FTPS(FTP+SSL)
# _7 L7 K$ A3 A1 e; @# o& w- m3 I4 x P0 D
ftps是一种多传输协议,相当于加密版的FTP。当你在FTP服务器上收发文件的时候,你面临两个风险。第一个风险是在上载文件的时候为文件加密。第二个风险是,这些文件在你等待接收方下载的时候将停留在FTP服务器上,这时你如何保证这些文件的安全。你的第二个选择(创建一个支持SSL的FTP服务器)能够让你的主机使用一个FTPS连接上载这些文件。这包括使用一个在FTP协议下面的SSL层加密控制和数据通道。一种替代FTPS的协议是安全文件传输协议(SFTP)。这个协议使用SSH文件传输协议加密从客户机到服务器的FTP连接。
5 c3 [) x$ W' ~5 o
: ]; V( E* A. }3 e- R
3 G; R' \7 y/ x! T0 ]& cFTPS是在安全套接层使用标准的FTP协议和指令的一种增强型TFP协议,为FTP协议和数据通道增加了SSL安全功能。FTPS也称作“FTP-SSL”和“FTP-over-SSL”。SSL是一个在客户机和具有SSL功能的服务器之间的安全连接中对数据进行加密和解密的协议。* b, B. r( ?) Y6 w- `9 S
. B, i0 l/ L. \
) y( M% E( H+ X- q& y# x4 ^3 [; N1 q
和sftp连接方法类似,在windows中可以使用FileZilla等传输软件来连接FTPS进行上传,下载文件,建立,删除目录等操作,在FileZilla连接时,有显式和隐式TLS/SSL连接之分,连接时也有指纹提示。' D$ V( L. n1 s9 c, ^
P' s7 L. X& Z$ k% B$ u 8 n3 _; A; m/ T5 D0 u4 F1 o/ W
- t+ r* e! Y+ ?% C- _安全:ftps ftp+ssl
- U% i6 t4 G% {; K, P, u4 I3 L. y" Q$ P
准备工作:
) s/ u0 P0 Z# g, t
" o( o2 |5 Q1 Y9 o/ @7 J4 O1 }" h准备一:关闭防火墙;
. m5 R/ N' o/ W/ u, }- H8 C+ q# ~% b. l- r8 R
准备二:挂载光盘;# b* {" ~8 C4 I; j r f6 m
/ H$ Y. P3 _ g4 p* J
准备三:构建本地yum服务器。6 \- B3 B4 }# j- L. X% T( D2 ?
" F& q0 ~) l! L) v2 PFTP+SSL配置详细过程:
% k/ c4 A# K: c/ N! X/ |* _
- X' P% s9 N7 N" q6 m: U' }/ }; {①.安装配置FTP服务器和抓包工具:(ftp:192.168.101.210)
% i* M/ e) Z! o; Z' |0 K' d8 h1 E" `3 Z: K, l
[root@ftp ~]# yum list all |grep vsftpd
& _6 H& X j+ ?0 m7 ~[root@ftp ~]# yum install -y vsftpd
% b2 v/ O4 O* C- j# k
/ O5 H I1 V- f1 N[root@ftp ~]# yum list all |grep wireshark
1 h( Q; p3 {- `7 n: `
4 p( V, m( Y: o; K, L[root@ftp ~]# yum install -y wireshark
% l! N, `8 p+ Q* D2 V+ d4 V7 {- H# P
[root@ftp ~]# useradd user1 A$ v' R' \' A* m
[root@ftp ~]# echo "123" |passwd --stdin user1+ z- L# Q& C Q
5 l* @% T0 I( K' T5 a0 A- D2 Q
[root@ftp ~]# service vsftpd start
7 o: a2 F5 U9 `! } ], j) o+ S7 h+ E2 x
Starting vsftpd for vsftpd: [ OK ]' V2 ]/ p" C* g0 ~) l& I* J
2 R: l# I. z; G/ P
5 m9 A% X, S! j- q: _6 r @[root@ftp ~]# tshark -ni eth0 -R "tcp.dstport eq 21"
: j2 H8 U; f0 ~* {9 J: B( l0 X; z8 v7 O- y+ N9 l
" R/ G/ p/ Z/ y/ X) e7 `4 Q* z9 Y) j7 A& u% T+ C% d: C* J9 S
②.配置本地CA证书服务器:
5 K) n( G' ^ T% F, }+ f; ]
3 y* G' P0 @' F$ d[root@ftp ~]# cd /etc/pki/
$ F3 Z' N2 G4 G* l[root@ftp pki]# ll
6 C. q$ r$ `/ b: z[root@ftp pki]# vim tls/openssl.cnf
# V7 Q0 L, `* y1 A) W9 r45 dir = /etc/pki/CA+ H$ ?8 t5 l( w& w
88 countryName = optional* F6 i* `, S0 C+ B+ p
6 O( X/ h" U3 r7 Y- X6 g
89 stateOrProvinceName = optional
5 ~1 T; L& M5 Z3 v. ~- H6 F# ?% d( L4 t8 \
90 organizationName = optional8 W0 @8 |) L% G
; G; N" k& }2 m G9 Y7 A; ^[root@ftp pki]# cd CA/
; }/ W5 M ]- V2 u[root@ftp CA]# mkdir certs newcerts crl
~0 ~, z" F( l. W0 u/ C[root@ftp CA]# touch index.txt serial; N3 J$ i) ]6 b8 w* z
[root@ftp CA]# echo "01" >serial
& b3 x2 \8 {9 k* v; x
3 D6 Q, M6 `6 o' v- I% V[root@ftp CA]# ll
0 v' M! A+ v# d' E[root@ftp CA]# openssl genrsa 1024 > private/cakey.pem7 Z6 Y0 _1 z7 ^! v2 X) E8 m6 j# r! P
( Z% O4 O6 z( ]; BGenerating RSA private key, 1024 bit long modulus
3 \; s8 Q6 \ H; O( ?7 s% ~5 \* A7 O, s" ]- x3 ^. Y
...........++++++4 t0 q% H1 }$ D; c/ X, M
....++++++% o. @( F: c* s3 }, O* K7 m
e is 65537 (0x10001)3 C: R2 P( a5 Q0 B
' Y- J, _2 J9 f& x5 J& a1 y[root@ftp CA]# chmod 600 private/cakey.pem
, y8 `# j7 q6 W3 k5 Q# K- d[root@ftp CA]# ll private/cakey.pem
& ^+ n3 Y1 G. t2 q. [" `-rw------- 1 root root 887 Feb 10 23:22 private/cakey.pem
" N" q6 Z2 x1 U: {0 }[root@ftp CA]# openssl req -new -x509 -key private/cakey.pem -out cacert.pem -days 3650
4 L0 F7 Y8 s U* g& a2 x
; {" x9 d) U7 H: g5 AYou are about to be asked to enter information that will be incorporated
w1 Y, l$ f! I$ P6 `
( v4 B5 e$ D+ K7 m0 C* Ninto your certificate request.$ ~4 r/ y2 {$ v, H T
$ P$ A: b8 ~9 D) j! l" _/ K/ jWhat you are about to enter is what is called a Distinguished Name or a DN.; _) _ X, m4 d+ U1 y3 S6 V) M
! c; [( N4 ?2 }" g e/ t4 f7 i
There are quite a few fields but you can leave some blank# |6 _5 K: I! m4 }; ^- ]
. f$ b# B2 @% q) d4 ^% gFor some fields there will be a default value,; Y" h6 y) s, b( N- U5 C3 Q
! t3 `( n$ b4 |( F- pIf you enter '.', the field will be left blank.
: T: E) I: v o: q% i5 \. i& m/ x3 b4 z2 B: Y! q* I+ g0 h6 x/ r
------ i: N2 v. I; Q6 a- g
Country Name (2 letter code) [GB]:cn
" L! |% L; C4 ^- f4 ]
" }- H7 i: m# Q& ~# ?$ M; `6 JState or Province Name (full name) [Berkshire]:henan
' o+ L m8 W' H: t% e% \" _
3 s3 }1 m1 [7 d! iLocality Name (eg, city) [Newbury]:zhengzhou
" N. X2 V% o s3 a/ O. J$ M" F0 r
Organization Name (eg, company) [My Company Ltd]:junjie3 r5 _4 x% Y9 L0 x6 l# M7 k
) w( X+ ^8 r e' [' w8 x0 sOrganizational Unit Name (eg, section) []:soft% B6 [* d5 d) u% a. F
) @8 j9 P$ s. R% W% ?& GCommon Name (eg, your name or your server's hostname) []:ca.junjie.com
! G3 O4 [8 P. K% q; _4 a$ ?9 h% R& G1 `* i( Y7 b7 q
Email Address []:junjie@junjie.com/ y1 Z+ t4 k; m8 S) G
[root@ftp CA]#ll
* ^ c3 ^3 m' P" u③.为ftp服务器创建证书:
t Q/ i5 n* c/ p7 J( X( Z2 Q
( O0 j, r( t9 f( S5 X* K[root@ftp CA]# mkdir /etc/vsftpd/certs
) t) _! r# ]8 B6 ?; T7 r9 ~1 f[root@ftp CA]# cd /etc/vsftpd/certs% G$ X( N' V7 ^ U2 Y: l, X
[root@ftp certs]# openssl genrsa 1024 >vsftpd.key5 J0 Q; r$ ]( B
Generating RSA private key, 1024 bit long modulus/ Y! H- z7 c% m0 L9 J4 y
& A. A+ m/ [8 r5 e. X) D7 _/ E....++++++
- Q& e. L7 {4 ]. B7 W1 h...++++++4 r1 s& B& i% U+ z: f( ^
e is 65537 (0x10001)8 ~3 `) [/ z. T8 Q2 W
. l, x$ q4 [( O[root@ftp certs]# openssl req -new -key vsftpd.key -out vsftpd.csr
% F8 ?2 t' @, s# [: A
L( ^+ |/ i$ z4 u+ H. CYou are about to be asked to enter information that will be incorporated
4 a5 x- ~ [1 p" m
3 q) @; h( z$ i# dinto your certificate request.
4 V/ }* i/ |# O2 Q4 i9 t- l
' s4 a2 Q- H- gWhat you are about to enter is what is called a Distinguished Name or a DN.8 i( Z- e" y4 Z
* r/ |2 q. W* e4 X) `1 ^# B- nThere are quite a few fields but you can leave some blank
6 Y! v. c. |5 Q5 K6 j( {0 b8 d7 f6 r# o/ a
For some fields there will be a default value,3 `; ?, j4 `( p" |2 y
1 B/ G1 ]" m$ w0 |* u7 J3 S/ AIf you enter '.', the field will be left blank.3 M: S1 d# w( Q
+ h* }. F5 b. b' q7 t3 E-----6 y5 {9 C" _- ~. m
Country Name (2 letter code) [GB]:cn) u* R/ n1 {5 K8 v5 x
# M" I9 `+ z i9 |; dState or Province Name (full name) [Berkshire]:henan; Y! Y8 B, ]: l" n
+ I# X8 d: p2 }, GLocality Name (eg, city) [Newbury]:zhengzhou
6 V: d. X4 a- w5 ?' ], D6 Q" B9 w. b" d& f7 Z
Organization Name (eg, company) [My Company Ltd]:junjie; A& j o4 ]1 a& a
4 w$ e0 v. ]* A0 o2 D9 I* C+ z9 _& J- n
Organizational Unit Name (eg, section) []:ftp2 x( P7 t' [; c; ]
3 E) O* X! S( q3 [7 V9 g$ _6 Q
Common Name (eg, your name or your server's hostname) []:ftp.junjie.com
# T6 D+ v( H: M
* ] c$ M, x6 R' y" o6 XEmail Address []:ftp@junjie.com
' q2 d1 L( F: s8 F& g0 y7 f 1 c5 z4 f1 E9 q' c% C
Please enter the following 'extra' attributes t+ i' V: M+ }# Z: ]6 ?5 B
- {& D, g' T/ N: e
to be sent with your certificate request7 p$ x4 m: a7 j1 O4 L8 {+ \
2 J/ d- K( ?1 m* U1 H% N7 _: ]
A challenge password []:
" ^3 u; [# G! `/ {& x8 `& B
: H5 j% X0 C1 b4 b9 FAn optional company name []:
t5 D1 | v0 S* _6 C) S. V# a5 S/ ?$ X$ \2 Y |- N8 e: i7 n. p+ x
[root@ftp certs]# openssl ca -in vsftpd.csr -out vsftpd.crt
0 l7 O7 Z* i9 Y1 y8 U0 O& d6 xUsing configuration from /etc/pki/tls/openssl.cnf. m; _- k- I: M2 a3 p7 k* @
9 w' V+ G9 t. e3 h1 lCheck that the request matches the signature
1 s! L% j5 E& l/ G% _: p3 p! P6 {6 ~5 H% k4 Z7 I5 K/ N8 ?# p
Signature ok
# U% r4 L. a/ n, NCertificate Details:
3 K' i6 f" {/ h
' `! X0 R+ S7 O' ] D; j% G" s# g( e Serial Number: 1 (0x1)7 g. d$ X! W% t, g
Validity
7 H1 @$ _ V" D3 }" L" H Not Before: Feb 10 15:48:55 2012 GMT
9 Z8 U* x& f# R& Q6 i
3 |- Y" o1 k+ k& ~: T9 a/ s Not After : Feb 9 15:48:55 2013 GMT
) g2 ]/ ?7 i% J Subject:
" N5 p6 k5 C" H( a' h countryName = cn9 B, n3 C2 V- c/ I; T0 ^
stateOrProvinceName = henan# ]0 |( T! k0 i. r3 \' t/ H# [; U
organizationName = junjie
0 k. s" ]; }# ^$ V organizationalUnitName = ftp9 m5 T" N# f; m7 z
commonName = ftp.junjie.com2 d& `- i% R5 v$ L
emailAddress = junjie@junjie.com
! _3 Z% g1 g9 e1 H X509v3 extensions:
- o, L8 \4 l5 T$ d8 N X509v3 Basic Constraints:
5 F# q2 w' Y+ u1 N1 W9 ]5 L" R CA:FALSE2 Y; m" u& `1 i% `" P. x0 l
Netscape Comment:
6 x. X4 F: j7 v- q- r, o4 O+ d2 { OpenSSL Generated Certificate
; c3 K0 V! k$ P- @- w0 s X509v3 Subject Key Identifier:6 ~9 X) @' A" |& p: M
33:C5:01:33:A5:CF:42:9F:24:A9:0D:E9:41:8E:26:C3:1B:7B:18:11
3 q) u4 F$ ^. l6 u+ A9 {8 J6 r4 ? O+ g$ |" n t
X509v3 Authority Key Identifier:+ f4 u5 |# }6 d- }; j F
keyid:50 1:A8:0A:1F:B7:CD:49:94:69:E3:70:E9:AE:93:73:2C:94:66:AC
: `1 X+ A$ w$ ~$ B( Z
5 ^; s/ e7 G' |' B
' r7 V7 R5 @' L; G" G: jCertificate is to be certified until Feb 9 15:48:55 2013 GMT (365 days)
8 @# X( i2 L6 `( f# y1 D6 G" h: k+ E/ s1 P1 `
Sign the certificate? [y/n]:y
7 G0 J# J4 q# F
0 \" y7 b4 U: y, m [
, f6 c* f5 d3 [, e, O
8 f9 t+ @+ q& u. q7 w( Z) P: F1 out of 1 certificate requests certified, commit? [y/n]y
' y) l+ t2 l1 @! }0 Z! B n8 X/ d3 K
4 s5 n( L6 c% {+ \& P( C1 r) VWrite out database with 1 new entries4 @3 e& G" H$ J0 Y2 r3 m! D
3 z! \: R7 E# W) C$ S. T* s+ w' }Data Base Updated+ g' ~- m, j; K; B& [
[root@ftp certs]# ll5 \' e* M& K/ o1 l5 c( V
[root@ftp certs]# chmod 600 *$ I9 \3 o7 J2 z6 l s9 Z
[root@ftp certs]# ll. j" C+ ~. q% n$ i$ h
④.使ftp服务应用证书:- H5 c5 m' `% B& Q5 [& D
( l! b, m8 r9 y- C[root@ftp certs]# cd /etc/vsftpd/ 9 _# A# l2 m6 a" p& o" W
[root@ftp vsftpd]# vim vsftpd.conf #增加以下内容; U4 b9 A- j+ g: Y5 G# g% @
118 rsa_cert_file=/etc/vsftpd/certs/vsftpd.crt
. \% y9 F9 D; S+ y' i d
, v4 N6 }4 I& z119 rsa_private_key_file=/etc/vsftpd/certs/vsftpd.key
: Z5 p7 y& Q5 f6 Y5 b! [6 Q7 U) J2 H/ h0 v, y! o+ c- i
120 force_local_data_ssl=YES) [( ^; H* ]7 M1 |' T
121 force_local_logins_ssl=YES
( F# Z1 I% G; ^4 g# n2 `1 r2 m9 U8 c122 ssl_enable=YES
& h5 k. q4 X2 {- y5 a123 ssl_sslv2=YES
* U/ _3 ]$ n. H1 n, P124 ssl_sslv3=YES
5 s4 t% L6 D9 ?( O$ N$ I. [+ r125 ssl_tlsv1=YES
" J& l" r$ q |* _8 z) ~6 o: g, @[root@ftp vsftpd]# service vsftpd restart! ]+ A5 t$ r: l0 M& d. P1 G
3 M. A; {7 k1 v. d5 ]Shutting down vsftpd: [ OK ]5 t) E8 D! y8 M3 i, _6 e
Starting vsftpd for vsftpd: [ OK ]
n$ @' h8 q/ f" Z& N' q) B2 E2 [6 j⑤客户端测试(已加密传输):
5 X1 ^/ f- ]% ]& r6 u% V N
: S) a" E! Q, k$ j+ n4 V& {
4 L; X- ~/ K1 }8 O4 k( G$ `
2 j1 M8 `9 S" T" ~* x1 U2 {2 v2 R3 o" n: P$ \0 t
0 Z! \2 T3 f# k U
从上面看出证书名称出现问题,但可是可以使用!选择接收一次!9 I7 q5 {) o$ L# I1 r1 w
+ D! X' h! N8 T0 c U) ^% L4 J4 h) ]$ S# r1 o+ a! M
; A1 L: D3 w7 g" D1 {
该次登录抓包内容如下所示:传输已经经过加密!$ p& T' ~+ i( F& v. v7 ]; p
[root@ftp ~]# tshark -ni eth0 -R "tcp.dstport eq 21"
3 f9 m5 y0 W5 O- l4 X- V* L2 o. ?+ C2 J& ?* _4 T5 u/ P
" ^5 ^2 d9 `2 ^0 p! c' K
2 a+ B7 _: Q0 d9 }' e9 p[root@ftp ~]# tshark -ni eth0 -R "tcp.dstport eq 21"' t0 C+ Y5 N q" l# Q. V% p
7 Q* Z' G/ W9 W9 T0 P9 j. J6 X# _
Running as user "root" and group "root". This could be dangerous.
4 Y' k; t! H3 n! b- ]
! M0 g; w8 [! L- i# XCapturing on eth0
& ]5 \0 @1 J* z; h9 Z$ D5 s7 e$ H
9.742109 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=27 ~5 ]4 W! ]( m- L. z
* }3 L4 x4 n! K/ U# b( ]
9.742144 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=1 Ack=1 Win=65700 Len=0- |1 L% O' z5 n0 r. _
' p4 H0 n+ s' ]+ ^* [4 e. ?7 i 9.747458 192.168.101.113 -> 192.168.101.210 FTP Request: AUTH SSL
/ f4 _% o; ]2 a+ ^
. E0 H' a( d( a* M) n 9.755605 192.168.101.113 -> 192.168.101.210 FTP Request: \200\310\001\003\001\000\237\000\000\000 \000\300\024\000\300' T' {' M1 B$ K# F2 s* N4 v \
$ t& r' b4 a ?" _4 p! V
9.758795 192.168.101.113 -> 192.168.101.210 FTP Request: \026\003\001\000\206\020\000\000\202\000\200n\257\315\204\324o
. `; G$ L' |$ I5 Q g( M. M( H5 E" X7 N8 Z. c, x0 [
9.778662 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\215\325t\357\277\001\376FZ\243D\373\003\367\231\207Q\324\003Q}/\335\025\027\003\001\000 \f\355b\270\355\325\020[\372\302s{^\375\307\364C\307\243\251v9\370\364\260\277\253\317\321gB]
1 r% w7 F7 k9 V( V* @& G# A) n4 Q9 j, {0 V$ r' R d
9.779885 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\324\000\267\312\0320\213\266y\311\025[\371\275?\254Y\257\024[\245vjM\027\003\001\000(\236\321\221Z\321Z(\316'\343.\235?\321=8\264b\270(j\336\231\210\265\207K\223A\037"\277\251\252t\252a`\374
, ~5 [# @/ v- r# H5 K( l7 y+ N8 l" y: |( _6 R3 i5 W
9.782153 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\257d\313mXZT\356\2366\334q\223\017gt\371\232\207\226\3256 C2 v: n" P2 Y" _5 @, {5 O
' H7 W! S8 v; F: e 9.793165 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\0301\020S\237\372\210\004N4\370\366\377\2213m\356\233w:\275)>@%\027\003\001\000 Y\032\275BM=3J\313\240\241\372Z\371@\335\262\252\240\235\021\345\271\305\223\211\020\340\332\323Q\251# u- `! d+ ?% [ ?# U* Z8 }4 x
2 n- w7 a+ i4 U( v! J. { | 9.795630 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\302\016=LR\272\030{\034\277V\256]\230\247\363\355M\241\327U\207k\032\027\003\001\000 OYi\216=S\322\212)\271V\016\2519w\332f\213\222S\244\275M\316\025N\302:k\312b\3310 v# x+ M8 {9 s/ T1 m7 N, P u
4 J; ]- }2 w/ A% |) M' I 9.796727 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=741 Ack=1260 Win=64440 Len=0
4 v9 N; S+ K1 @8 p, s" o
5 @7 c" n/ Q8 H' h _ 9.797542 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=741 Ack=1334 Win=64364 Len=0$ {* C- j$ S) ]1 u! P4 H4 R6 Z- J
" d- G4 o' g. o- ^+ ^' ? H 9.798327 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=741 Ack=1408 Win=64292 Len=0/ h; O7 ?- k' g
/ d" V: R3 a' q1 i: i1 R$ n8 h
9.798775 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=741 Ack=1482 Win=65700 Len=0
& G8 ^8 ~% ~" K0 ^8 Q# a$ |) y
3 h! Q# H6 B* | w' q" r2 V( G 9.799387 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=741 Ack=1564 Win=65616 Len=0
6 R& u. o: q3 z% I0 S3 o/ C1 j$ |0 ^, P; i0 `& {1 F% Q, X' h5 ^
9.799910 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=741 Ack=1638 Win=65544 Len=0
9 H4 i" g. z# Z: D* G
! ~ K& c8 b0 A f1 y- i( B$ s# W) Q 9.805078 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030G}\305\210\021s\244q\023k=\345R\232A\366B\360\202\320\361(x\344\027\003\001\000 \351W\350\377\362\2756\334\303\035+1l|{\304\277\224\326n\036d\213\217\b\216\023N\225\003a\2748 {9 p! \0 u1 O! p h/ r- |' l( d: a
8 Z& R! J+ ]: E/ D6 m
9.810763 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\203\354F\302\253\205\212\355\334$\321=\303h\276\302\350\320.\346\223\337BG\027\003\001\000 73\027\372#\232
) {8 T6 f* f4 I! E% ]
. P+ z( s3 L% K( {. { 9.813350 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\203x`k\337RM\341w\022N\255|f\260U ?\354)A\301^\251\027\003\001\000 \031`\366\364He\030\266z)\373\265\237\261\3430\220\331\340Kv[\033\347\tXj\344\314\236\242
5 W4 \7 U" J3 y4 Q/ a% E( p5 K2 ^5 I
9.814073 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\307\2126sY\a\237\034\321\277!j\320\213\235\032\277e\345\361E>|)\027\003\001\000 \256\304}:-\365\034\aD~\fk`]\314\b\207\365-\217\305\244
' F; n$ T0 D6 ?8 y" T" I
; D% Q! d& C, i; V; q7 y; x* z3 } 9.838659 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\300\272t&\t(\262\243\361\210\263\343\326\261\017$\317V\002\354\325\271\250\366\027\003\001\000 \350F\305\360\363\365\033\274W\207M\006\216\255\016\365\205z\033\002\032B\345,\3712\034\377\327[\272P$ l1 Z3 Q2 {6 s7 d; j' y! N7 K
' H* C4 J: t/ P2 h. S0 t7 \ 9.851675 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=1071 Ack=2041 Win=65140 Len=0! X! Q4 w3 D. z7 F" a( c/ B7 K$ ]8 |
0 X! @, ]* M$ U9 f) j
9.856073 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030\f\357\000E/\372\333\247\016\344\315\345\346\271L\327\214CE0*i\316\332\027\003\001\000(8\220\341\316.*\234dM\235
* T' E( v8 P5 K- ~# b9 U8 J1 T- i7 F% \4 a) i+ P* m2 ?
10.061779 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [ACK] Seq=1145 Ack=2094 Win=65088 Len=0
# F# Z5 B- ~/ G4 I f( A# Z; D6 U0 \4 @5 x" x, r$ v
39.978110 192.168.101.113 -> 192.168.101.210 FTP Request: \027\003\001\000\030=\032\322\022\216B\025O\016\0342 R9 H/ O) a& U+ D; @! q! ]
% P! s# y; G0 d# e- L; y2 E% r; V 39.980672 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [FIN, ACK] Seq=1211 Ack=2139 Win=65040 Len=0
4 Z/ P1 N; w9 U- L+ ]' D* R( H4 [* n" A8 A4 Y1 H5 E4 L
39.980725 192.168.101.113 -> 192.168.101.210 TCP 52572 > 21 [RST, ACK] Seq=1212 Ack=2149 Win=0 Len=0
# Z; E- Z2 C" _# N* a
: c! @+ G$ g% f27 packets captured
4 |8 T: ~: G7 T, n$ F: M! j6 X4 q; H1 s8 x6 C- ?
[root@ftp ~]# |