packet:
Code:
16:48:08.192205 192.168.0.2.1119 > eqzone-63-24.3035: [udp sum ok] udp 10 (ttl 128, id 12853, len 38)
0x0000 4500 0026 3235 0000 8011 7137 c0a8 0002 E..&25....q7....
0x0010 4025 968b 045f 0bdb 0012 4b5c 0004 d42b @%..._....K\...+
0x0020 f94b fd1c 4240 4240 4240 4240 4240 .K..B@B@B@B@B@
ipv4 header: (20 bytes long, as indicated by the low nibble of the first byte which is multiplied by 4, 5*4 = 20 bytes). Protocol is 11 (byte 0x9), so the data will be a udp packet. For other info about the header, look up its struct, and remember that network byte order is big endian.
Code:
16:48:08.192205 192.168.0.2.1119 > eqzone-63-24.3035: [udp sum ok] udp 10 (ttl 128, id 12853, len 38)
0x0000 4500 0026 3235 0000 8011 7137 c0a8 0002 E..&25....q7....
0x0010 4025 968b xxxx xxxx xxxx xxxx xxxx xxxx @%..._....K\...+
0x0020 xxxx xxxx xxxx xxxx xxxx xxxx xxxx .K..B@B@B@B@B@
udp header, 8 bytes. just src and dest ports, length and a checksum.
Code:
16:48:08.192205 192.168.0.2.1119 > eqzone-63-24.3035: [udp sum ok] udp 10 (ttl 128, id 12853, len 38)
0x0000 xxxx xxxx xxxx xxxx xxxx xxxx xxxx xxxx E..&25....q7....
0x0010 xxxx xxxx 045f 0bdb 0012 4b5c xxxx xxxx @%..._....K\...+
0x0020 xxxx xxxx xxxx xxxx xxxx xxxx xxxx .K..B@B@B@B@B@
udp data, this is the everquest data.
Code:
16:48:08.192205 192.168.0.2.1119 > eqzone-63-24.3035: [udp sum ok] udp 10 (ttl 128, id 12853, len 38)
0x0000 xxxx xxxx xxxx xxxx xxxx xxxx xxxx xxxx E..&25....q7....
0x0010 xxxx xxxx xxxx xxxx xxxx xxxx 0004 d42b @%..._....K\...+
0x0020 f94b fd1c 4240 4240 4240 4240 4240 .K..B@B@B@B@B@