Wireshark Lab 2

来源:互联网 发布:base64 java 保存图片 编辑:程序博客网 时间:2024/05/25 05:37

第二次wireshark作业,讲了一些较为实用的技巧,记录一下

What to do:
A. Run your wireshark for a few seconds and save the capture files on your desktop (test.pcapng)
B. Restart your Wireshark and open test.pcapng
C. Take a screen shot and paste it here

这里写图片描述

这里写图片描述

What to do: The newer version does not display a pop-up window. A line of command will appear below the live capturing packet filter window.
A. Open the find packet dialog. Apply filter to find ARP or TCP if you don’t have ARP. Take a screen shot and paste it HERE

这里写图片描述

这里写图片描述

What to do:
A. Mark the first packet you found in the previous tasks and take a screen shot.

这里写图片描述

这里写图片描述

这里写图片描述

What to do:
A. Follow the instruction except the port number. Instead use port 1900.
B. Run a few seconds and save your captured file as test2.pcapng
C. Take a screen shot

这里写图片描述

这里写图片描述

这里写图片描述

What to do:
A. Open your test.pcapng file and bring up endpoints dialogue. Choose IPv4 tap.
B. Make a screen-shot and put it HERE.

这里写图片描述

这里写图片描述

What to do:
A. Open your test.pcapng file again if it’s closed and bring up conversation dialogue. Choose IPv4 tap. Make a screen-shot and put it HERE.

这里写图片描述

B. Download lotsofweb.pcap and open it from your wireshark. Open endpoint dialogue box and choose IPv4 tab
Analyze top talkers and identify potential problems. What services/applications are making trouble for this network? : Write your answer HERE. Formulate your answer considering the following tips
• Which device is local, which is not? How do you know it?

这里写图片描述

172.16.X.X is local address.
74.125.103.163 is not.

• If you found suspicious non-local devices that cause problem, use whois service (http://www.geektools.com/whois.php) to identify its organization
It is Google, and analysis the traffic, it is probably from video clips, so we can guess it was coming from youtube

这里写图片描述

• Filter out packets which are related to the problematic device. Identify the nature of traffic (Guess with what you know already)

这里写图片描述

Usually the video clips are transmitted by UDP, but here are TCPs, we can guess it was the YouTube, in order to control it precisely with navigation bar, uses TCP to transmit video clips.

Submit this document with appropriate answers, test.pcapng, and test2.pcap ng on Canvas

0 0
原创粉丝点击