Skip to content
$ whois carlotomasini.dev

Carlo Tomasini

Network security architect. 25 years. I build the tools I wish existed.

ANNOTATED DECODE — SYN, initial exchange0x0000
No.TimeSourceDestinationProtoLenInfo
10.000000192.168.0.104192.168.0.1TCP6054321 → 443 [SYN] Seq=0 Win=64240
20.031204192.168.0.1192.168.0.104TCP60443 → 54321 [SYN, ACK] Seq=0 Ack=1
30.031388192.168.0.104192.168.0.1TCP5254321 → 443 [ACK] Seq=1 Ack=1
40.032910192.168.0.104192.168.0.1TLSv1.3569Client Hello (SNI redacted)
50.198441192.168.0.1192.168.0.104TCP52[TCP ZeroWindow] 443 → 54321 Win=0
60.402117192.168.0.1192.168.0.104TCP52[TCP Window Update] Win=32128
PACKET DETAIL
Internet Protocol Version 4, Src: 192.168.0.104, Dst: 192.168.0.1
· ver/ihl, dscp — IPv4, 20-byte header, best effort
· total length — 60 bytes on the wire
· identification — fragment id, unfragmented here
· flags/frag — DF set, offset 0
· ttl / proto — 64 hops remaining; protocol 6 = TCP
· header checksum — valid
· src addr — 192.168.0.104
· dst addr — 192.168.0.1
Transmission Control Protocol, Src Port: 54321, Dst Port: 443, Len: 0
· src port — 54321, ephemeral
· dst port — 443, HTTPS
· sequence — ISN — nothing sent yet
· acknowledgment — zero; no data acknowledged
· offset / flags — 40-byte header, SYN set
· window — 64240 bytes advertised, pre-scale
· checksum — valid
· urgent pointer — unused
· option: MSS — 1460 — standard Ethernet path
· option: SACK ok — selective ack permitted
· option: timestamp — RTT measurement enabled
BYTESIPv4TCPportsseq/ackoptionsflags
00004500003c1c4640004006b1e6c0a80068E..<.F@[email protected]
0010c0a80001d43101bb9c1e2f0a00000000.....1..../.....
0020a002faf0917c0000020405b40402080a.....|..........
Figure 0.1  Three planes, one packet: list, dissection, bytes — selection moves through all three.