Security Basics mailing list archives

keepalive message or not?


From: "SB CH" <chulmin2 () hotmail com>
Date: Thu, 17 Oct 2002 03:28:35 +0000


Hello all.

I remote connected my server using ssh and executed like this.

# tcpdump tcp
and I can see so lots of packets like this.

12:24:08.901473 eth0 < client.com.2157 > www.server.com.ssh: P 2801:2841(40) ack 13496 win 16736 (DF) 12:24:08.901481 eth0 < client.com.2157 > www.server.com.ssh: P 2801:2841(40) ack 13496 win 16736 (DF) 12:24:08.901483 eth0 < client.com.2157 > www.server.com.ssh: P 2801:2841(40) ack 13496 win 16736 (DF) 12:24:08.901492 eth0 < client.com.2157 > www.server.com.ssh: P 2801:2841(40) ack 13496 win 16736 (DF) 12:24:08.901498 eth0 < client.com.2157 > www.server.com.ssh: P 2801:2841(40) ack 13496 win 16736 (DF)

* client.com is my pc name.

Surely, I didn't do anything except ssh login and  just tcpdump.

Is this a keepalive message or not?

Please let me know the meaning about this message.

Thanks in advance.

_________________________________________________________________
증권 정보 가장 빠르고 편하게 보실 수 있습니다. MSN 증권/투자 http://www.msn.co.kr/stock/

Current thread: