




已阅读5页,还剩3页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Test 2. Basic Packet analysis by WiredharkThe Wireshark packet analyser is used to capture and show the control information and data stored in packets transmitted on a network.In order to start capturing packet data transmitted over the network you need to specify an interface on which you want to capture information.1. On the menu bar, click on the capture option in the main Wireshark menu and then select the interfaces. This choice will let you to assign a network adapter for capturing data packets transmitted over the network. Select a network interface that can be used for data collection and click the corresponding Start button. (Such interface will have an IP address corresponding to the network segment was the data you are interested in originates). The data that have been collected during the capture will be shown in the Wireshark application window. To terminate a capture session click on the Stop button.2. The application window is divided into 3 panes. The top pane show a row of information for each packed captured (including a sequence number, capture time, source and destination address, the protocol used and information column about the purpose for each captured packet) . Note: source and destination addresses could be IP, MAC or port addresses (depending on the protocol used by the packet). (The order (ascending/ descending) of the content in each column can be changed by clicking on the Heading)3. The center pane displays the protocols associated by the selected packet. 4. The bottom pane displays the hexadecimal representation of data contained in the selected packet on the left and a character based version of same information on the right. Exercise1.1.Start a capture session and observe the middle pane for a few minutes.2.Open a browser and enter / into the browser address bar and press Enter.3.Once the science direct page displayed click the close button on the browser and Stop the Wireshark capture. Packet FilterThe data captured could be thousands of packets. In order to focus just on those packets which are relevant to the problem, we can use Wireshark filtering utility.Wireshark display filters can be created by typing the keyword into the Filter text box.For example if you want to see only those packets which contain TCP protocol, type TCP in the Filter text box and Wireshark will hide all the packets that do not meet the selection.4.Go to Wireshark window and type ftp in the Filter text box and then click on the Apply Button. Does it work? Why?NO,/ using the protocol is http, rather than ftp.5.To remove a filter and return to the full view click the Clear button.Type DNS in the Filter text box and click on the Apply Button.Does it work? Why?Yes。The Domain Name System (DNS) is a hierarchical decentralized naming system for computers, services, or any resource connected to the Internet or a private network. It associates various information with domain names assigned to each of the participating entities. Most prominently, it translates more readily memorized domain names to the numerical IP addresses needed for the purpose of locating and identifying computer services and devices with the underlying network protocols. By providing a worldwide, distributed directory service, the Domain Name System is an essential component of the functionality of the Internet.The Domain Name System delegates the responsibility of assigning domain names and mapping those names to Internet resources by designating authoritative name servers for each domain. Network administrators may delegate authority over sub-domains of their allocated name space to other name servers. This mechanism provides distributed and fault tolerant service and was designed to avoid a single large central database.6.Create a filter that displays only those packets that use HTTP protocol. Explain how you do this task:To remove a filter and return to the full view click the Clear button.Type HTTP in the Filter text box and click on the Apply Button.Exercise2 1.What is the purpose of DHCP? Can you filter packets that are using DHCP?How?DHCP is a client/server protocol used to dynamically assign IP-address parameters (and other things) to a DHCP client. It is implemented as an option of BOOTP.DHCP usesBOOTPas its transport protocol.Close all the windowsGo to command prompt and ask the server to release your IP address( by typing : Ipconfig/release)Start Wireshark and start filtering Packets associated with DHCP.Go back to thecommand prompt and ask the server to renew your IP address( by typing : Ipconfig/renew)Go to Wireshark and stop the wireshark captureObserve the filtered packets 2.Take a note of destination and source of these packets.Exercise 3In this exercise you will learn to filter and see the packets that your computer receives from one specific source. As an example you are going to capture the packets that you receive from .Logical and Comparison Operators (LCO):Wireshark display filter also use logical and comparison operators including equals (eq), less than (le), greater than (ge), and (and), (or), and (not). For complete list of available display filter go to the Wireshark Filter section in Help menu. Go to this section and explore available operators.1.What protocol is used by Ping command? List the steps that you need to take to check that. 1、open the wireshark,then click start2. Type ICMP in the Filter text box and click on the Apply Button3.win+R and type cmd,then type ping in the window of DOS2.Go to the command prompt and type nslookup www. S. Take a note of the output of this command.3.What is the purpose of nslookup command?Nslookup is a command line driven utility supplied as part of most Windows operating systems that can reveal information related to domain names and the Internet Protocol (IP) addresses associated with them.4.Go to the Wireshark and view only those packets that are coming from .5.What did you wrote into the filter text box?Ip.addr=76.What is most used protocol used in center pane?TCP7.What is the full name and purpose of this protocol?Transmission Control ProtocolThe Transmission Control Protocol (TCP) is a core protocol of the Internet protocol suite. It originated in the initial network implementation in which it complemented the Internet Protocol (IP). There
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025文具店转让合同协议书范本
- 汽车租赁完美合同范本
- 合伙创业股东合同范本
- 汽车销售订购合同范本
- 饿了吗劳务合同范本
- 融租租赁合同范本
- 家政洗涤服务合同范本
- 车库简装改造合同范本
- 借用集体林地合同范本
- 楼房兴建合同范本
- 2024年黑龙江省哈尔滨市中考英语试题卷(含答案及解析)
- 高一语文开学第一课课件
- 非高危行业生产经营单位主要负责人及安全管理人员安全生产知识和管理能力试题及答案
- JGT163-2013钢筋机械连接用套筒
- DL∕T 782-2001 110kV及以上送变电工程启动及竣工验收规程
- 人教版初一数学课程讲义+练习(教师整合版)
- DL∕T 5161.1-2018 电气装置安装工程质量检验及评定规程 第1部分:通则
- 思想政治教育原理方法论
- 2024广西公需课高质量共建“一带一路”谱写人类命运共同体新篇章答案
- 客舱安全与应急处置(含活页实训手册) 课件 模块四 客舱失火处置
- JJG 692-2010无创自动测量血压计
评论
0/150
提交评论