fennec72_MbkM3Max@MacBook-Pro-de-Herve ~ % sudo tcpdump host 192.168.1.119 -A
Password:
tcpdump: data link type PKTAP
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on pktap, link-type PKTAP (Apple DLT_PKTAP), snapshot length 524288 bytes
22:53:07.791242 IP 192.168.1.119.41450 > 192.168.1.122.netbios-ssn: Flags [S], seq 867382334, win 64240, options [mss 1460,sackOK,TS val 2628188136 ecr 0,nop,wscale 7], length 0
E..<..@[email protected]>........)..........
............
22:53:07.791273 ARP, Request who-has 192.168.1.119 (7c:c3:a1:71:84:e1 (oui Unknown)) tell 192.168.1.122, length 28
........`>[email protected]|..q.....w
22:53:07.791290 IP 192.168.1.122.netbios-ssn > 192.168.1.119.41450: Flags [R.], seq 0, ack 867382335, win 0, length 0
E..(..@[email protected]?P...!'..
22:53:07.799710 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [S], seq 2138595983, win 64240, options [mss 1460,sackOK,TS val 2628188148 ecr 0,nop,wscale 7], length 0
E..<q.@[email protected]....................
............
22:53:07.799711 ARP, Reply 192.168.1.119 is-at 7c:c3:a1:71:84:e1 (oui Unknown), length 28
........|..q.....w`>[email protected]
22:53:07.799940 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [S.], seq 1800104916, ack 2138595984, win 65535, options [mss 1460,nop,wscale 6,nop,nop,TS val 4180430721 ecr 2628188148,sackOK,eol], length 0
E..@..@[email protected]....................
.,O.........
22:53:07.805766 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [.], ack 1, win 502, options [nop,nop,TS val 2628188154 ecr 4180430721], length 0
E..4q.@[email protected].....
.....,O.
22:53:07.805766 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [P.], seq 1:265, ack 1, win 502, options [nop,nop,TS val 2628188155 ecr 4180430721], length 264
E..<q.@[email protected]............
.....,O......SMB@...........................................................$...........X.L x.HB.I..[.eip.....................&....... ......E..........L.+..p.....i.^tT......
.......................................4.....m.a.c.b.o.o.k.-.p.r.o.-.d.e.-.h.e.r.v.e...l.o.c.a.l.
22:53:07.805790 IP 192.168.1.119.41460 > 192.168.1.122.netbios-ssn: Flags [S], seq 346256029, win 64240, options [mss 1460,sackOK,TS val 2628188153 ecr 0,nop,wscale 7], length 0
E..<..@.@..|...w...z......r.........
m.........
............
22:53:07.805802 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [.], ack 265, win 2010, options [nop,nop,TS val 4180430727 ecr 2628188155], length 0
E..4..@[email protected].....
.,O.....
22:53:07.805807 IP 192.168.1.122.netbios-ssn > 192.168.1.119.41460: Flags [R.], seq 0, ack 346256030, win 0, length 0
E..(..@[email protected].......
22:53:07.970061 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [P.], seq 1:261, ack 265, win 2048, options [nop,nop,TS val 4180430891 ecr 2628188155], length 260
E..8..@.@..~...z...w....kKk..xc..... v.....
.,P+.........SMB@...........................................................A.......\s..m.\Z.T..y.s.f.....@...@[email protected][.MK..................`~..+......t0r.D0B.*.H....... *.H........*.p+....+......
+.....7..
..+.......+......*0(.&.$not_defined_in_RFC4178@please_ignore
22:53:08.082935 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [P.], seq 1:261, ack 265, win 2048, options [nop,nop,TS val 4180431004 ecr 2628188155], length 260
E..8..@.@..~...z...w....kKk..xc..... ......
.,P..........SMB@...........................................................A.......\s..m.\Z.T..y.s.f.....@...@[email protected][.MK..................`~..+......t0r.D0B.*.H....... *.H........*.p+....+......
+.....7..
..+.......+......*0(.&.$not_defined_in_RFC4178@please_ignore
22:53:08.085565 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [.], ack 261, win 501, options [nop,nop,TS val 2628188434 ecr 4180430891], length 0
E..4q.@[email protected]............
.....,P+
22:53:08.085566 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [P.], seq 265:431, ack 261, win 501, options [nop,nop,TS val 2628188435 ecr 4180430891], length 166
E...q.@[email protected]............
.....,P+.....SMB@.......................................................................X.J.........`H..+......>0<..0..
+.....7..
.*.(NTLMSSP........b....(.......(...........
22:53:08.085604 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [.], ack 431, win 2045, options [nop,nop,TS val 4180431007 ecr 2628188435], length 0
E..4..@[email protected]>.....v.....
.,P.....
22:53:08.091325 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [.], ack 261, win 501, options [nop,nop,TS val 2628188441 ecr 4180431004,nop,nop,sack 1 {1:261}], length 0
E..@q.@[email protected]>kKl............
.....,P....
kKk.kKl.
22:53:08.107381 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [P.], seq 261:599, ack 431, win 2048, options [nop,nop,TS val 4180431029 ecr 2628188441], length 338
E.....@[email protected]>....x......
.,[email protected]._................. ...H.......0....
.....
+.....7..
......NTLMSSP.........8...5..b.....n.p............L...........M.A.C.-.4.0.C.B.1.7...(.M.A.C.B.O.O.K.-.P.R.O.-.D.E.-.H.E.R.V.E.....M.A.C.-.4.0.C.B.1.7...4.M.a.c.B.o.o.k.-.P.r.o.-.d.e.-.H.e.r.v.e...l.o.c.a.l...
.l.o.c.a.l......z..MK......
22:53:08.114257 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [.], ack 599, win 501, options [nop,nop,TS val 2628188462 ecr 4180431029], length 0
E..4q.@[email protected]>kKn+...........
.....,P.
22:53:08.115139 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [P.], seq 431:1135, ack 599, win 501, options [nop,nop,TS val 2628188463 ecr 4180431029], length 704
E...r.@[email protected]>kKn+.....6.....
.../.,[email protected]._.............................X.d............`0..\[email protected]...&.&.............$.$.........0......b........l...7e.mm..S.~. ............................. G.w..K.,.f.........z..MK......\L........(.M.A.C.B.O.O.K.-.P.R.O.-.D.E.-.H.E.R.V.E.....M.A.C.-.4.0.C.B.1.7...4.M.a.c.B.o.o.k.-.P.r.o.-.d.e.-.H.e.r.v.e...l.o.c.a.l...
.l.o.c.a.l......z..MK............0.0...............}.y.Q..0.9........P.B}.'U.v.o...
................... .>.c.i.f.s./.m.a.c.b.o.o.k.-.p.r.o.-.d.e.-.h.e.r.v.e...l.o.c.a.l.....S.M.B.:././.1.9.2...1.6.8...1...1.2.2.H.e.r.v... .L.e. .D.a.n.t.e.c.H.E.R.V.E.-.M.A.C.M.I.N.I.Z.O.R.I.N....S.6..
7..................N..{....
22:53:08.115173 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [.], ack 1135, win 2037, options [nop,nop,TS val 4180431036 ecr 2628188463], length 0
E..4..@[email protected]+.xf......3.....
.,P..../
22:53:08.116312 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [P.], seq 599:676, ack 1135, win 2048, options [nop,nop,TS val 4180431038 ecr 2628188463], length 77
E.....@[email protected]+.xf............
.,P..../[email protected]._................. ........
22:53:08.120599 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [F.], seq 1135, ack 676, win 501, options [nop,nop,TS val 2628188470 ecr 4180431038], length 0
E..4r.@[email protected]...........
...6.,P.
22:53:08.120642 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [.], ack 1136, win 2048, options [nop,nop,TS val 4180431042 ecr 2628188470], length 0
E..4..@[email protected]............
.,P....6
22:53:08.120834 IP 192.168.1.122.microsoft-ds > 192.168.1.119.34280: Flags [F.], seq 676, ack 1136, win 2048, options [nop,nop,TS val 4180431042 ecr 2628188470], length 0
E..4..@[email protected]............
.,P....6
22:53:08.126416 IP 192.168.1.119.34280 > 192.168.1.122.microsoft-ds: Flags [.], ack 677, win 501, options [nop,nop,TS val 2628188476 ecr 4180431042], length 0
E..4..@[email protected]...........
...<.,P.
22:53:11.010876 IP 192.168.1.119.17500 > broadcasthost.17500: UDP, length 407
E...w.@[email protected]\D\....{"version": [2, 0], "port": 17500, "host_int": 301322645095660830451549060616859220241, "displayname": "",