hi
i have captured dump of a client accessing a webserver.What i don't
understand
is lines 4 to 7 ( i have put arrows ). why is the client machine
setting the
"P"(ush) flag ?? and why is the webserver setting the flag as well??
any help is appreciated thanks..
.......
client_machine.2967 > webserver.www: S 1703314630:1703314630(0) win
16384 <mss 1460,nop,nop,sackOK> (DF)
webserver.www > client_machine.2967: S 3872603931:3872603931(0) ack
1793314621 win 5840 <mss 1460,nop,nop,sackOK> (DF)
client_machine.2967 > webserver.www: . ack 1 win 17520 (DF)
client_machine.2967 > webserver.www: P 1:28(27) ack 1 win 17520 (DF)
<-------
webserver.www > client_machine.2967: . ack 28 win 5840 (DF)
webserver.www > client_machine.2967: P 1:848(847) ack 28 win 5840 (DF)
webserver.www > client_machine.2967: F 848:848(0) ack 28 win 5840 (DF)
<------
client_machine.2967 > webserver.www: . ack 849 win 16673 (DF)
client_machine.2967 > webserver.www: F 28:28(0) ack 849 win 16673 (DF)
webserver.www > client_machine.2967: . ack 29 win 5840 (DF)
client_machine.2970 > webserver.www: S 989305384:989305384(0) win
16384 <mss 1460,nop,nop,sackOK> (DF)
webserver.www > client_machine.2970: S 3914599614:3914599614(0) ack
989304385 win 5840 <mss 1460,nop,nop,sackOK> (DF)
client_machine.2970 > webserver.www: . ack 1 win 17520 (DF)
client_machine.2970 > webserver.www: P 1:28(27) ack 1 win 17520 (DF)
webserver.www > client_machine.2970: . ack 28 win 5840 (DF)
webserver.www > client_machine.2970: P 1:848(847) ack 28 win 5840 (DF)
webserver.www > client_machine.2970: F 848:848(0) ack 28 win 5840 (DF)
client_machine.2970 > webserver.www: . ack 849 win 16673 (DF)
client_machine.2970 > webserver.www: F 28:28(0) ack 849 win 16673 (DF)
webserver.www > client_machine.2970: . ack 29 win 5840 (DF)
|