nop,timestamp 63455198 63455017>
20:40:53.834274 IP laber-land.de.www > laber-land.de.40492: . ack 8 win 8192 <nop,nop,timestamp 63455198 63455198>
20:40:53.835207 IP laber-land.de.www > laber-land.de.40492: P 1:218(217) ack 8 win 8192 <nop,nop,timestamp 63455198 63455198>
20:40:53.835270 IP laber-land.de.40492 > laber-land.de.www: . ack 218 win 8198 <nop,nop,timestamp 63455198 63455198>
20:40:53.835693 IP laber-land.de.40492 > laber-land.de.www: P 8:11(3) ack 218 win 8198 <nop,nop,timestamp 63455199 63455198>
20:40:53.835877 IP laber-land.de.www > laber-land.de.40492: F 218:218(0) ack 11 win 8192 <nop,nop,timestamp 63455199 63455199>
20:40:53.836084 IP laber-land.de.40492 > laber-land.de.www: F 11:11(0) ack 219 win 8198 <nop,nop,timestamp 63455199 63455199>
20:40:53.836138 IP laber-land.de.www > laber-land.de.40492: . ack 12 win 8192 <nop,nop,timestamp 63455199 63455199>
20:40:54.127632 IP laber-land.de.42966 > laber-land.de.https: S 1206061665:1206061665(0) win 32792 <mss 16396,sackOK,timestamp 63455272 0,nop,wscale 2>
20:40:54.127697 IP laber-land.de.https > laber-land.de.42966: S 1199176351:1199176351(0) ack 1206061666 win 32768 <mss 16396,sackOK,timestamp 63455272 63455272,nop,wscale 2>
20:40:54.128148 IP laber-land.de.42966 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63455272 63455272>
20:40:54.128548 IP laber-land.de.42966 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63455272 63455272>
20:40:54.128628 IP laber-land.de.https > laber-land.de.42966: . ack 67 win 8192 <nop,nop,timestamp 63455272 63455272>
20:40:54.129655 IP laber-land.de.https > laber-land.de.42966: P 1:471(470) ack 67 win 8192 <nop,nop,timestamp 63455272 63455272>
20:40:54.129743 IP laber-land.de.https > laber-land.de.42966: F 471:471(0) ack 67 win 8192 <nop,nop,timestamp 63455272 63455272>
20:40:54.130332 IP laber-land.de.42966 > laber-land.de.https: . ack 471 win 8198 <nop,nop,timestamp 63455272 63455272>
20:40:54.130671 IP laber-land.de.42966 > laber-land.de.https: R 67:67(0) ack 472 win 8198 <nop,nop,timestamp 63455272 63455272>
20:40:55.135583 IP laber-land.de.42967 > laber-land.de.https: S 1204101502:1204101502(0) win 32792 <mss 16396,sackOK,timestamp 63455524 0,nop,wscale 2>
20:40:55.135647 IP laber-land.de.https > laber-land.de.42967: S 1196825664:1196825664(0) ack 1204101503 win 32768 <mss 16396,sackOK,timestamp 63455524 63455524,nop,wscale 2>
20:40:55.136110 IP laber-land.de.42967 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63455524 63455524>
20:40:55.136510 IP laber-land.de.42967 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63455524 63455524>
20:40:55.136587 IP laber-land.de.https > laber-land.de.42967: . ack 67 win 8192 <nop,nop,timestamp 63455524 63455524>
20:40:55.137018 IP laber-land.de.42967 > laber-land.de.https: F 67:67(0) ack 1 win 8198 <nop,nop,timestamp 63455524 63455524>
20:40:55.139361 IP laber-land.de.https > laber-land.de.42967: P 1:471(470) ack 68 win 8192 <nop,nop,timestamp 63455524 63455524>
20:40:55.139471 IP laber-land.de.42967 > laber-land.de.https: R 1204101570:1204101570(0) win 0
20:40:56.135591 IP laber-land.de.42968 > laber-land.de.https: S 1200170522:1200170522(0) win 32792 <mss 16396,sackOK,timestamp 63455774 0,nop,wscale 2>
20:40:56.135656 IP laber-land.de.https > laber-land.de.42968: S 1197798697:1197798697(0) ack 1200170523 win 32768 <mss 16396,sackOK,timestamp 63455774 63455774,nop,wscale 2>
20:40:56.136111 IP laber-land.de.42968 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63455774 63455774>
20:40:56.136511 IP laber-land.de.42968 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63455774 63455774>
20:40:56.136592 IP laber-land.de.https > laber-land.de.42968: . ack 67 win 8192 <nop,nop,timestamp 63455774 63455774>
20:40:56.137013 IP laber-land.de.42968 > laber-land.de.https: F 67:67(0) ack 1 win 8198 <nop,nop,timestamp 63455774 63455774>
20:40:56.138256 IP laber-land.de.https > laber-land.de.42968: P 1:471(470) ack 68 win 8192 <nop,nop,timestamp 63455774 63455774>
20:40:56.138339 IP laber-land.de.42968 > laber-land.de.https: R 1200170590:1200170590(0) win 0
^[[C^[[D20:43:44.141076 IP laber-land.de.42969 > laber-land.de.https: S 1371009477:1371009477(0) win 32792 <mss 16396,sackOK,timestamp 63497775 0,nop,wscale 2>
20:43:44.141140 IP laber-land.de.https > laber-land.de.42969: S 1371648365:1371648365(0) ack 1371009478 win 32768 <mss 16396,sackOK,timestamp 63497775 63497775,nop,wscale 2>
20:43:44.141384 IP laber-land.de.42969 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63497775 63497775>
20:43:44.141577 IP laber-land.de.42969 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63497775 63497775>
20:43:44.141644 IP laber-land.de.https > laber-land.de.42969: . ack 67 win 8192 <nop,nop,timestamp 63497775 63497775>
20:43:44.141867 IP laber-land.de.42969 > laber-land.de.https: F 67:67(0) ack 1 win 8198 <nop,nop,timestamp 63497775 63497775>
20:43:44.143368 IP laber-land.de.https > laber-land.de.42969: P 1:471(470) ack 68 win 8192 <nop,nop,timestamp 63497775 63497775>
20:43:44.143450 IP laber-land.de.42969 > laber-land.de.https: R 1371009545:1371009545(0) win 0
20:43:45.141052 IP laber-land.de.42970 > laber-land.de.https: S 1379139164:1379139164(0) win 32792 <mss 16396,sackOK,timestamp 63498025 0,nop,wscale 2>
20:43:45.141114 IP laber-land.de.https > laber-land.de.42970: S 1379412135:1379412135(0) ack 1379139165 win 32768 <mss 16396,sackOK,timestamp 63498025 63498025,nop,wscale 2>
20:43:45.141354 IP laber-land.de.42970 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63498025 63498025>
20:43:45.141538 IP laber-land.de.42970 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63498025 63498025>
20:43:45.141609 IP laber-land.de.https > laber-land.de.42970: . ack 67 win 8192 <nop,nop,timestamp 63498025 63498025>
20:43:45.141823 IP laber-land.de.42970 > laber-land.de.https: F 67:67(0) ack 1 win 8198 <nop,nop,timestamp 63498025 63498025>
20:43:45.143280 IP laber-land.de.https > laber-land.de.42970: P 1:471(470) ack 68 win 8192 <nop,nop,timestamp 63498025 63498025>
20:43:45.143365 IP laber-land.de.42970 > laber-land.de.https: R 1379139232:1379139232(0) win 0
20:43:46.141060 IP laber-land.de.42971 > laber-land.de.https: S 1379055381:1379055381(0) win 32792 <mss 16396,sackOK,timestamp 63498275 0,nop,wscale 2>
20:43:46.141121 IP laber-land.de.https > laber-land.de.42971: S 1371596084:1371596084(0) ack 1379055382 win 32768 <mss 16396,sackOK,timestamp 63498275 63498275,nop,wscale 2>
20:43:46.141578 IP laber-land.de.42971 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63498275 63498275>
20:43:46.141980 IP laber-land.de.42971 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63498275 63498275>
20:43:46.142063 IP laber-land.de.https > laber-land.de.42971: . ack 67 win 8192 <nop,nop,timestamp 63498275 63498275>
20:43:46.144359 IP laber-land.de.https > laber-land.de.42971: P 1:471(470) ack 67 win 8192 <nop,nop,timestamp 63498275 63498275>
20:43:46.144510 IP laber-land.de.https > laber-land.de.42971: F 471:471(0) ack 67 win 8192 <nop,nop,timestamp 63498275 63498275>
20:43:46.145263 IP laber-land.de.42971 > laber-land.de.https: . ack 471 win 8198 <nop,nop,timestamp 63498276 63498275>
20:43:46.145628 IP laber-land.de.42971 > laber-land.de.https: R 67:67(0) ack 472 win 8198 <nop,nop,timestamp 63498276 63498275>
20:43:56.149177 IP laber-land.de.42972 > laber-land.de.https: S 1391715398:1391715398(0) win 32792 <mss 16396,sackOK,timestamp 63500777 0,nop,wscale 2>
20:43:56.149243 IP laber-land.de.https > laber-land.de.42972: S 1392296252:1392296252(0) ack 1391715399 win 32768 <mss 16396,sackOK,timestamp 63500777 63500777,nop,wscale 2>
20:43:56.149751 IP laber-land.de.42972 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63500777 63500777>
20:43:56.150152 IP laber-land.de.42972 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63500777 63500777>
20:43:56.150234 IP laber-land.de.https > laber-land.de.42972: . ack 67 win 8192 <nop,nop,timestamp 63500777 63500777>
20:43:56.151699 IP laber-land.de.https > laber-land.de.42972: P 1:471(470) ack 67 win 8192 <nop,nop,timestamp 63500777 63500777>
20:43:56.151792 IP laber-land.de.https > laber-land.de.42972: F 471:471(0) ack 67 win 8192 <nop,nop,timestamp 63500777 63500777>
20:43:56.152414 IP laber-land.de.42972 > laber-land.de.https: . ack 471 win 8198 <nop,nop,timestamp 63500777 63500777>
20:43:56.152755 IP laber-land.de.42972 > laber-land.de.https: R 67:67(0) ack 472 win 8198 <nop,nop,timestamp 63500777 63500777>
20:43:57.157152 IP laber-land.de.42973 > laber-land.de.https: S 1381547020:1381547020(0) win 32792 <mss 16396,sackOK,timestamp 63501029 0,nop,wscale 2>
20:43:57.157215 IP laber-land.de.https > laber-land.de.42973: S 1380267561:1380267561(0) ack 1381547021 win 32768 <mss 16396,sackOK,timestamp 63501029 63501029,nop,wscale 2>
20:43:57.157676 IP laber-land.de.42973 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63501029 63501029>
20:43:57.158076 IP laber-land.de.42973 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63501029 63501029>
20:43:57.158158 IP laber-land.de.https > laber-land.de.42973: . ack 67 win 8192 <nop,nop,timestamp 63501029 63501029>
20:43:57.159199 IP laber-land.de.https > laber-land.de.42973: P 1:471(470) ack 67 win 8192 <nop,nop,timestamp 63501029 63501029>
20:43:57.159291 IP laber-land.de.https > laber-land.de.42973: F 471:471(0) ack 67 win 8192 <nop,nop,timestamp 63501029 63501029>
20:43:57.159881 IP laber-land.de.42973 > laber-land.de.https: . ack 471 win 8198 <nop,nop,timestamp 63501029 63501029>
20:43:57.160221 IP laber-land.de.42973 > laber-land.de.https: R 67:67(0) ack 472 win 8198 <nop,nop,timestamp 63501029 63501029>
Kann da irgendwer was mit anfangen? ;-)
Ah OK, hat wohl irgendwas mit https zu tun:
[root@laber-land pierre]# tcpdump -s0 -X -i lo
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on lo, link-type EN10MB (Ethernet), capture size 65535 bytes
21:04:06.631599 IP laber-land.de.52529 > laber-land.de.https: S 2656484577:2656484577(0) win 32792 <mss 16396,sackOK,timestamp 63803395 0,nop,wscale 2>
0x0000: 4500 003c 2ce2 4000 4006 0fd8 7f00 0001 E..<,.@.@.......
0x0010: 7f00 0001 cd31 01bb 9e56 bce1 0000 0000 .....1...V......
0x0020: a002 8018 d19c 0000 0204 400c 0402 080a ..........@.....
0x0030: 03cd 9003 0000 0000 0103 0302 ............
21:04:06.631665 IP laber-land.de.https > laber-land.de.52529: S 2664791350:2664791350(0) ack 2656484578 win 32768 <mss 16396,sackOK,timestamp 63803395 63803395,nop,wscale 2>
0x0000: 4500 003c 0000 4000 4006 3cba 7f00 0001 E..<..@.@.<.....
0x0010: 7f00 0001 01bb cd31 9ed5 7d36 9e56 bce2 .......1..}6.V..
0x0020: a012 8000 21c7 0000 0204 400c 0402 080a ....!.....@.....
0x0030: 03cd 9003 03cd 9003 0103 0302 ............
21:04:06.633049 IP laber-land.de.52529 > laber-land.de.https: . ack 1 win 8198 <nop,nop,timestamp 63803395 63803395>
0x0000: 4500 0034 2ce3 4000 4006 0fdf 7f00 0001 E..4,.@.@.......
0x0010: 7f00 0001 cd31 01bb 9e56 bce2 9ed5 7d37 .....1...V....}7
0x0020: 8010 2006 eae0 0000 0101 080a 03cd 9003 ................
0x0030: 03cd 9003 ....
21:04:06.633541 IP laber-land.de.52529 > laber-land.de.https: P 1:67(66) ack 1 win 8198 <nop,nop,timestamp 63803395 63803395>
0x0000: 4500 0076 2ce4 4000 4006 0f9c 7f00 0001 E..v,.@.@.......
0x0010: 7f00 0001 cd31 01bb 9e56 bce2 9ed5 7d37 .....1...V....}7
0x0020: 8018 2006 fe6a 0000 0101 080a 03cd 9003 .....j..........
0x0030: 03cd 9003 4745 5420 2f20 4854 5450 2f31 ....GET./.HTTP/1
0x0040: 2e30 0d0a 5573 6572 2d41 6765 6e74 3a20 .0..User-Agent:.
0x0050: 4170 6163 6865 2028 696e 7465 726e 616c Apache.(internal
0x0060: 2064 756d 6d79 2063 6f6e 6e65 6374 696f .dummy.connectio
0x0070: 6e29 0d0a 0d0a n)....
21:04:06.633620 IP laber-land.de.https > laber-land.de.52529: . ack 67 win 8192 <nop,nop,timestamp 63803395 63803395>
0x0000: 4500 0034 ed34 4000 4006 4f8d 7f00 0001 E..4.4@.@.O.....
0x0010: 7f00 0001 01bb cd31 9ed5 7d37 9e56 bd24 .......1..}7.V.$
0x0020: 8010 2000 eaa4 0000 0101 080a 03cd 9003 ................
0x0030: 03cd 9003 ....
21:04:06.635244 IP laber-land.de.https > laber-land.de.52529: P 1:471(470) ack 67 win 8192 <nop,nop,timestamp 63803395 63803395>
0x0000: 4500 020a ed35 4000 4006 4db6 7f00 0001 E....5@.@.M.....
0x0010: 7f00 0001 01bb cd31 9ed5 7d37 9e56 bd24 .......1..}7.V.$
0x0020: 8018 2000 fffe 0000 0101 080a 03cd 9003 ................
0x0030: 03cd 9003 3c21 444f 4354 5950 4520 4854 ....<!DOCTYPE.HT
0x0040: 4d4c 2050 5542 4c49 4320 222d 2f2f 4945 ML.PUBLIC."-//IE
0x0050: 5446 2f2f 4454 4420 4854 4d4c 2032 2e30 TF//DTD.HTML.2.0
0x0060: 2f2f 454e 223e 0a3c 6874 6d6c 3e3c 6865 //EN">.<html><he
0x0070: 6164 3e0a 3c74 6974 6c65 3e34 3030 2042 ad>.<title>400.B
0x0080: 6164 2052 6571 7565 7374 3c2f 7469 746c ad.Request</titl
0x0090: 653e 0a3c 2f68 6561 643e 3c62 6f64 793e e>.</head><body>
0x00a0: 0a3c 6831 3e42 6164 2052 6571 7565 7374 .<h1>Bad.Request
0x00b0: 3c2f 6831 3e0a 3c70 3e59 6f75 7220 6272 </h1>.<p>Your.br
0x00c0: 6f77 7365 7220 7365 6e74 2061 2072 6571 owser.sent.a.req
0x00d0: 7565 7374 2074 6861 7420 7468 6973 2073 uest.that.this.s
0x00e0: 6572 7665 7220 636f 756c 6420 6e6f 7420 erver.could.not.
0x00f0: 756e 6465 7273 7461 6e64 2e3c 6272 202f understand.<br./
0x0100: 3e0a 5265 6173 6f6e 3a20 596f 7527 7265 >.Reason:.You're
0x0110: 2073 7065 616b 696e 6720 706c 6169 6e20 .speaking.plain.
0x0120: 4854 5450 2074 6f20 616e 2053 534c 2d65 HTTP.to.an.SSL-e
0x0130: 6e61 626c 6564 2073 6572 7665 7220 706f nabled.server.po
0x0140: 7274 2e3c 6272 202f 3e0a 496e 7374 6561 rt.<br./>.Instea
0x0150: 6420 7573 6520 7468 6520 4854 5450 5320 d.use.the.HTTPS.
0x0160: 7363 6865 6d65 2074 6f20 6163 6365 7373 scheme.to.access
0x0170: 2074 6869 7320 5552 4c2c 2070 6c65 6173 .this.URL,.pleas
0x0180: 652e 3c62 7220 2f3e 0a3c 626c 6f63 6b71 e.<br./>.<blockq
0x0190: 756f 7465 3e48 696e 743a 203c 6120 6872 uote>Hint:.<a.hr
0x01a0: 6566 3d22 6874 7470 733a 2f2f 6164 6d69 ef="https://admi
0x01b0: 6e2e 6c61 6265 722d 6c61 6e64 2e64 652f n.laber-land.de/
0x01c0: 223e 3c62 3e68 7474 7073 3a2f 2f61 646d "><b>https://adm
0x01d0: 696e 2e6c 6162 6572 2d6c 616e 642e 6465 in.laber-land.de
0x01e0: 2f3c 2f62 3e3c 2f61 3e3c 2f62 6c6f 636b /</b></a></block
0x01f0: 7175 6f74 653e 3c2f 703e 0a3c 2f62 6f64 quote></p>.</bod
0x0200: 793e 3c2f 6874 6d6c 3e0a y></html>.
21:04:06.635335 IP laber-land.de.https > laber-land.de.52529: F 471:471(0) ack 67 win 8192 <nop,nop,timestamp 63803395 63803395>
0x0000: 4500 0034 ed36 4000 4006 4f8b 7f00 0001 E..4.6@.@.O.....
0x0010: 7f00 0001 01bb cd31 9ed5 7f0d 9e56 bd24 .......1.....V.$
0x0020: 8011 2000 e8cd 0000 0101 080a 03cd 9003 ................
0x0030: 03cd 9003 ....
21:04:06.636441 IP laber-land.de.52529 > laber-land.de.https: . ack 471 win 8198 <nop,nop,timestamp 63803396 63803395>
0x0000: 4500 0034 2ce5 4000 4006 0fdd 7f00 0001 E..4,.@.@.......
0x0010: 7f00 0001 cd31 01bb 9e56 bd24 9ed5 7f0d .....1...V.$....
0x0020: 8010 2006 e8c7 0000 0101 080a 03cd 9004 ................
0x0030: 03cd 9003 ....
21:04:06.636869 IP laber-land.de.52529 > laber-land.de.https: R 67:67(0) ack 472 win 8198 <nop,nop,timestamp 63803396 63803395>
0x0000: 4500 0034 2ce6 4000 4006 0fdc 7f00 0001 E..4,.@.@.......
0x0010: 7f00 0001 cd31 01bb 9e56 bd24 9ed5 7f0e .....1...V.$....
0x0020: 8014 2006 e8c2 0000 0101 080a 03cd 9004 ................
0x0030: 03cd 9003 ....
Interessant ist:
0x0050: 4170 6163 6865 2028 696e 7465 726e 616c Apache.(internal
0x0060: 2064 756d 6d79 2063 6f6e 6e65 6374 696f .dummy.connectio
0x0070: 6e29 0d0a 0d0a n)....
Scheinbar ist das kein Angriff und ich habe nur bei der SSL-Konfiguration irgendwie Mist gebaut :-)
Powered by vBulletin® Version 4.2.5 Copyright ©2024 Adduco Digital e.K. und vBulletin Solutions, Inc. Alle Rechte vorbehalten.