PuTTY terminate on open Alteon Director - Contains packet dump (LONG POSTING)

From: Francis Libble (garyoffsite_at_yahoo.co.uk)
Date: 04/05/04


Date: 5 Apr 2004 00:44:21 -0700

PuTTY is terminating immediately on open when establishing a
connection to our Alteon Director. No error, no nothing, just a quick
flash of the PuTTY terminal screen and then vanish.

PuTTY log has:

Writing new session log (SSH packets mode) to file k:\putty.log
Looking up host "192.168.160.1"
Connecting to 192.168.160.1 port 22
Server version: SSH-1.5-1.2.27
We claim version: SSH-1,5-PuTTY-Release-0.53b
Using SSH protocol version 1

I have also tried multiple different protocol settings and bugs
settings, versions 0.53b, 0.54, and latest snapshot to no avail.

Any help much appreciated.

An ethereal dump shows (apologies for long posting)

Frame 6 (62 bytes on wire, 62 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.989393000
    Time delta from previous packet: 0.309666000 seconds
    Time since reference or first frame: 1.863240000 seconds
    Frame Number: 6
    Packet Length: 62 bytes
    Capture Length: 62 bytes
Ethernet II, Src: 00:09:6b:30:b3:ba, Dst: 00:60:cf:42:4c:50
    Destination: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Source: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.171.132 (192.168.171.132), Dst
Addr: 192.168.160.1 (192.168.160.1)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 48
    Identification: 0x702f (28719)
    Flags: 0x04
        .1.. = Don't fragment: Set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 128
    Protocol: TCP (0x06)
    Header checksum: 0xbdc1 (correct)
    Source: 192.168.171.132 (192.168.171.132)
    Destination: 192.168.160.1 (192.168.160.1)
Transmission Control Protocol, Src Port: 2759 (2759), Dst Port: ssh
(22), Seq: 53896108, Ack: 0, Len: 0
    Source port: 2759 (2759)
    Destination port: ssh (22)
    Sequence number: 53896108
    Header length: 28 bytes
    Flags: 0x0002 (SYN)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...0 .... = Acknowledgment: Not set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..1. = Syn: Set
        .... ...0 = Fin: Not set
    Window size: 64512
    Checksum: 0x4888 (correct)
    Options: (8 bytes)
        Maximum segment size: 1460 bytes
        NOP
        NOP
        SACK permitted

Frame 7 (60 bytes on wire, 60 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.989996000
    Time delta from previous packet: 0.000603000 seconds
    Time since reference or first frame: 1.863843000 seconds
    Frame Number: 7
    Packet Length: 60 bytes
    Capture Length: 60 bytes
Ethernet II, Src: 00:60:cf:42:4c:50, Dst: 00:09:6b:30:b3:ba
    Destination: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Source: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Type: IP (0x0800)
    Trailer: 0000
Internet Protocol, Src Addr: 192.168.160.1 (192.168.160.1), Dst Addr:
192.168.171.132 (192.168.171.132)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 44
    Identification: 0x290d (10509)
    Flags: 0x00
        .0.. = Don't fragment: Not set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 255
    Protocol: TCP (0x06)
    Header checksum: 0xc5e7 (correct)
    Source: 192.168.160.1 (192.168.160.1)
    Destination: 192.168.171.132 (192.168.171.132)
Transmission Control Protocol, Src Port: ssh (22), Dst Port: 2759
(2759), Seq: 3695459033, Ack: 53896109, Len: 0
    Source port: ssh (22)
    Destination port: 2759 (2759)
    Sequence number: 3695459033
    Acknowledgement number: 53896109
    Header length: 24 bytes
    Flags: 0x0012 (SYN, ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..1. = Syn: Set
        .... ...0 = Fin: Not set
    Window size: 4096
    Checksum: 0x3261 (correct)
    Options: (4 bytes)
        Maximum segment size: 1460 bytes

Frame 8 (54 bytes on wire, 54 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.990018000
    Time delta from previous packet: 0.000022000 seconds
    Time since reference or first frame: 1.863865000 seconds
    Frame Number: 8
    Packet Length: 54 bytes
    Capture Length: 54 bytes
Ethernet II, Src: 00:09:6b:30:b3:ba, Dst: 00:60:cf:42:4c:50
    Destination: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Source: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.171.132 (192.168.171.132), Dst
Addr: 192.168.160.1 (192.168.160.1)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 40
    Identification: 0x7030 (28720)
    Flags: 0x04
        .1.. = Don't fragment: Set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 128
    Protocol: TCP (0x06)
    Header checksum: 0xbdc8 (correct)
    Source: 192.168.171.132 (192.168.171.132)
    Destination: 192.168.160.1 (192.168.160.1)
Transmission Control Protocol, Src Port: 2759 (2759), Dst Port: ssh
(22), Seq: 53896109, Ack: 3695459034, Len: 0
    Source port: 2759 (2759)
    Destination port: ssh (22)
    Sequence number: 53896109
    Acknowledgement number: 3695459034
    Header length: 20 bytes
    Flags: 0x0010 (ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...0 = Fin: Not set
    Window size: 64512
    Checksum: 0x5e1d (correct)

Frame 9 (70 bytes on wire, 70 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.990889000
    Time delta from previous packet: 0.000871000 seconds
    Time since reference or first frame: 1.864736000 seconds
    Frame Number: 9
    Packet Length: 70 bytes
    Capture Length: 70 bytes
Ethernet II, Src: 00:60:cf:42:4c:50, Dst: 00:09:6b:30:b3:ba
    Destination: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Source: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Type: IP (0x0800)
    Trailer: 00
Internet Protocol, Src Addr: 192.168.160.1 (192.168.160.1), Dst Addr:
192.168.171.132 (192.168.171.132)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 55
    Identification: 0x290f (10511)
    Flags: 0x00
        .0.. = Don't fragment: Not set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 255
    Protocol: TCP (0x06)
    Header checksum: 0xc5da (correct)
    Source: 192.168.160.1 (192.168.160.1)
    Destination: 192.168.171.132 (192.168.171.132)
Transmission Control Protocol, Src Port: ssh (22), Dst Port: 2759
(2759), Seq: 3695459034, Ack: 53896109, Len: 15
    Source port: ssh (22)
    Destination port: 2759 (2759)
    Sequence number: 3695459034
    Next sequence number: 3695459049
    Acknowledgement number: 53896109
    Header length: 20 bytes
    Flags: 0x0018 (PSH, ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 1... = Push: Set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...0 = Fin: Not set
    Window size: 4096
    Checksum: 0xa897 (correct)
SSH Protocol
    Protocol: SSH-1.5-1.2.27\n

Frame 10 (82 bytes on wire, 82 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.995590000
    Time delta from previous packet: 0.004701000 seconds
    Time since reference or first frame: 1.869437000 seconds
    Frame Number: 10
    Packet Length: 82 bytes
    Capture Length: 82 bytes
Ethernet II, Src: 00:09:6b:30:b3:ba, Dst: 00:60:cf:42:4c:50
    Destination: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Source: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.171.132 (192.168.171.132), Dst
Addr: 192.168.160.1 (192.168.160.1)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 68
    Identification: 0x7031 (28721)
    Flags: 0x04
        .1.. = Don't fragment: Set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 128
    Protocol: TCP (0x06)
    Header checksum: 0xbdab (correct)
    Source: 192.168.171.132 (192.168.171.132)
    Destination: 192.168.160.1 (192.168.160.1)
Transmission Control Protocol, Src Port: 2759 (2759), Dst Port: ssh
(22), Seq: 53896109, Ack: 3695459049, Len: 28
    Source port: 2759 (2759)
    Destination port: ssh (22)
    Sequence number: 53896109
    Next sequence number: 53896137
    Acknowledgement number: 3695459049
    Header length: 20 bytes
    Flags: 0x0018 (PSH, ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 1... = Push: Set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...0 = Fin: Not set
    Window size: 64497
    Checksum: 0x114f (correct)
SSH Protocol
    Protocol: SSH-1.5-PuTTY-Release-0.53b\n

Frame 11 (60 bytes on wire, 60 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.997067000
    Time delta from previous packet: 0.001477000 seconds
    Time since reference or first frame: 1.870914000 seconds
    Frame Number: 11
    Packet Length: 60 bytes
    Capture Length: 60 bytes
Ethernet II, Src: 00:60:cf:42:4c:50, Dst: 00:09:6b:30:b3:ba
    Destination: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Source: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Type: IP (0x0800)
    Trailer: 000000000000
Internet Protocol, Src Addr: 192.168.160.1 (192.168.160.1), Dst Addr:
192.168.171.132 (192.168.171.132)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 40
    Identification: 0x2911 (10513)
    Flags: 0x00
        .0.. = Don't fragment: Not set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 255
    Protocol: TCP (0x06)
    Header checksum: 0xc5e7 (correct)
    Source: 192.168.160.1 (192.168.160.1)
    Destination: 192.168.171.132 (192.168.171.132)
Transmission Control Protocol, Src Port: ssh (22), Dst Port: 2759
(2759), Seq: 3695459049, Ack: 53896137, Len: 0
    Source port: ssh (22)
    Destination port: 2759 (2759)
    Sequence number: 3695459049
    Acknowledgement number: 53896137
    Header length: 20 bytes
    Flags: 0x0011 (FIN, ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...1 = Fin: Set
    Window size: 4068
    Checksum: 0x4a0e (correct)

Frame 12 (54 bytes on wire, 54 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.997105000
    Time delta from previous packet: 0.000038000 seconds
    Time since reference or first frame: 1.870952000 seconds
    Frame Number: 12
    Packet Length: 54 bytes
    Capture Length: 54 bytes
Ethernet II, Src: 00:09:6b:30:b3:ba, Dst: 00:60:cf:42:4c:50
    Destination: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Source: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.171.132 (192.168.171.132), Dst
Addr: 192.168.160.1 (192.168.160.1)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 40
    Identification: 0x7032 (28722)
    Flags: 0x04
        .1.. = Don't fragment: Set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 128
    Protocol: TCP (0x06)
    Header checksum: 0xbdc6 (correct)
    Source: 192.168.171.132 (192.168.171.132)
    Destination: 192.168.160.1 (192.168.160.1)
Transmission Control Protocol, Src Port: 2759 (2759), Dst Port: ssh
(22), Seq: 53896137, Ack: 3695459050, Len: 0
    Source port: 2759 (2759)
    Destination port: ssh (22)
    Sequence number: 53896137
    Acknowledgement number: 3695459050
    Header length: 20 bytes
    Flags: 0x0010 (ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...0 = Fin: Not set
    Window size: 64497
    Checksum: 0x5e00 (correct)

Frame 13 (54 bytes on wire, 54 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:00.997315000
    Time delta from previous packet: 0.000210000 seconds
    Time since reference or first frame: 1.871162000 seconds
    Frame Number: 13
    Packet Length: 54 bytes
    Capture Length: 54 bytes
Ethernet II, Src: 00:09:6b:30:b3:ba, Dst: 00:60:cf:42:4c:50
    Destination: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Source: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Type: IP (0x0800)
Internet Protocol, Src Addr: 192.168.171.132 (192.168.171.132), Dst
Addr: 192.168.160.1 (192.168.160.1)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 40
    Identification: 0x7033 (28723)
    Flags: 0x04
        .1.. = Don't fragment: Set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 128
    Protocol: TCP (0x06)
    Header checksum: 0xbdc5 (correct)
    Source: 192.168.171.132 (192.168.171.132)
    Destination: 192.168.160.1 (192.168.160.1)
Transmission Control Protocol, Src Port: 2759 (2759), Dst Port: ssh
(22), Seq: 53896137, Ack: 3695459050, Len: 0
    Source port: 2759 (2759)
    Destination port: ssh (22)
    Sequence number: 53896137
    Acknowledgement number: 3695459050
    Header length: 20 bytes
    Flags: 0x0011 (FIN, ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...1 = Fin: Set
    Window size: 64497
    Checksum: 0x5dff (correct)

Frame 14 (60 bytes on wire, 60 bytes captured)
    Arrival Time: Apr 5, 2004 07:44:01.000097000
    Time delta from previous packet: 0.002782000 seconds
    Time since reference or first frame: 1.873944000 seconds
    Frame Number: 14
    Packet Length: 60 bytes
    Capture Length: 60 bytes
Ethernet II, Src: 00:60:cf:42:4c:50, Dst: 00:09:6b:30:b3:ba
    Destination: 00:09:6b:30:b3:ba (Ibm_30:b3:ba)
    Source: 00:60:cf:42:4c:50 (AlteonNe_42:4c:50)
    Type: IP (0x0800)
    Trailer: 000000000000
Internet Protocol, Src Addr: 192.168.160.1 (192.168.160.1), Dst Addr:
192.168.171.132 (192.168.171.132)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN:
0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 40
    Identification: 0x2913 (10515)
    Flags: 0x00
        .0.. = Don't fragment: Not set
        ..0. = More fragments: Not set
    Fragment offset: 0
    Time to live: 255
    Protocol: TCP (0x06)
    Header checksum: 0xc5e5 (correct)
    Source: 192.168.160.1 (192.168.160.1)
    Destination: 192.168.171.132 (192.168.171.132)
Transmission Control Protocol, Src Port: ssh (22), Dst Port: 2759
(2759), Seq: 3695459050, Ack: 53896138, Len: 0
    Source port: ssh (22)
    Destination port: 2759 (2759)
    Sequence number: 3695459050
    Acknowledgement number: 53896138
    Header length: 20 bytes
    Flags: 0x0010 (ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgment: Set
        .... 0... = Push: Not set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...0 = Fin: Not set
    Window size: 4068
    Checksum: 0x4a0d (correct)



Relevant Pages

  • Re: Client certificate private key prompt
    ... Windows Server 2003 server without the Header manually added to the request. ... Frame 34 will be closing the connection. ... Protocol: TCP ... Transmission Control Protocol, Src Port: 2954, Dst Port: https, ...
    (microsoft.public.dotnet.framework)
  • Sygate Firewall warning
    ... Ethernet II (Packet Length: 76) ... Internet Protocol ... Header checksum: 0x76cd ... Source port: 1161 ...
    (alt.computer.security)
  • Re: Remote access from Internet
    ... An initial proposal was to implement the entire user interface as a Java applet and use a simple back-end protocol to move data. ... The user who desires access connects to relay server with a browser and logs in. ... then you probably need to block all ports *except* for one that you actively manage - ideally by something strong like SSH. ... As a side note on ssh security, there is no need to put ssh on port 22. ...
    (comp.arch.embedded)
  • Re: mystery martian source from 127.0.0.1 - more details
    ... > MAC address in the data link header. ... > This is a TCP reset packet from the WWW server port. ... Transmission Control Protocol, Src Port: http, Dst Port: ...
    (comp.os.linux.security)
  • SSH protocol2 without a password
    ... Have read 'ssh without a password' and apparently the problem lingers. ... # similar for protocol version 2 ... server listening on 0.0.0.0 Port 22 ... failed publickey for root from 192.168.0.1 port 32769 ssh2 ...
    (comp.security.ssh)