Post Page Advertisement [Top]



Click here to send WhatsApp On Unsaved Mobile Numbers For Free

 

Ethical Hacking Wireshark Deep Dive: Ethernet, ARP, IP, TCP, UDP & DNS Analysis | Day 9
Ethical Hacking

🛡️ Ethical Hacking — Day 9

Wireshark Deep Dive: Ethernet, ARP, IP, TCP, UDP & DNS Analysis

⚠️ LEARNING PURPOSE ONLY: This tutorial is strictly for educational and defensive cybersecurity learning. Capture and analyze traffic only on systems, networks, applications, virtual machines, or labs that you own or have explicit permission to monitor. Never capture another person's traffic, credentials, or private communications without authorization.

Welcome to Day 9 of the Ethical Hacking Learning Series.

On Day 8, we learned the basics of Wireshark, packet capture, display filters, DNS, ICMP, and the TCP three-way handshake.

Today we'll go deeper into what is actually inside a packet.


🎯 Day 9 Learning Objectives

By the end of today, you should understand:

  • Ethernet frames

  • Source and destination MAC addresses

  • ARP packets

  • IPv4 headers

  • Source and destination IP addresses

  • TTL

  • TCP headers

  • TCP sequence numbers

  • TCP acknowledgment numbers

  • TCP flags

  • UDP headers

  • DNS queries and responses

  • Wireshark protocol filters

  • Following conversations

  • Packet statistics

  • Basic packet analysis methodology

  • Equivalent practical exercises on Linux, Windows, and macOS


1. The Packet Layer Model

When you inspect a packet in Wireshark, you'll often see something similar to:

Frame
  ↓
Ethernet II
  ↓
Internet Protocol Version 4
  ↓
Transmission Control Protocol
  ↓
Application Protocol

For example:

Ethernet
   ↓
IPv4
   ↓
TCP
   ↓
HTTPS/TLS

Or:

Ethernet
   ↓
IPv4
   ↓
UDP
   ↓
DNS

This layered structure is fundamental to packet analysis.


2. Ethernet Frame

Ethernet operates at the data-link layer.

An Ethernet frame can contain information such as:

Destination MAC
Source MAC
EtherType
Payload
Frame Check Sequence

Conceptually:

┌─────────────────────────────────────┐
│ Destination MAC                     │
├─────────────────────────────────────┤
│ Source MAC                          │
├─────────────────────────────────────┤
│ EtherType                           │
├─────────────────────────────────────┤
│                                     │
│          IP Packet                  │
│                                     │
└─────────────────────────────────────┘

3. MAC Addresses

A MAC address may look like:

00:11:22:33:44:55

In Wireshark, expand:

Ethernet II

You'll typically find:

Destination
Source
Type

For example:

Ethernet II
    Destination: xx:xx:xx:xx:xx:xx
    Source: xx:xx:xx:xx:xx:xx
    Type: IPv4

Don't publish your actual MAC address in screenshots or blog posts.


🧪 Practical Lab 1 — Ethernet

Start Wireshark and capture traffic from your own computer.

Generate some traffic.

For example:

Linux

ping -c 4 127.0.0.1

macOS

ping -c 4 127.0.0.1

Windows

ping 127.0.0.1 -n 4

Then select a packet and expand:

Frame
Ethernet II

Observe:

Source
Destination
Type

Note: Loopback traffic may not contain a normal Ethernet header. If you want to study Ethernet specifically, capture traffic on your active Wi-Fi/Ethernet interface rather than only the loopback interface.


4. ARP — Address Resolution Protocol

On an IPv4 local network, ARP helps map an IP address to a MAC address.

Imagine your computer wants to communicate with:

192.168.1.1

but needs the corresponding MAC address.

Conceptually:

Computer
   │
   │ Who has 192.168.1.1?
   ▼
Local Network
   │
   ▼
Gateway
   │
   │ I have it.
   ▼
MAC Address

5. ARP Request and Reply

An ARP exchange can look conceptually like:

ARP Request

Who has 192.168.1.1?

        ↓

ARP Reply

192.168.1.1 is at
AA:BB:CC:DD:EE:FF

This is an excellent packet-analysis exercise.


🧪 Practical Lab 2 — Capture ARP

First inspect your local ARP/neighbor information.

Linux

ip neigh

macOS

arp -a

Windows

arp -a

Then start a Wireshark capture on your active local network interface.

Use this display filter:

arp

You may see:

ARP Request
ARP Reply

Your network may not generate a fresh ARP exchange immediately because your operating system can already have the information cached.


6. IPv4 Header

Now select an IPv4 packet and expand:

Internet Protocol Version 4

You'll find fields such as:

Version
Header Length
Differentiated Services
Total Length
Identification
Flags
Fragment Offset
TTL
Protocol
Header Checksum
Source
Destination

Don't try to memorize everything today.

Focus on:

Source
Destination
TTL
Protocol
Total Length

7. Source and Destination IP

Suppose Wireshark shows:

Source: 192.168.1.20
Destination: 192.168.1.1

This tells you the direction of that particular packet.

Remember:

The source and destination are relative to that individual packet.

A response packet will generally reverse those addresses.


8. TTL — Time To Live

IPv4 includes a field called:

TTL

TTL helps prevent packets from circulating indefinitely through routing loops.

Each router that forwards an IPv4 packet generally decreases its TTL.

Conceptually:

TTL 64
   ↓
Router
   ↓
TTL 63
   ↓
Router
   ↓
TTL 62

Eventually, a packet whose TTL reaches zero is discarded.


🧪 Practical Lab 3 — Analyze IPv4

Start a capture.

Generate a connection or other IPv4 traffic from your own computer.

Apply:

ip

Select an IPv4 packet.

Expand:

Internet Protocol Version 4

Record:

Source IP:
Destination IP:
TTL:
Protocol:
Total Length:

Do not publish real private/public addresses from your capture.


9. What Is the IP Protocol Field?

The IPv4 header contains a field identifying the next protocol.

For example:

Protocol: TCP

or:

Protocol: UDP

or:

Protocol: ICMP

This connects the layers:

IPv4
 │
 ├── TCP
 │
 ├── UDP
 │
 └── ICMP

10. TCP Deep Dive

Now we'll examine TCP more closely.

A TCP segment contains information such as:

Source Port
Destination Port
Sequence Number
Acknowledgment Number
Flags
Window Size
Checksum

These fields help TCP provide reliable, ordered communication.


11. TCP Sequence Numbers

TCP uses sequence numbers to keep track of data.

Imagine a stream:

Data:
ABCDEFGHIJ...

TCP doesn't simply say:

"Here is some data."

It tracks where the data belongs within the stream.

Conceptually:

Sequence Number
      ↓
Position of data in TCP stream

12. TCP Acknowledgment Numbers

TCP also uses acknowledgments.

Conceptually:

Client
   │
   │ Data
   │ Seq = X
   ▼
Server
   │
   │ ACK = next expected value
   ▼
Client

This helps the sender know which data has been received.


13. TCP Flags

Important TCP flags include:

FlagPurpose
SYNInitiate/synchronize connection
ACKAcknowledge
FINGracefully close
RSTReset connection
PSHPush data toward application
URGUrgent pointer significant

The most important sequence for beginners remains:

SYN
 ↓
SYN + ACK
 ↓
ACK

🧪 Practical Lab 4 — TCP Handshake

Start Wireshark.

Generate a new TCP connection from your own machine.

Apply:

tcp

Look through the packets for:

[SYN]
[SYN, ACK]
[ACK]

Click the packets and expand:

Transmission Control Protocol

Look for:

Source Port
Destination Port
Sequence Number
Acknowledgment Number
Flags
Window Size

14. Filtering TCP Flags

Wireshark lets you filter specific TCP flags.

For SYN packets:

tcp.flags.syn == 1

For ACK:

tcp.flags.ack == 1

For reset packets:

tcp.flags.reset == 1

For FIN:

tcp.flags.fin == 1

These filters are useful when analyzing TCP behavior.


15. Finding the TCP Handshake

A useful filter is:

tcp.flags.syn == 1

You'll see SYN-related packets.

To find the initial SYN without ACK:

tcp.flags.syn == 1 && tcp.flags.ack == 0

This can make the handshake easier to identify.


16. TCP Conversation

A TCP connection consists of many packets.

Instead of examining each packet independently, you can examine the conversation.

In Wireshark:

Right-click a TCP packet → Follow → TCP Stream

This can help you understand which packets belong to the same TCP conversation.

⚠️ Only follow streams from traffic you are authorized to inspect.


17. TCP Stream Filter

After selecting a TCP conversation, Wireshark may provide a stream identifier.

You can also filter TCP conversations using fields such as:

tcp.stream

For example:

tcp.stream == 0

The exact stream number depends on your capture.


18. UDP Deep Dive

UDP is simpler than TCP.

A UDP header contains:

Source Port
Destination Port
Length
Checksum

There is no TCP-style:

SYN
SYN-ACK
ACK

because UDP is connectionless.


🧪 Practical Lab 5 — UDP

Generate DNS traffic.

Linux

dig example.com

macOS

dig example.com

Windows

nslookup example.com

Then use:

udp

as your Wireshark display filter.

You should be able to identify UDP packets associated with DNS if your DNS traffic is using UDP.


19. DNS Packet Analysis

Now use:

dns

Select a DNS query.

Expand:

Domain Name System

You may see information such as:

Transaction ID
Flags
Questions
Answers
Queries

20. DNS Query

A DNS query might conceptually say:

Client:

What is the IPv4 address for
example.com?

The DNS server responds:

Server:

example.com
→
IPv4 address

In Wireshark, inspect:

Queries
Answers

21. DNS Record Types

You may encounter:

A
AAAA
CNAME
MX
NS
TXT

For example:

A
↓
IPv4 address

AAAA
↓
IPv6 address

🧪 Practical Lab 6 — DNS Query

Start capture.

Run:

Linux/macOS

dig example.com

Windows

nslookup example.com

Stop the capture.

Apply:

dns

Find your DNS query.

Record:

Query name:
Query type:
DNS server:
Response:

22. DNS Over HTTPS / TLS

Not all DNS traffic is plain DNS over UDP port 53.

Modern systems and applications can use encrypted DNS technologies such as:

DNS over HTTPS
DNS over TLS

Therefore, simply filtering:

dns

may not reveal every DNS lookup generated by every application.

This is an important lesson:

Absence of visible plaintext DNS does not necessarily mean no DNS resolution occurred.


23. HTTP Analysis

If you have a local HTTP service or an authorized HTTP lab, you can filter:

http

You may see:

GET
POST
HTTP/1.1
Host
User-Agent

For example:

GET /index.html HTTP/1.1

⚠️ HTTP Privacy Warning

Plain HTTP can expose application data to anyone who can legitimately observe that traffic.

This is one reason HTTPS is important.

Never capture another person's HTTP traffic.


24. HTTPS / TLS

For HTTPS traffic, use:

tls

You may see:

Client Hello
Server Hello
Certificate
Encrypted Application Data

Modern TLS encrypts application data, so Wireshark generally cannot simply display the underlying HTTPS content as readable HTTP without the necessary session keys and appropriate authorized analysis setup.


25. TLS Client Hello

A TLS Client Hello can contain useful metadata such as:

  • TLS version information

  • Cipher-suite information

  • Extensions

  • Server Name Indication (where applicable)

  • Supported groups

This demonstrates an important security concept:

Encryption protects content, but network traffic can still expose metadata.


🧪 Practical Lab 7 — TLS

Generate HTTPS traffic from your own computer.

Open a website you are authorized to access.

Then filter:

tls

Find a:

Client Hello

Expand it.

Look at:

Handshake Protocol
Extensions
Supported Versions

Don't attempt to decrypt traffic that you aren't authorized to analyze.


26. Wireshark Statistics

Wireshark provides several statistics tools that help summarize a capture.

Useful areas include:

Statistics
    ↓
Protocol Hierarchy
    ↓
Conversations
    ↓
Endpoints

These are useful for understanding your own capture at a higher level.


27. Protocol Hierarchy

The protocol hierarchy can give you a summary such as:

Ethernet
 └── IPv4
      ├── TCP
      │    └── TLS
      └── UDP
           └── DNS

This gives you a quick overview of the protocols present in your capture.


28. Conversations

The Conversations view can help identify communication pairs.

Conceptually:

Endpoint A
     ↕
Endpoint B

You can investigate:

Packets
Bytes
Duration
Direction

Only analyze endpoints belonging to your authorized capture.


29. Endpoints

The Endpoints view helps identify addresses seen in the capture.

For example:

IPv4
MAC
TCP
UDP

This can help answer:

"Which addresses actually appeared in this capture?"


🧪 Day 9 Main Practical Lab

Let's combine everything.

Step 1 — Start Wireshark

Select your active interface.


Step 2 — Start Capture

Capture only your own authorized traffic.


Step 3 — Generate DNS Traffic

Linux/macOS

dig example.com

Windows

nslookup example.com

Step 4 — Generate ICMP Traffic

Linux/macOS

ping -c 4 127.0.0.1

Windows

ping 127.0.0.1 -n 4

Step 5 — Generate Normal HTTPS Traffic

Open an HTTPS website using your browser.


Step 6 — Stop Capture

Save as:

day9-wireshark-analysis.pcapng

🔎 Step 7 — Analyze the Capture

Use these filters one at a time:

arp
ip
tcp
udp
dns
tls
icmp

🔬 Step 8 — Analyze TCP Flags

Try:

tcp.flags.syn == 1

Then:

tcp.flags.fin == 1

Then:

tcp.flags.reset == 1

Observe how different TCP events appear.


📊 Step 9 — Create Your Analysis Table

ProtocolWhat did you observe?
Ethernet__________
ARP__________
IPv4__________
TCP__________
UDP__________
DNS__________
ICMP__________
TLS__________

🐧 Linux Command-Line Analysis with TShark

If TShark is installed:

tshark --version

List interfaces:

tshark -D

Read your capture:

tshark -r day9-wireshark-analysis.pcapng

Display DNS packets:

tshark -r day9-wireshark-analysis.pcapng -Y "dns"

Display TCP packets:

tshark -r day9-wireshark-analysis.pcapng -Y "tcp"

Display TCP SYN packets:

tshark -r day9-wireshark-analysis.pcapng -Y "tcp.flags.syn == 1"

🪟 Windows Command-Line Analysis

PowerShell:

tshark --version

List interfaces:

tshark -D

Read your capture:

tshark -r day9-wireshark-analysis.pcapng

DNS:

tshark -r day9-wireshark-analysis.pcapng -Y "dns"

TCP:

tshark -r day9-wireshark-analysis.pcapng -Y "tcp"

TCP SYN:

tshark -r day9-wireshark-analysis.pcapng -Y "tcp.flags.syn == 1"

🍎 macOS Command-Line Analysis

Terminal:

tshark --version

List interfaces:

tshark -D

Read the capture:

tshark -r day9-wireshark-analysis.pcapng

DNS:

tshark -r day9-wireshark-analysis.pcapng -Y "dns"

TCP:

tshark -r day9-wireshark-analysis.pcapng -Y "tcp"

TCP SYN:

tshark -r day9-wireshark-analysis.pcapng -Y "tcp.flags.syn == 1"

🧠 Day 9 Security Mindset

When analyzing packets, don't immediately ask:

"Can I attack this?"

Instead ask:

1. What is happening?

What protocol?

2. Who is communicating?

Source ↔ Destination

3. How are they communicating?

TCP?
UDP?
ICMP?

4. What information is visible?

Metadata?
Plaintext?
Encrypted?

5. Is the communication expected?

Normal?
Unexpected?
Suspicious?

6. What security control protects it?

TLS?
Firewall?
Authentication?
Network segmentation?

This is the mindset of a defensive security professional.


📝 Day 9 Assignment

Answer these questions:

1.

What is an Ethernet frame?

2.

What information can you find under Ethernet II?

3.

What is ARP used for?

4.

What is the difference between a MAC address and an IP address?

5.

What does the IPv4 TTL field do?

6.

What is a TCP sequence number?

7.

What is a TCP acknowledgment number?

8.

What are SYN, ACK, FIN, and RST?

9.

Why doesn't UDP use the TCP three-way handshake?

10.

What information can you find inside a DNS query?

11.

What is the difference between HTTP and HTTPS from a packet-analysis perspective?

12.

Why can encrypted traffic still reveal metadata?


🏆 Day 9 Challenge

Complete this investigation using your own authorized traffic:

Start Wireshark
       ↓
Capture traffic
       ↓
Generate DNS traffic
       ↓
Generate ICMP traffic
       ↓
Generate HTTPS traffic
       ↓
Stop capture
       ↓
Find ARP
       ↓
Find IPv4
       ↓
Find TCP
       ↓
Find UDP
       ↓
Find DNS
       ↓
Find TLS
       ↓
Analyze TCP flags
       ↓
Check Protocol Hierarchy
       ↓
Check Conversations
       ↓
Write observations

Then answer:

What is the difference between what an application does and how that activity appears on the network?

For example:

Application:
"Open a website"

Network:
DNS
 ↓
TCP
 ↓
TLS
 ↓
Encrypted Application Data

Understanding this relationship is a major step toward professional network security analysis.


⚠️ Ethical Hacking Reminder

LEARNING PURPOSE ONLY: Wireshark and TShark can expose sensitive network information. Use them only on your own computer, your own lab, or a network for which you have explicit authorization. Never capture passwords, cookies, personal communications, or other users' traffic without permission.

Capture ethically. Analyze responsibly. Protect privacy.


✅ Day 9 Summary

Today you learned:

  • Ethernet frames

  • MAC addresses

  • ARP

  • IPv4 headers

  • Source and destination IPs

  • TTL

  • TCP headers

  • Sequence numbers

  • Acknowledgment numbers

  • TCP flags

  • TCP conversations

  • UDP

  • DNS analysis

  • HTTP and HTTPS

  • TLS

  • Wireshark statistics

  • Protocol hierarchy

  • Conversations

  • Endpoints

  • TShark analysis

  • Practical analysis on Linux, Windows and macOS

🔐 Key Lesson

A security professional doesn't just see packets—they understand the story those packets tell.


🔜 Day 10 — Reconnaissance Fundamentals

Tomorrow we'll begin learning reconnaissance, one of the earliest phases of an authorized penetration test.

We'll cover:

  • Passive vs active reconnaissance

  • Attack surface

  • Domains and subdomains

  • DNS information

  • WHOIS concepts

  • IP and hosting information

  • Technology identification

  • Metadata

  • Search-engine-based information gathering

  • Linux, Windows and macOS tools

  • Building a safe reconnaissance lab

  • Documentation and scope control

⚠️ All reconnaissance exercises will remain focused on your own assets or explicitly authorized targets.

🔐 LEARN → CAPTURE → ANALYZE → UNDERSTAND → SECURE.

No comments:

Post a Comment

Bottom Ad [Post Page]

rrkksinha.