// Ubuntu 192.168.2.201
root@Ubuntu-Asus 192.168.2.201 15:17:27 ~
tshark: Lua: Error during loading:
[string "/usr/share/wireshark/init.lua"]:46: dofile has been disabled due to running Wireshark as superuser. See http://wiki.wireshark.org/CaptureSetup/CapturePrivileges for help in running Wireshark as an unprivileged user.
Running as user "root" and group "root". This could be dangerous.
Capturing on 'docker0'
1 0.000000 02:42:ac:11:00:02 -> Broadcast ARP 42 Who has 172.17.0.1? Tell 172.17.0.2
2 0.000033 02:42:08:03:7a:e6 -> 02:42:ac:11:00:02 ARP 42 172.17.0.1 is at 02:42:08:03:7a:e6
3 0.000046 172.17.0.2 -> 172.18.0.2 TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
4 0.032752 172.18.0.2 -> 172.17.0.2 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
5 0.032982 172.17.0.2 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
6 0.057003 172.18.0.2 -> 172.17.0.2 MySQL 144 Server Greeting proto=10 version=5.7.10
7 0.057052 172.17.0.2 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
8 0.057149 172.17.0.2 -> 172.18.0.2 MySQL 249 Login Request user=root
9 0.091636 172.18.0.2 -> 172.17.0.2 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
10 0.097889 172.18.0.2 -> 172.17.0.2 MySQL 77 Response OK
11 0.098129 172.17.0.2 -> 172.18.0.2 MySQL 103 Request Query
12 0.125942 172.18.0.2 -> 172.17.0.2 MySQL 158 Response
13 0.162720 172.17.0.2 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
13 14 4.602119 172.17.0.2 -> 172.18.0.2 MySQL 71 Request Quit
15 4.602301 172.17.0.2 -> 172.18.0.2 TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322574 TSecr=182278599
16 4.670611 172.17.0.2 -> 172.18.0.2 TCP 66 [TCP Retransmission] 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
17 4.675746 172.18.0.2 -> 172.17.0.2 TCP 66 [TCP Previous segment not captured] mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
18 4.843638 172.18.0.2 -> 172.17.0.2 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
19 4.843713 172.17.0.2 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
19 20 5.038625 02:42:08:03:7a:e6 -> 02:42:ac:11:00:02 ARP 42 Who has 172.17.0.2? Tell 172.17.0.1
21 5.038670 02:42:ac:11:00:02 -> 02:42:08:03:7a:e6 ARP 42 172.17.0.2 is at 02:42:ac:11:00:02
21 ^C
$ tshark -i wlan0 | grep mysql
tshark: Lua: Error during loading:
[string "/usr/share/wireshark/init.lua"]:46: dofile has been disabled due to running Wireshark as superuser. See http://wiki.wireshark.org/CaptureSetup/CapturePrivileges for help in running Wireshark as an unprivileged user.
Running as user "root" and group "root". This could be dangerous.
Capturing on 'wlan0'
405 396 64.586967 192.168.2.201 -> 172.18.0.2 TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
397 64.619458 172.18.0.2 -> 192.168.2.201 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
418 398 64.619905 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
400 64.643935 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
402 64.678468 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
406 64.749772 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
466 444 69.189204 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322574 TSecr=182278599
446 69.257519 192.168.2.201 -> 172.18.0.2 TCP 66 [TCP Retransmission] 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
471 447 69.262593 172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Previous segment not captured] mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
448 69.430439 172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
449 69.430616 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
613 ^C
// Centos 192.168.2.202
[root@Centos-L410 docker]
Running as user "root" and group "root". This could be dangerous.
Capturing on 'docker0'
1 0.000000000 192.168.2.201 -> 172.18.0.2 TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
2 0.000094913 172.18.0.2 -> 192.168.2.201 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
3 0.030116575 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
4 0.030976025 172.18.0.2 -> 192.168.2.201 MySQL 144 Server Greeting proto=10 version=5.7.10
5 0.056176778 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
6 0.066130572 192.168.2.201 -> 172.18.0.2 MySQL 249 Login Request user=root
7 0.066173733 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
8 0.066262220 172.18.0.2 -> 192.168.2.201 MySQL 77 Response OK
9 0.093104979 192.168.2.201 -> 172.18.0.2 MySQL 103 Request Query
10 0.093395793 172.18.0.2 -> 192.168.2.201 MySQL 158 Response
11 0.159316774 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
12 4.599128670 192.168.2.201 -> 172.18.0.2 MySQL 71 Request Quit
13 4.599292166 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [FIN, ACK] Seq=182 Ack=226 Win=30080 Len=0 TSval=182283104 TSecr=39322574
14 4.665013615 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
15 4.665053144 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
16 4.832475608 172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
17 4.849718662 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
18 5.014473661 02:42:38:14:f7:88 -> 02:42:ac:12:00:02 ARP 42 Who has 172.18.0.2? Tell 172.18.0.1
19 5.014525272 02:42:ac:12:00:02 -> 02:42:38:14:f7:88 ARP 42 172.18.0.2 is at 02:42:ac:12:00:02
^C19 packets captured
[root@Centos-L410 arnes]
Running as user "root" and group "root". This could be dangerous.
Capturing on 'wlp5s0'
354 318 39.616348312 192.168.2.201 -> 172.18.0.2 TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
319 39.616526473 172.18.0.2 -> 192.168.2.201 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
321 39.646494918 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
324 39.672552747 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
326 39.682593002 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
333 39.775693441 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
379 384 44.215727358 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [FIN, ACK] Seq=182 Ack=226 Win=30080 Len=0 TSval=182283104 TSecr=39322574
386 44.281387627 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
387 44.281474299 172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
421 389 44.448924489 172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
391 44.466095818 192.168.2.201 -> 172.18.0.2 TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
596 ^C
1 packet dropped