1 1.1.1.2 christos 1 2016-11-30 15:35:08.640523 IP (tos 0x0, ttl 128, id 376, offset 0, flags [DF], proto TCP (6), length 128) 2 1.1 christos 192.168.56.55.445 > 192.168.56.119.49199: Flags [P.], cksum 0x3e2f (incorrect -> 0x3d49), seq 4267808374:4267808462, ack 628292694, win 63102, length 88 3 1.1 christos SMB PACKET: SMBtrans2 (REPLY) 4 1.1 christos SMB Command = 0x32 5 1.1 christos Error class = 0x0 6 1.1 christos Error code = 0 (0x0) 7 1.1 christos Flags1 = 0xFF 8 1.1 christos Flags2 = 0x7 9 1.1 christos Tree ID = 2048 (0x800) 10 1.1 christos Proc ID = 2848 (0xb20) 11 1.1 christos UID = 4098 (0x1002) 12 1.1 christos MID = 1616 (0x650) 13 1.1 christos Word Count = 10 (0xa) 14 1.1 christos TRANSACT2_OPEN param_length=2 data_length=24 15 1.1 christos TotParam=2 (0x2) 16 1.1 christos TotData=24 (0x18) 17 1.1 christos Res1=0x0 18 1.1 christos ParamCnt=2 (0x2) 19 1.1 christos ParamOff=56 (0x38) 20 1.1 christos ParamDisp0 (0x0) 21 1.1 christos DataCnt=24 (0x18) 22 1.1 christos DataOff=60 (0x3c) 23 1.1 christos DataDisp=0 (0x0) 24 1.1 christos SetupCnt=0 (0x0) 25 1.1 christos smb_bcc=29 26 1.1 christos Handle=0 (0x0) 27 1.1 christos Attrib=Data= 28 1.1 christos Data: (24 bytes) 29 1.1 christos [000] 00 00 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 ^@^@^K^@^@^@^@^@ ^@^@^@^@^@^@^@^@ 30 1.1 christos [010] 01 00 00 00 00 00 00 00 ^A^@^@^@^@^@^@^@ 31 1.1 christos 32 1.1.1.2 christos 2 2016-11-30 15:35:08.640906 IP (tos 0x0, ttl 128, id 632, offset 0, flags [DF], proto TCP (6), length 114) 33 1.1 christos 192.168.56.119.49199 > 192.168.56.55.445: Flags [P.], cksum 0x2437 (correct), seq 1:75, ack 88, win 254, length 74 34 1.1 christos SMB PACKET: SMBtrans2 (REQUEST) 35 1.1 christos SMB Command = 0x32 36 1.1 christos Error class = 0x0 37 1.1 christos Error code = 0 (0x0) 38 1.1 christos Flags1 = 0x18 39 1.1 christos Flags2 = 0x7 40 1.1 christos Tree ID = 2048 (0x800) 41 1.1 christos Proc ID = 2848 (0xb20) 42 1.1 christos UID = 4098 (0x1002) 43 1.1 christos MID = 1632 (0x660) 44 1.1 christos Word Count = 15 (0xf) 45 1.1 christos TRANSACT2_QFSINFO param_length=2 data_length=0 46 1.1 christos TotParam=2 (0x2) 47 1.1 christos TotData=0 (0x0) 48 1.1 christos MaxParam=0 (0x0) 49 1.1 christos MaxData=560 (0x230) 50 1.1 christos MaxSetup=0 (0x0) 51 1.1 christos Flags=0x0 52 1.1 christos TimeOut=0 (0x0) 53 1.1 christos Res1=0x0 54 1.1 christos ParamCnt=2 (0x2) 55 1.1 christos ParamOff=68 (0x44) 56 1.1 christos DataCnt=0 (0x0) 57 1.1 christos DataOff=0 (0x0) 58 1.1 christos SetupCnt=1 (0x1) 59 1.1 christos smb_bcc=5 60 1.1 christos InfoLevel=261 (0x105) 61 1.1 christos 62 1.1.1.2 christos 3 2016-11-30 15:35:08.641033 IP (tos 0x0, ttl 128, id 377, offset 0, flags [DF], proto TCP (6), length 120) 63 1.1 christos 192.168.56.55.445 > 192.168.56.119.49199: Flags [P.], cksum 0xf1fb (incorrect -> 0x1559), seq 88:168, ack 75, win 63028, length 80 64 1.1 christos SMB PACKET: SMBtrans2 (REPLY) 65 1.1 christos SMB Command = 0x32 66 1.1 christos Error class = 0x0 67 1.1 christos Error code = 0 (0x0) 68 1.1 christos Flags1 = 0x98 69 1.1 christos Flags2 = 0x7 70 1.1 christos Tree ID = 0 (0x0) 71 1.1 christos Proc ID = 0 (0x0) 72 1.1 christos UID = 0 (0x0) 73 1.1 christos MID = 0 (0x0) 74 1.1 christos Word Count = 11 (0xb) 75 1.1 christos TRANSACT2_QFSINFO param_length=0 data_length=20 76 1.1 christos TotParam=0 (0x0) 77 1.1 christos TotData=0 (0x0) 78 1.1 christos Res1=0x0 79 1.1 christos ParamCnt=0 (0x0) 80 1.1 christos ParamOff=56 (0x38) 81 1.1 christos ParamDisp0 (0x0) 82 1.1 christos DataCnt=20 (0x14) 83 1.1 christos DataOff=56 (0x38) 84 1.1 christos DataDisp=0 (0x0) 85 1.1 christos SetupCnt=0 (0x0) 86 1.1 christos smb_bcc=65280 87 1.1 christos Capabilities=0x700FF 88 1.1 christos MaxFileLen=255 (0xff) 89 1.1 christos VolNameLen=4278190088 90 1.1 christos Volume=... [|smb] 91 1.1 christos data: 92 1.1 christos [000] FF 00 07 00 FF 00 00 00 08 00 00 FF FF FF FF 00 M-^?^@^G^@M-^?^@^@^@ ^H^@^@M-^?M-^?M-^?M-^?^@ 93 1.1 christos [010] 46 00 53 00 F^@S^@ 94 1.1 christos 95 1.1.1.2 christos 4 2038-01-01 00:00:00.000000 IP (tos 0x0, ttl 128, id 633, offset 0, flags [DF], proto TCP (6), length 116) 96 1.1 christos 192.168.56.119.49199 > 192.168.56.55.445: Flags [P.], cksum 0x2253 (incorrect -> 0x229b), seq 75:151, ack 168, win 253, length 76 SMB-over-TCP packet:(raw data or continuation?) 97 1.1 christos 98