Learn the basics of TShark and take your protocol and PCAP analysis skills a step further.
Lab link.
Task 2: Command-Line Packet Analysis Hints | TShark and Supplemental CLI Tools
2.2. View the details of the demo.pcapng file with “capinfos”.
What is the “RIPEMD160” value?
data:image/s3,"s3://crabby-images/51983/51983cfc587495193ca0b7423470ce34bd5a4249" alt=""
6ef5f0c165a1db4a3cad3116b0c5bcc0cf6b9ab7
Task 3: TShark Fundamentals I | Main Parameters I
3.1. What is the installed TShark version in the given VM?
data:image/s3,"s3://crabby-images/257c8/257c8f5b62647bd025e2e768aeed0cd160cb7d4c" alt=""
3.2.3
3.2. List the available interfaces with TShark.
What is the number of available interfaces in the given VM?
data:image/s3,"s3://crabby-images/f649e/f649e317dd1b1e18eddcf0635b8b509d493d87ee" alt=""
12
Task 4: TShark Fundamentals I | Main Parameters II
4.1. Read the “demo.pcapng” file with TShark.
What are the assigned TCP flags in the 29th packet?
data:image/s3,"s3://crabby-images/2296b/2296b962daea09dfc41669b9f4d038d9ac5b780e" alt=""
data:image/s3,"s3://crabby-images/bf35f/bf35fb78a580babce7ac02e5e526f9e8564aa018" alt=""
PSH, ACK
4.2. What is the “Ack” value of the 25th packet?
data:image/s3,"s3://crabby-images/f7457/f7457fc70318874fea59fbf46bb06ceebb5cc941" alt=""
12421
4.3. What is the “Window size value” of the 9th packet?
data:image/s3,"s3://crabby-images/4d099/4d0996d0407b7a3c34b717abf8ba9fd28c672ae7" alt=""
9660
Task 5: TShark Fundamentals II | Capture Conditions
5.1. Which parameter can help analysts to create a continuous capture dump?
-b
5.2. Can we combine autostop and ring buffer parameters with TShark? y/n
y
Task 6: TShark Fundamentals III | Packet Filtering Options: Capture vs. Display Filters
6.1. Which parameter is used to set “Capture Filters”?
-f
6.2. Which parameter is used to set “Display Filters”?
-Y
Task 7: TShark Fundamentals IV | Packet Filtering Options: Capture Filters
In the first terminal we execute the following command.
tshark -f "host 10.10.10.10",
data:image/s3,"s3://crabby-images/9acc2/9acc2c968cd905c91aca8034f355ace0d1be445b" alt=""
In the second terminal we execute the following command.
curl -v 10.10.10.10
data:image/s3,"s3://crabby-images/fef93/fef930b5825813df50a4f6f75ec79d5a02d60984" alt=""
After the command in the second terminal, sniffing happens in the first terminal.
7.1. What is the number of packets with SYN bytes?
data:image/s3,"s3://crabby-images/141f3/141f32cb282eb02ea43b942b8827cc7de2787f49" alt=""
2
7.2. What is the number of packets sent to the IP address “10.10.10.10”?
data:image/s3,"s3://crabby-images/bb213/bb21373a45e7ae11159ed50e5566a0d78d949230" alt=""
7
7.3. What is the number of packets with ACK bytes?
data:image/s3,"s3://crabby-images/fa67e/fa67ee5fa3a505b2243859ab0bafaae1c7bafc98" alt=""
8
Task 8: TShark Fundamentals V | Packet Filtering Options: Display Filters
Use the “demo.pcapng” file to answer the questions.
8.1. What is the number of packets with a “65.208.228.223” IP address?
data:image/s3,"s3://crabby-images/e73ef/e73ef4d6e5ebbf6428cb4c9e55c5d28cfc0571b5" alt=""
data:image/s3,"s3://crabby-images/6c8e4/6c8e4714a0fa3204654cde5215ae5d3450e58af7" alt=""
34
8.2. What is the number of packets with a “TCP port 3371”?
data:image/s3,"s3://crabby-images/0b349/0b3498d509c9e36f044e5f2433128f9a56049b87" alt=""
7
8.3. What is the number of packets with a “145.254.160.237” IP address as a source address?
data:image/s3,"s3://crabby-images/f3778/f37785607b158ed738c5a5050ee05bd6cc367271" alt=""
20
8.4. Rerun the previous query and look at the output.
What is the packet number of the “Duplicate” packet?
data:image/s3,"s3://crabby-images/b76d8/b76d8ad516c333e165fb94e779148d8967ffa4c1" alt=""
37