13
CS 135602 : Introduction to Information Engineering Wireshark

CS 135602 : Introduction to Information Engineering

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: CS 135602 : Introduction to Information Engineering

CS 135602 : Introduction to Information Engineering

Wireshark

Page 2: CS 135602 : Introduction to Information Engineering

Introduction

• What is Wireshark?

– Wireshark is a network packet analyzer.

• Examples people use Wireshark for:

– troubleshoot network problems

– examine security problems

– debug protocol implementations

– learn network protocol

2

Page 3: CS 135602 : Introduction to Information Engineering

Download Wireshark

• Get Wireshark

– http://www.wireshark.org/download.html

3

Page 4: CS 135602 : Introduction to Information Engineering

Getting Started

4

Page 5: CS 135602 : Introduction to Information Engineering

Capture Device

5

Page 6: CS 135602 : Introduction to Information Engineering

Result

6

Packet received or transmitted history

Packet information

Page 7: CS 135602 : Introduction to Information Engineering

Example - HTTP

7

Page 8: CS 135602 : Introduction to Information Engineering

The Internet software layers

8

1. HTTP

2. TCP

3. IP

4. Ethernet

4 3 2 1

Page 9: CS 135602 : Introduction to Information Engineering

9

Page 10: CS 135602 : Introduction to Information Engineering

Detail of HTTP Packet Information (1/2)

10

Source & Destination IP

MAC Address

Page 11: CS 135602 : Introduction to Information Engineering

Detail of HTTP Packet Information (2/2)

11

Sequence number for TCP

Information about HTTP

Page 12: CS 135602 : Introduction to Information Engineering

Example - MSN

12

Set the filter to “msnms” for MSN

MSNMS for Application layer

Page 13: CS 135602 : Introduction to Information Engineering

13

My IP address