Imperva block analyze

 

1)客戶端抓包信息  服務器

三次握手 ide

13:32:15.998245 180.168.xxx.xxx.3942 > 172.16.8.14.http: S 3786149313:3786149313(0) win 4380 <mss 1460,nop,wscale 0,sackOK,eol> (DF) this

13:32:15.998678 172.16.8.14.http > 180.168.xxx.xxx.3942: S 2800298907:2800298907(0) ack 3786149314 win 5840 <mss 1460,nop,nop,sackOK,nop,wscale 9> (DF) spa

13:32:15.998685 180.168.xxx.xxx.3942 > 172.16.8.14.http: . ack 1 win 4380 (DF) orm

 

客戶端發送不符合規則的HTTP REQUEST blog

13:32:15.998691 180.168.xxx.xxx.3942 > 172.16.8.14.http: P 1:800(799) ack 1 win 4380 (DF) ci

 

Imperva block後,imperva會代替服務器發送錯誤頁面,而且帶有FIN標誌,要求關閉此鏈接 get

13:32:15.999654 172.16.8.14.http > 180.168.xxx.xxx.3942: FP 1:565(564) ack 800 win 5840 (DF) it

客戶端看到的信息: io

 

客戶端收到imperva發送的FIN包後,發送確認的ack包,確認接收到的FIN請求

13:32:15.999671 180.168.xxx.xxx.3942 > 172.16.8.14.http: . ack 566 win 4944 (DF)

 

服務器收到客戶端的確認的ack包,服務器以前被髮送RESET包,因此發生icmp迴應,類型3,代碼10,表示目標主機被強制禁止,

13:32:16.000386 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

客戶端TCP重傳FIN

13:32:16.018214 180.168.xxx.xxx.3942 > 172.16.8.14.http: F 800:800(0) ack 566 win 4944 (DF)

 

13:32:16.018941 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

客戶端TCP重傳FIN

13:32:17.217440 180.168.xxx.xxx.3942 > 172.16.8.14.http: F 800:800(0) ack 566 win 4944 (DF)

 

13:32:17.217690 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

客戶端TCP重傳FIN

13:32:19.417414 180.168.xxx.xxx.3942 > 172.16.8.14.http: F 800:800(0) ack 566 win 4944 (DF)

13:32:19.417660 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

客戶端TCP重傳FIN

13:32:23.617405 180.168.xxx.xxx.3942 > 172.16.8.14.http: F 800:800(0) ack 566 win 4944 (DF)

13:32:23.617652 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

客戶端TCP重傳FIN

13:32:31.817678 180.168.xxx.xxx.3942 > 172.16.8.14.http: F 800:800(0) ack 566 win 4944 (DF)

13:32:31.817930 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

WINDOWS默認的客戶端TCP重傳次數爲5次,發送RESET包,重置鏈接

13:32:40.078809 180.168.xxx.xxx.3942 > 172.16.8.14.http: R 801:801(0) ack 566 win 4944 (DF)

 

13:32:40.079231 172.16.8.14 > 180.168.xxx.xxx: icmp: host 172.16.8.14 unreachable - admin prohibited [tos 0xc0]

 

2)服務器抓包信息

三次握手

13:32:15.999401 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: S 3786149313:3786149313(0) win 4380 <mss 1460,nop,wscale 0,sackOK,eol>

13:32:15.999509 IP 172.16.8.14.http > 180.168.xxx.xxx.srdp: S 2800298907:2800298907(0) ack 3786149314 win 5840 <mss 1460,nop,nop,sackOK,nop,wscale 9>

13:32:15.999842 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: . ack 1 win 4380

 

Imperva block後,imperva會代替客戶端向服務器發送reset包,重置此鏈接

13:32:16.000343 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: R 1:1(0) ack 1 win 4380

 

客戶端收到imperva發送的FIN包後,發送確認的ack包,確認接收到的FIN請求

13:32:16.000990 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: . ack 566 win 4944

 

13:32:16.001011 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

 

客戶端TCP重傳FIN

13:32:16.019413 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: F 800:800(0) ack 566 win 4944

 

13:32:16.019424 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

 

客戶端TCP重傳FIN

13:32:17.218344 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: F 800:800(0) ack 566 win 4944

13:32:17.218365 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

 

客戶端TCP重傳FIN

13:32:19.418370 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: F 800:800(0) ack 566 win 4944

13:32:19.418396 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

 

客戶端TCP重傳FIN

13:32:23.618343 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: F 800:800(0) ack 566 win 4944

13:32:23.618363 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

 

客戶端TCP重傳FIN

13:32:31.818658 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: F 800:800(0) ack 566 win 4944

13:32:31.818685 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

 

WINDOWS默認的客戶端TCP重傳次數爲5次,發送RESET包,重置鏈接

13:32:40.079904 IP 180.168.xxx.xxx.srdp > 172.16.8.14.http: R 801:801(0) ack 566 win 4944

 

13:32:40.079930 IP 172.16.8.14 > 180.168.xxx.xxx: ICMP host 172.16.8.14 unreachable - admin prohibited, length 48

相關文章
相關標籤/搜索