Beruflich Dokumente
Kultur Dokumente
Appendix A:
Wireshark Lab
Exercises
Wireshark University™
Slow Browsing
Trace File: extra01.pcap
This trace begins with a really slow DNS response. In fact, the client
sends out two DNS queries. When the first DNS response arrives, the
client shuts down the listening port and responds to the second DNS
response with an ICMP Destination Unreachable/Port Unreachable. How
much delay was caused by packet loss?
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
DHCP Slow
Trace File: misc04.pcap
You know it's going to be a bad day when the first one you talk to ignores you. In this
case the client sends a DHCP Discover out and waits six seconds without a reply (you
could hear a pin drop). When the server does finally answer the client already has
another Discover queued up and ready to send – out it goes. Let's hope the rest of the
day goes better.
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
Bad FTP
Trace File: extra03.pcap
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
FTP Fail
Trace File: extra04.pcap
• The client?
• The server?
• The network?
• The application?
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
POST no Bills
Trace File: extra05.pcap
HTTP clients use the POST command to send data to HTTP servers. In this case, the
client does not receive the expected confirmation message.
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
Poisoned
Trace File: sym-404.pcap
A system appears to have been infected with a virus. After checking the system, you
notice that the virus detection software is out-of-date even though it is set up for
automatic update. You want to analyze the update process to ensure it is working
properly.
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
Client Frustrated
Trace File: extra07.pcap
The user complains that the “network is down.” You have captured the traffic as the
client tries to connect to a web server.
Step 2. Review the Appendix A video for an introduction and your questions for
this lab. The video of the lab answers follow the introduction.
Notes:
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________
_______________________________________________