We have managed to capture an incoming post from the client which causes the error. We still haven't got a client side capture due to the difficulty of establishing a direct line with a client who can reproduce the error who has relevant permission / ability to perform network monitoring.
Frame: Number = 9853, Captured Frame Length = 1077, MediaType = ETHERNET
- Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[###########],SourceAddress:[##########]
- DestinationAddress: VMWare, Inc. 8D6B2A [###############]
IG: (0.......) Individual address
UL: (.0......) Universally Administered Address
Rsv: (..000000)
- SourceAddress: Fortinet Inc. 090000 [###############]
UL: .0...... Universally Administered Address
EthernetType: Internet IP (IPv4), 2048(0x800)
- Ipv4: Src = ############, Dest = #########, Next Protocol = TCP, Packet ID = 51719, Total IP Length = 1063
- Versions: IPv4, Internet Protocol; Header Length = 20
Version: (0100....) IPv4, Internet Protocol
HeaderLength: (....0101) 20 bytes (0x5)
- DifferentiatedServicesField: DSCP: 0, ECN: 0
DSCP: (000000..) Differentiated services codepoint 0
ECT: (......0.) ECN-Capable Transport not set
CE: (.......0) ECN-CE not set
TotalLength: 1063 (0x427)
Identification: 51719 (0xCA07)
- FragmentFlags: 16384 (0x4000)
Reserved: (0...............)
DF: (.1..............) Do not fragment
MF: (..0.............) This is the last fragment
Offset: (...0000000000000) 0
TimeToLive: 48 (0x30)
NextProtocol: TCP, 6(0x6)
Checksum: 58238 (0xE37E)
SourceAddress: ###########
DestinationAddress: #########
- Tcp: Flags=...AP..., SrcPort=53991, DstPort=HTTP(80), PayloadLen=1011, Seq=4164216244 - 4164217255, Ack=2415043762, Win=5840 (scale factor 0x0) = 5840
SrcPort: 53991
DstPort: HTTP(80)
SequenceNumber: 4164216244 (0xF834E5B4)
AcknowledgementNumber: 2415043762 (0x8FF2A4B2)
- DataOffset: 128 (0x80)
DataOffset: (1000....) 32 bytes
Reserved: (....000.)
NS: (.......0) Nonce Sum not significant
- Flags: ...AP...
CWR: (0.......) CWR not significant
ECE: (.0......) ECN-Echo not significant
Urgent: (..0.....) Not Urgent Data
Ack: (...1....) Acknowledgement field significant
Push: (....1...) Push Function
Reset: (.....0..) No Reset
Syn: (......0.) Not Synchronize sequence numbers
Fin: (.......0) Not End of data
Window: 5840 (scale factor 0x0) = 5840
Checksum: 0x9D2E, Good
UrgentPointer: 0 (0x0)
- TCPOptions:
- NoOption:
type: No operation. 1(0x1)
- NoOption:
type: No operation. 1(0x1)
- TimeStamp:
type: Timestamp. 8(0x8)
Length: 10 (0xA)
TimestampValue: 1427302923 (0x5512EA0B)
TimestampEchoReply: 0 (0x0)
- Http: Request, POST /qol6.0/de/SpecOrder.aspx
Command: POST
- URI: /qol6.0/de/SpecOrder.aspx
Location: /qol6.0/de/SpecOrder.aspx
ProtocolVersion: HTTP/1.0
Cookie: SessionID=##################; ASPSESSIONIDSSQSQSDC=JPAKJACDCFBLBECBGEPCBNBB; SessionID=########
ContentType: application/x-www-form-urlencoded
UserAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Host: ##############
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Referer: ###########/qol6.0/qmgtrmq.asp?ThisPage=qmgtrm01&Option=#######
Accept-Language: en-nz
UA-CPU: x86
Pragma: no-cache
ContentLength: 0
Via: 1.1 FFX400, 1.1 proxy1.#####.net:80 (squid/2.5.STABLE3), 1.0 proxy1.#####.net:8082 (squid/2.5.STABLE3)
X-Forwarded-For: ######, #####
Cache-Control: max-age=259200
Connection: keep-alive
HeaderEnd: CRLF