tags:

views:

13

answers:

0

Trying to form RTP packets using CCRTP library. I use Wireshark to look at the packets, and see that the packets appear as MALFORMED RTP packet, and fragmented IP packets. Please help.

I am not sure how to attach the error pcap file here. So I am specifying the error packets as .csv format right here.

---------------------------- ERROR PACKETS IN WIRESHARK (.txt format) ----------------------

No.     Time        Source                Destination           Protocol Info
    195 5.197341    192.168.2.2           213.192.59.92         RTP      PT=speex, SSRC=0x74B3A80D, Seq=1794, Time=4058344229 [Malformed Packet]

Frame 195 (215 bytes on wire, 215 bytes captured)
Ethernet II, Src: GemtekTe_22:b0:cf (00:21:00:22:b0:cf), Dst: BelkinIn_cd:16:80 (00:1c:df:cd:16:80)
Internet Protocol, Src: 192.168.2.2 (192.168.2.2), Dst: 213.192.59.92 (213.192.59.92)
User Datagram Protocol, Src Port: irdmi (8000), Dst Port: 23806 (23806)
    Source port: irdmi (8000)
    Destination port: 23806 (23806)
    Length: 9013
    Checksum: 0xef70 [validation disabled]
        [Good Checksum: False]
        [Bad Checksum: False]
Real-Time Transport Protocol
    [Stream setup by SDP (frame 15)]
    10.. .... = Version: RFC 1889 Version (2)
    ..1. .... = Padding: True
    ...0 .... = Extension: False
    .... 0000 = Contributing source identifiers count: 0
    0... .... = Marker: False
    Payload type: speex (97)
    Sequence number: 1794
    [Extended sequence number: 67330]
    Timestamp: 4058344229
    Synchronization Source identifier: 0x74b3a80d (1957931021)
    Payload: 0DA8B374D08EB70100000000800300000000000020000000...
[Malformed Packet: RTP]
    [Expert Info (Error/Malformed): Malformed Packet (Exception occurred)]
        [Message: Malformed Packet (Exception occurred)]
        [Severity level: Error]
        [Group: Malformed]

Frame (215 bytes):

0000  00 1c df cd 16 80 00 21 00 22 b0 cf 08 00 45 00   .......!."....E.
0010  00 c9 5e ea 04 50 40 11 43 23 c0 a8 02 02 d5 c0   ..^[email protected]#......
0020  3b 5c 94 02 00 00 9c 01 00 00 00 00 00 00 00 00   ;\..............
0030  00 00 00 00 00 00 30 00 00 00 56 00 00 00 dc 00   ......0...V.....
0040  00 00 00 00 00 00 00 00 00 00 88 00 00 00 e5 00   ................
0050  00 00 89 02 00 00 1e 02 00 00 00 00 00 00 5b 00   ..............[.
0060  00 00 8d 00 00 00 d7 01 00 00 ec 00 00 00 62 00   ..............b.
0070  00 00 4d 02 00 00 0c 02 00 00 00 00 00 00 01 02   ..M.............
0080  00 00 ac 02 00 00 4c 00 00 00 10 00 00 5b 15 15   ......L......[..
0090  51 45 61 07 00 00 00 00 00 00 b0 2a e8 01 00 00   QEa........*....
00a0  00 00 58 f3 25 b5 ab 7f 00 00 b0 2a e8 01 00 00   ..X.%......*....
00b0  00 00 b0 2a e8 01 00 00 00 00 a7 1d 00 fc f1 19   ...*............
00c0  0f 0b 27 0a 3d 30 ca 27 70 d4 62 94 24 00 00 ee   ..'.=0.'p.b.$...
00d0  0c 60 9f 00 00 00 00                              .`.....

Reassembled IPv4 (9013 bytes):

0000  1f 40 5c fe 23 35 ef 70 a0 61 07 02 f1 e5 6b 25   .@\.#5.p.a....k%
0010  74 b3 a8 0d 0d a8 b3 74 d0 8e b7 01 00 00 00 00   t......t........
0020  80 03 00 00 00 00 00 00 20 00 00 00 00 00 00 00   ........ .......
0030  00 8f b7 01 00 00 00 00 10 8f b7 01 00 00 00 00   ................
0040  79 eb 13 7b 76 98 cd 77 bc 76 77 77 77 77 77 77   y..{v..w.vwwwwww
0050  77 77 dc 08 77 77 28 fb 49 82 63 a4 50 fd 8e 49   ww..ww(.I.c.P..I
0060  6f 4f 9c 94 4f 50 ec ea ba 67 20 0a 5c 4f 62 ba   oO..OP...g .\Ob.
0070  95 36 7a 1e 42 0a 29 9e 65 63 80 08 c1 0e d7 5b   .6z.B.).ec.....[
0080  ae 76 77 77 77 77 3d 30 ae 76 77 77 77 77 3d 30   .vwwww=0.vwwww=0
0090  ae 76 77 77 77 77 77 77 77 77 77 77 77 77 77 77   .vwwwwwwwwwwwwww
00a0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
00b0  77 77 75 77 77 77 77 77 77 77 77 77 77 77 d7 16   wwuwwwwwwwwwww..
00c0  85 76 86 92 1c 52 03 c4 df 7a 7a df c4 03 a7 f9   .v...R...zz.....
00d0  c0 76 77 77 77 77 f7 74 77 77 77 77 77 77 57 77   .vwwww.twwwwwwWw
00e0  77 77 77 77 77 77 77 f8 c0 76 77 77 77 77 67 f8   wwwwwww..vwwwwg.
00f0  c0 76 77 77 77 77 f7 d0 ae 76 77 77 77 77 69 c9   .vwwww...vwwwwi.
0100  ae 76 77 77 77 77 b5 ba ae 76 77 77 77 77 57 67   .vwwww...vwwwwWg
0110  a5 76 77 77 77 77 86 6b a5 76 77 77 77 77 86 6b   .vwwww.k.vwwww.k
0120  a5 76 77 77 77 77 a6 7b 77 77 74 77 75 ee 77 77   .vwwww.{wwtwu.ww
0130  77 77 77 77 77 77 d7 16 75 75 86 92 1c 52 03 c4   wwwwww..uu...R..
0140  df 7a 7a df c4 03 a7 f9 c0 76 77 77 77 77 f7 74   .zz......vwwww.t
0150  77 77 77 77 77 77 57 77 77 77 77 77 77 77 77 f8   wwwwwwWwwwwwwww.
0160  c0 76 77 77 77 77 67 f8 c0 76 77 77 77 77 37 3f   .vwwwwg..vwwww7?
0170  eb 76 77 77 77 77 fb 2e eb 76 77 77 77 77 84 07   .vwwww...vwwww..
0180  eb 76 77 77 77 77 67 bb 9d 76 77 77 77 77 9e 9d   .vwwwwg..vwwww..
0190  9d 76 77 77 77 77 9e 9d 9d 76 77 77 77 77 ae 69   .vwwww...vwwww.i
01a0  77 77 74 77 65 ee 77 77 77 77 77 77 77 77 cd 77   wwtwe.wwwwwwww.w
01b0  b9 76 77 77 77 77 77 77 77 77 dc 08 77 77 87 90   .vwwwwwwww..ww..
01c0  ed 41 45 30 e5 fa 4b ae 4e 73 03 63 72 bc 41 44   .AE0..K.Ns.cr.AD
01d0  31 83 e0 f0 06 81 a7 12 07 7f e0 94 a8 a4 75 e6   1.............u.
01e0  a5 9e 17 a2 1d 06 77 04 e2 76 77 77 77 77 2d fd   ......w..vwwww-.
01f0  e2 76 77 77 77 77 2d fd e2 76 77 77 77 77 77 77   .vwwww-..vwwwwww
0200  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
0210  77 77 77 77 77 77 77 77 77 77 75 77 77 77 77 77   wwwwwwwwwwuwwwww
0220  77 77 77 77 77 77 cd 77 b8 76 77 77 77 77 77 77   wwwwww.w.vwwwwww
0230  77 77 dc 08 77 77 b5 35 8f 18 ee 6d 29 50 91 af   ww..ww.5...m)P..
0240  e5 16 11 b1 bc e6 69 a5 6e e4 b8 21 29 72 c9 00   ......i.n..!)r..
0250  00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00   ................
0260  ba 00 d0 01 00 00 00 00 00 00 00 00 00 00 00 00   ................
0270  c8 bc 98 01 00 00 00 00 88 44 9c 01 00 00 00 00   .........D......
0280  28 ba 98 01 00 00 00 00 01 00 00 00 01 00 00 00   (...............
0290  68 bd 98 01 00 00 00 00 10 aa da 01 00 00 00 00   h...............
<------------------------------ data truncated ------------------------>
2310  b0 2a e8 01 00 00 00 00 a7 1d 00 fc f1 19 0f 0b   .*..............
2320  27 0a 3d 30 ca 27 70 d4 62 94 24 00 00 ee 0c 60   '.=0.'p.b.$....`
2330  9f 00 00 00 00                                    .....

No.     Time        Source                Destination           Protocol Info
    196 5.197785    192.168.2.2           213.192.59.92         IP       Fragmented IP protocol (proto=UDP 0x11, off=0, ID=5eeb) [Reassembled in #205]

Frame 196 (1506 bytes on wire, 1506 bytes captured)
Ethernet II, Src: GemtekTe_22:b0:cf (00:21:00:22:b0:cf), Dst: BelkinIn_cd:16:80 (00:1c:df:cd:16:80)
Internet Protocol, Src: 192.168.2.2 (192.168.2.2), Dst: 213.192.59.92 (213.192.59.92)
Data (1472 bytes)

0000  00 1c df cd 16 80 00 21 00 22 b0 cf 08 00 45 00   .......!."....E.
0010  05 d4 5e eb 20 00 40 11 22 67 c0 a8 02 02 d5 c0   ..^. .@."g......
0020  3b 5c 1f 40 5c fe 34 3b 5e 13 a0 61 08 02 f1 e5   ;\.@\.4;^..a....
0030  6b 25 74 b3 a8 0d 0d a8 b3 74 d0 8e b7 01 00 00   k%t......t......
0040  00 00 80 03 00 00 00 00 00 00 20 00 00 00 00 00   .......... .....
0050  00 00 00 8f b7 01 00 00 00 00 10 8f b7 01 00 00   ................
0060  00 00 79 eb 13 7b 76 98 cd 77 d0 76 77 77 77 77   ..y..{v..w.vwwww
0070  77 77 77 77 77 77 77 77 ff 3b a7 76 77 77 77 77   wwwwwwww.;.vwwww
0080  df e0 c0 76 77 77 77 77 7f 25 f9 76 77 77 77 77   ...vwwww.%.vwwww
0090  ef 76 f9 76 77 77 77 77 77 77 77 77 77 77 77 77   .v.vwwwwwwwwwwww
00a0  07 9e e5 76 77 77 77 77 2d 76 e4 76 77 77 77 77   ...vwwww-v.vwwww
00b0  38 75 e4 76 77 77 77 77 77 77 77 77 77 77 77 77   8u.vwwwwwwwwwwww
00c0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
00d0  77 77 77 77 75 77 77 77 77 77 77 77 77 77 77 77   wwwwuwwwwwwwwwww
00e0  cd 77 df 76 77 77 77 77 77 77 77 77 dc 08 77 77   .w.vwwwwwwww..ww
00f0  bf 0e 9e 06 5b bb 0d 84 cb 95 ac a4 5e fd 3a 54   ....[.......^.:T
0100  38 b2 55 0b 0b 12 de 00 77 77 77 77 77 77 75 77   8.U.....wwwwwwuw
0110  77 77 77 77 77 77 77 77 77 77 cd 77 de 76 77 77   wwwwwwwwww.w.vww
0    120  77 77 77 77 77 77 dc 08 77 77 e0 17 9b fe 65 3a   wwwwww..ww....e:
0130  c9 20 4f 29 92 de 91 c1 94 b4 71 01 f0 1b fc de   . O)......q.....
0140  58 46 fa ae 1f 5b 38 db 72 b0 77 19 87 52 ed 27   XF...[8.r.w..R.'
0150  cd 85 27 b2 e4 76 77 77 77 77 7d 9c e4 76 77 77   ..'..vwwww}..vww
0160  77 77 e7 73 e3 76 77 77 77 77 77 77 77 77 77 77   ww.s.vwwwwwwwwww
0170  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
0180  77 77 77 77 77 77 75 77 77 77 77 77 77 77 77 77   wwwwwwuwwwwwwwww
0190  77 77 cd 77 dd 76 77 77 77 77 77 77 77 77 dc 08   ww.w.vwwwwwwww..
01a0  77 77 85 4b 5e 9c 41 a6 63 ae 02 74 d1 aa cb 77   ww.K^.A.c..t...w
01b0  a9 b5 a9 59 c0 f2 57 48 cb e5 16 b4 5e 5a bf 1c   ...Y..WH....^Z..
01c0  7e d6 ab f2 60 3b 9c 05 40 3a d7 73 e3 76 77 77   ~...`;..@:.s.vww
01d0  77 77 1b 72 e3 76 77 77 77 77 f5 6e e3 76 77 77   ww.r.vwwww.n.vww
01e0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
01f0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 75 77   wwwwwwwwwwwwwwuw
0200  77 77 77 77 77 77 77 77 77 77 cd 77 dc 76 77 77   wwwwwwwwww.w.vww
0210  77 77 77 77 77 77 dc 08 77 77 1c 4a d4 be 65 7e   wwwwww..ww.J..e~
<------------------------------ data truncated ------------------------>
05a0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
05b0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 75 77   wwwwwwwwwwwwwwuw
05c0  77 77 77 77 77 77 77 77 77 77 cd 77 c4 76 77 77   wwwwwwwwww.w.vww
05d0  77 77 77 77 77 77 dc 08 77 77 1a e1 98 f3 07 11   wwwwww..ww......
05e0  e5 0c                                             ..

No.     Time        Source                Destination           Protocol Info
    197 5.197803    192.168.2.2           213.192.59.92         IP       Fragmented IP protocol (proto=UDP 0x11, off=1472, ID=5eeb) [Reassembled in #205]

Frame 197 (1506 bytes on wire, 1506 bytes captured)
Ethernet II, Src: GemtekTe_22:b0:cf (00:21:00:22:b0:cf), Dst: BelkinIn_cd:16:80 (00:1c:df:cd:16:80)
Internet Protocol, Src: 192.168.2.2 (192.168.2.2), Dst: 213.192.59.92 (213.192.59.92)
Data (1472 bytes)

0000  00 1c df cd 16 80 00 21 00 22 b0 cf 08 00 45 00   .......!."....E.
0010  05 d4 5e eb 20 b8 40 11 21 af c0 a8 02 02 d5 c0   ..^. .@.!.......
0020  3b 5c 4c d3 42 eb 62 5e 7c 9c 5e 35 2d db a1 c8   ;\L.B.b^|.^5-...
0030  9d f3 fb 6f 8b bb f6 5f e3 ed 47 b1 ef 0a 5d 3e   ...o..._..G...]>
0040  a3 98 67 a7 e6 76 77 77 77 77 c8 a2 e6 76 77 77   ..g..vwwww...vww
0050  77 77 13 af e6 76 77 77 77 77 77 77 77 77 77 77   ww...vwwwwwwwwww
0060  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
0070  77 77 77 77 77 77 75 77 77 77 77 77 77 77 77 77   wwwwwwuwwwwwwwww
0080  77 77 cd 77 c3 76 77 77 77 77 77 77 77 77 dc 08   ww.w.vwwwwwwww..
0090  77 77 c7 b5 f9 76 77 77 77 77 c7 b5 f9 76 77 77   ww...vwwww...vww
<------------------------------ data truncated ------------------------>
05c0  77 77 f7 74 77 77 77 77 77 77 57 77 77 77 77 77   ww.twwwwwwWwwwww
05d0  77 77 77 f8 c0 76 77 77 77 77 67 f8 c0 76 77 77   www..vwwwwg..vww
05e0  77 77                                             ww

No.     Time        Source                Destination           Protocol Info
    198 5.197812    192.168.2.2           213.192.59.92         IP       Fragmented IP protocol (proto=UDP 0x11, off=2944, ID=5eeb) [Reassembled in #205]

Frame 198 (1506 bytes on wire, 1506 bytes captured)
Ethernet II, Src: GemtekTe_22:b0:cf (00:21:00:22:b0:cf), Dst: BelkinIn_cd:16:80 (00:1c:df:cd:16:80)
Internet Protocol, Src: 192.168.2.2 (192.168.2.2), Dst: 213.192.59.92 (213.192.59.92)
Data (1472 bytes)

0000  00 1c df cd 16 80 00 21 00 22 b0 cf 08 00 45 00   .......!."....E.
0010  05 d4 5e eb 21 70 40 11 20 f7 c0 a8 02 02 d5 c0   ..^.!p@. .......
0020  3b 5c 17 e9 a1 76 77 77 77 77 9f b1 a1 76 77 77   ;\...vwwww...vww
0030  77 77 e6 b8 a1 76 77 77 77 77 b7 f1 91 76 77 77   ww...vwwww...vww
0040  77 77 f6 ec 91 76 77 77 77 77 f6 ec 91 76 77 77   ww...vwwww...vww
0050  77 77 b6 63 77 77 74 77 7d ee 77 77 77 77 77 77   ww.cwwtw}.wwwwww
0060  77 77 d7 16 88 76 86 92 1c 52 03 c4 df 7a 7a df   ww...v...R...zz.
0070  c4 03 a7 f9 c0 76 77 77 77 77 f7 74 77 77 77 77   .....vwwww.twwww
0080  77 77 57 77 77 77 77 77 77 77 77 f8 c0 76 77 77   wwWwwwwwwww..vww
0090  77 77 67 f8 c0 76 77 77 77 77 a7 d7 ee 76 77 77   wwg..vwwww...vww
00a0  77 77 9e d0 ee 76 77 77 77 77 23 a5 ee 76 77 77   ww...vwwww#..vww
00b0  77 77 17 2a 9e 76 77 77 77 77 78 0c 9e 76 77 77   ww.*.vwwwwx..vww
00c0  77 77 78 0c 9e 76 77 77 77 77 d8 6a 77 77 74 77   wwx..vwwww.jwwtw
00d0  78 ee 77 77 77 77 77 77 77 77 cd 77 b6 76 77 77   x.wwwwwwww.w.vww
00e0  77 77 77 77 77 77 dc 08 77 77 30 0d ff 87 ef cb   wwwwww..ww0.....
00f0  fa 87 82 be 6d 4b f9 5c 18 0b c9 58 7b b8 a6 3e   ....mK.\...X{..>
0100  54 2b b3 b9 5a 84 27 ca e5 f2 0e c6 a7 90 c6 3e   T+..Z.'........>
0110  b6 52 b7 58 a0 76 77 77 77 77 ec 1d a0 76 77 77   .R.X.vwwww...vww
0120  77 77 ec 1d a0 76 77 77 77 77 77 77 77 77 77 77   ww...vwwwwwwwwww
0130  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
0140  77 77 77 77 77 77 75 77 77 77 77 77 77 77 77 77   wwwwwwuwwwwwwwww
0150  77 77 cd 77 b5 76 77 77 77 77 77 77 77 77 dc 08   ww.w.vwwwwwwww..
0160  77 77 af ae 13 2a 72 39 fb 1a dd d0 16 bc 3f e9   ww...*r9......?.
0170  cb 2e 9a bd 6c 4c a6 c5 32 c9 40 f2 29 f5 04 c0   ....lL..2.@.)...
0180  7f 94 59 01 5a 96 49 18 05 2f b7 dd a0 76 77 77   ..Y.Z.I../...vww
0190  77 77 dd a6 a0 76 77 77 77 77 dd a6 a0 76 77 77   ww...vwwww...vww
01a0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 77 77   wwwwwwwwwwwwwwww
01b0  77 77 77 77 77 77 77 77 77 77 77 77 77 77 75 77   wwwwwwwwwwwwwwuw
01c0  77 77 77 77 77 77 77 77 77 77 d7 16 73 75 86 92   wwwwwwwwww..su..
01d0  1c 52 03 c4 df 7a 7a df c4 03 a7 f9 c0 76 77 77   .R...zz......vww
01e0  77 77 f7 74 77 77 77 77 77 77 57 77 77 77 77 77   ww.twwwwwwWwwwww
01f0  77 77 77 f8 c0 76 77 77 77 77 67 f8 c0 76 77 77   www..vwwwwg..vww
<------------------------------ data truncated ------------------------>
05c0  c1 0e d7 5b ae 76 77 77 77 77 3d 30 ae 76 77 77   ...[.vwwww=0.vww
05d0  77 77 3d 30 ae 76 77 77 77 77 77 77 77 77 77 77   ww=0.vwwwwwwwwww
05e0  77 77                                             ww