Sie sind auf Seite 1von 15

WireShark

plus
ASCII character set
and
TCP/IP protocols

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 1

The Rules
Message Encoding

encode decode

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 2

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Data Encapsulation

Protocol Data Units (PDUs)

Data

Segment

Packet

Frame

Bits
bits

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 3

 Labels in encapsulation headers are used to manage


communication in data networks

Application
NIC Operating s/w
Card System
Letters
Hexdecimal IPv4 Decimal &
Symbols

1010101010101011111011110001000100010001000010101111111111110

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 4

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
The Rules

Message Coding & Decoding

 Binary to Decimal

 Binary to HexaDecimal

For Example:  Binary to ASCII

 Binary to ??? Application unique


(JPEG, WAV, )

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 5

The Rules
Binary to ASCII: the Character Map

.
2007 Cisco Systems, Inc. All rights reserved. Cisco Public 6

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
 How do you know where to start?
 NIC card SFD start frame delimiter
Common to layer 2 protocols
Timing & Synchronization

1010101010101011111011110001000100010001000010101111111111110
NIC card
Ethernet = HEX

Addressing and Naming Schemes


 Labels in encapsulation headers are used to manage
communication in data networks

Layer 2 Operating Application


card System s/w
(ethernet, wireless,
serial COM,)

1010101010101011111011110001000100010001000010101111111111110

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 12

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
 Layers 1 & 2: Binary to HEX
 Layers 3 & 4: Binary to Decimal
 Layers 5-6-7: Application Layer:
- Bits to ASCII character map
- App: Bits to JPEG, MPEG, etc bits is bits

Application
Operating
1010101010101011111011110001000100010001000010101111111111110
NIC card System
s/w
Ethernet = HEX IP = Decimal Whatever ?

What you did in the


ASCII character map exercise

1010101010101011111011110001000100010001000010101111111111110

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
WireShark decodes the bits it sniffs

IP packet

.
Bits
to
Ethernet
& IP
.

Bits .
to
HEX
and ASCII
.

WireShark decodes the bits it sniffs

IP packet

.
Bits
to
Ethernet
& IP
.

Bits
to
HEX Bits for Frame #2
and ASCII

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
WireShark decodes the bits it sniffs

IP packet
.
Bits
to
Ethernet
& IP
.
.
Bits
to
HEX Bits for Frame #3
and ASCII
.

Filtering from NIC to the O/S

NIC Operating Application


card System s/w
Promiscuous Mode Application
(wireshark)

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 19

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
WireShark LABs
Find the interfaces: IPconfig

WireShark LABs

Find the interfaces: ipconfig /all

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
WireShark LABs
Find the interfaces: But which one ? The names dont match !

Loop
MS is software

WireShark LABs
Pick the correct interface

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Start Capture in WireShark, then Start an Application
.

Start an Application (ping)


.

Send an ICMP request to another computer

PING
generates

ICMP requests

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
With WireShark in capture mode,
and an application generating traffic,
use WireShark to view the PDUs

LAB  WireShark Sniffing


Use WireShark to view the PDUs

LAB 3.4.1.2 p.70 - Using WireShark

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Lecture Part 2
Session 5

O/S to NIC card


Binding

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 31

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Couple more notes on NIC cards

TCP
O/S
To IP
NIC card Ethernet or Wireless
Binding

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 32

Binding from NIC to the O/S

NIC Operating Application


card System s/w

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 33

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Binding order and what if you have more than one NIC ?

Establishes the protocol to use first


when a network connection is established

The client computer in an exchange determines


the protocol to use to establish the connection

You can manually change the binding order of the


protocols to enhance network performance

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 34

Changing the binding order


IPX-SPX
is obsolete
LAN Novell

LAN
Use the Up and
Down arrow
buttons to change
the order in which
protocols are
bound to the NIC

2007 Cisco Systems, Inc. All rights reserved. Cisco Public 35

Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Copyright 2001, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr

Das könnte Ihnen auch gefallen