验证分析 Telnet通信过程——客户端同意激活认证选项 No. Time Source Destination Protocol Length Info 70510160101910.30 TELNET75 elnet data, 816.537072192.168.0.30 192.168.0 10 TELNET 57 Telnet Data . 91910168.0.10192168.0.30EET652 re lnet Data, 10155351168.0.31901680.10 TELNET81 telnet Data, ddd,P严 daspan dA用dPAA"A AA-1 nternet Protocol version,:90019..3,.0:191.01090158.10) : Telnet Command: will Authentication option
验证分析Telnet通信过程----客户端同意激活认证选项
验证分析 Telnet通信过程服务器就认证选项进行子选项协商 Ime Source Destination Protocol Length Info 816.537078192,168.0.30192.168,0.10 TELNET57 Telnet data, 916.3291160.01921680.30 TELNET2Tent Data ., 1016.537361192,168,0.30192.168,0.10 TELNET 81 Telnet Data 11157526192,168.0.10192.,168.0.30 TELNET89 Telnet Data,, t Frame 9: 62 bytes on wire(496 bits), 62 bytes captured (496 bits) t Ethernet II, srC: Vmware_8c: 24: f2(00: 0c: 29: 8C: 24: f2), Dst: Vmware_b3: e8: e8(00: 0c: 29: b3: e8: e8) Internet Protocol version4,Src:192.168.0.10(9.1.0.10),st:192.168.0.30(19.16.3) Transmission Control Protocol, Src Port: telnet(23), Dst Port: rap-service (1530), seq: 4203513863, Ack: 311 F Telnet e suboption Begin: Authentication option Auth Cmd: SEND(1) Auth Type: NTLM(15) ,0,0,=Erpt:0f(0) O,,= Cred Fwd: client will NoT forward auth creds 0.=HOW: One way authentication 0 who: Mask client to server Command: Suboption End
验证分析Telnet通信过程----服务器就认证选项进行子选项协商
验证分析Tene通信过程客户端发起选项协商 No. Time Source Destination Protocol Length Into 816.53707:192,168.0.30192,168.0.,10 TELNET57 reInet data,, 916,537298192,168.0.,10192,168,0.30 TELNET62 Telnet Data, 1016.537361192.168.0.30192.168.0.10 TELNET 81 Telnet Data 1116.537526192,168.0.10192.168.0.30 TELNET 89 Telnet Data 1.P-,.1-dJ4iPAAI4APARP Frame 10: 81 bytes on wire(648 bits), 81 bytes captured(648 bits) t Ethernet II, src: Vmware_b3: e8: e8(00: 0c: 29: b3: e8: e8), Dst: Vmware_8c: 24: f2(00: 0c: 29: 8C: 24: f2) Internet Protocol version4,src:19.168.0.30(192,168.0.30),Dst:192,168.0.10(19.168.0.10) Transmission Control Protocol, src Port: rap-service (1530), Dst Port: telnet(23), seq: 3113424481, Ack: 42035 Telnet Command: Do echo Command: Do Suppress Go Ahead Command: will New Environment option Command: will Negotiate About window Size a suboption Begin: Negotiate About window size width: 80 Height: 24 Command: Suboption End ommand: will Binary Transmission Command: Do Binary Transmission
验证分析Telnet通信过程----客户端发起选项协商
验证分析 Telnet通信过程—客户端回应认证子选项协商 No. T Destination Protocol Length Info 1116.537526192.168.0.10192.168.0.30 TELNET89 Telnet Data, 1216.684124192,168,0.30192,168.0,10Tp 54 rap-service >telnet [ACK] Seq=3113424508 Ack=4203513906 132689839:1680.10TMET11 telnet Data 1423.689471192,168.0.,10192,168.0.30 TELNET207 Tenet data, 1502 60056410716002010160010 TrI ACT 00 Talat n+1 t Frame 13: 111 bytes on wire(888 bits), 111 bytes captured(888 bits) t Ethernet II, Src: Vmware_b3: e8: e8(00: 0C: 29: b3: e8: e8), Dst: Vmware_8c: 24: f2(00: 0C: 29: 8C: 24: f2 f Internet protocol version4,Src:192,168.0.30(192.168.0.30),Dt:192,168.0.10(192.168.0.10) f Transmission Control Protocol, Src Port: rap-service(1530), Dst Port: telnet(23), seq: 3113424508, Ack: 420351 - Telnet a suboption Begin: Authentication option Auth Cmd: IS(0) Auth Type: NTLM(15) 0. 0..= Encrypt: off(O) O., cred Fwd: client will NoT forward auth creds 0. HoW: one way authentication 0= who: Mask client to server Command: Auth(0) Command: Suboption End
验证分析Telnet通信过程----客户端回应认证子选项协商
验证分析 Telnet通信过程——开始传输数据 1me S ource Destinati Protocol Length Info 1723.805389192.168.0.30192.168.0.10 TELNET 285 Telnet Data 1823.80661192.168.0.10192.168.0.30 TELNET 245 Telnet Data 1924.016019192168.0.30192.168.0.10TcP 54 rap-service> telnet [ACk] Seq=3113424841 Ack=420 2025.039897192.168.0.30192.168.0.10 TELNET55 Telnet data t Frame 18: 245 bytes on wire(1960 bits), 245 bytes captured(1960 bits) Ethernet II, Src: Vmware_8c: 24: f2(00: 0c: 29: 8c: 24: f2), Dst: Vmware_b3: e8: e8(00: 0c: 29: b3: e8: e8) Internet Protocol version4,src:192.168.0.10(192.168.0.10),Dst:192.168.0.30(192.168.0.30) Transmission Control protocol, Src Port: telnet(23), Dst Port: rap-service(1530), seq: 4203514059, Ack: Telnet 3 Suboption Begin: Authentication option Auth Cmd: REPLY(2) Auth Type: NTLM(15) 0.0.= Encrypt: off (o) 0..,= Cred Fwd: client will not forward auth cred 0.= HoW: one way authentication 0= who: Mask client to server Command: Forward(4) Command: Subopt ion End Data: Telnet server could not log you in using NTLM authentication. rn Data: Your password may have expired. rn Data: Login using username and passwordrn Data: rn Data: we lcome to microsoft Telnet service rn 传输数据 Data: n Data: rlogin
验证分析Telnet通信过程----开始传输数据