![]() |
| Ethical Hacking |
🛡️ Ethical Hacking — Day 9
Wireshark Deep Dive: Ethernet, ARP, IP, TCP, UDP & DNS Analysis
⚠️ LEARNING PURPOSE ONLY: This tutorial is strictly for educational and defensive cybersecurity learning. Capture and analyze traffic only on systems, networks, applications, virtual machines, or labs that you own or have explicit permission to monitor. Never capture another person's traffic, credentials, or private communications without authorization.
Welcome to Day 9 of the Ethical Hacking Learning Series.
On Day 8, we learned the basics of Wireshark, packet capture, display filters, DNS, ICMP, and the TCP three-way handshake.
Today we'll go deeper into what is actually inside a packet.
🎯 Day 9 Learning Objectives
By the end of today, you should understand:
Ethernet frames
Source and destination MAC addresses
ARP packets
IPv4 headers
Source and destination IP addresses
TTL
TCP headers
TCP sequence numbers
TCP acknowledgment numbers
TCP flags
UDP headers
DNS queries and responses
Wireshark protocol filters
Following conversations
Packet statistics
Basic packet analysis methodology
Equivalent practical exercises on Linux, Windows, and macOS
1. The Packet Layer Model
When you inspect a packet in Wireshark, you'll often see something similar to:
Frame
↓
Ethernet II
↓
Internet Protocol Version 4
↓
Transmission Control Protocol
↓
Application Protocol
For example:
Ethernet
↓
IPv4
↓
TCP
↓
HTTPS/TLS
Or:
Ethernet
↓
IPv4
↓
UDP
↓
DNS
This layered structure is fundamental to packet analysis.
2. Ethernet Frame
Ethernet operates at the data-link layer.
An Ethernet frame can contain information such as:
Destination MAC
Source MAC
EtherType
Payload
Frame Check Sequence
Conceptually:
┌─────────────────────────────────────┐
│ Destination MAC │
├─────────────────────────────────────┤
│ Source MAC │
├─────────────────────────────────────┤
│ EtherType │
├─────────────────────────────────────┤
│ │
│ IP Packet │
│ │
└─────────────────────────────────────┘
3. MAC Addresses
A MAC address may look like:
00:11:22:33:44:55
In Wireshark, expand:
Ethernet II
You'll typically find:
Destination
Source
Type
For example:
Ethernet II
Destination: xx:xx:xx:xx:xx:xx
Source: xx:xx:xx:xx:xx:xx
Type: IPv4
Don't publish your actual MAC address in screenshots or blog posts.
🧪 Practical Lab 1 — Ethernet
Start Wireshark and capture traffic from your own computer.
Generate some traffic.
For example:
Linux
ping -c 4 127.0.0.1
macOS
ping -c 4 127.0.0.1
Windows
ping 127.0.0.1 -n 4
Then select a packet and expand:
Frame
Ethernet II
Observe:
Source
Destination
Type
Note: Loopback traffic may not contain a normal Ethernet header. If you want to study Ethernet specifically, capture traffic on your active Wi-Fi/Ethernet interface rather than only the loopback interface.
4. ARP — Address Resolution Protocol
On an IPv4 local network, ARP helps map an IP address to a MAC address.
Imagine your computer wants to communicate with:
192.168.1.1
but needs the corresponding MAC address.
Conceptually:
Computer
│
│ Who has 192.168.1.1?
▼
Local Network
│
▼
Gateway
│
│ I have it.
▼
MAC Address
5. ARP Request and Reply
An ARP exchange can look conceptually like:
ARP Request
Who has 192.168.1.1?
↓
ARP Reply
192.168.1.1 is at
AA:BB:CC:DD:EE:FF
This is an excellent packet-analysis exercise.
🧪 Practical Lab 2 — Capture ARP
First inspect your local ARP/neighbor information.
Linux
ip neigh
macOS
arp -a
Windows
arp -a
Then start a Wireshark capture on your active local network interface.
Use this display filter:
arp
You may see:
ARP Request
ARP Reply
Your network may not generate a fresh ARP exchange immediately because your operating system can already have the information cached.
6. IPv4 Header
Now select an IPv4 packet and expand:
Internet Protocol Version 4
You'll find fields such as:
Version
Header Length
Differentiated Services
Total Length
Identification
Flags
Fragment Offset
TTL
Protocol
Header Checksum
Source
Destination
Don't try to memorize everything today.
Focus on:
Source
Destination
TTL
Protocol
Total Length
7. Source and Destination IP
Suppose Wireshark shows:
Source: 192.168.1.20
Destination: 192.168.1.1
This tells you the direction of that particular packet.
Remember:
The source and destination are relative to that individual packet.
A response packet will generally reverse those addresses.
8. TTL — Time To Live
IPv4 includes a field called:
TTL
TTL helps prevent packets from circulating indefinitely through routing loops.
Each router that forwards an IPv4 packet generally decreases its TTL.
Conceptually:
TTL 64
↓
Router
↓
TTL 63
↓
Router
↓
TTL 62
Eventually, a packet whose TTL reaches zero is discarded.
🧪 Practical Lab 3 — Analyze IPv4
Start a capture.
Generate a connection or other IPv4 traffic from your own computer.
Apply:
ip
Select an IPv4 packet.
Expand:
Internet Protocol Version 4
Record:
Source IP:
Destination IP:
TTL:
Protocol:
Total Length:
Do not publish real private/public addresses from your capture.
9. What Is the IP Protocol Field?
The IPv4 header contains a field identifying the next protocol.
For example:
Protocol: TCP
or:
Protocol: UDP
or:
Protocol: ICMP
This connects the layers:
IPv4
│
├── TCP
│
├── UDP
│
└── ICMP
10. TCP Deep Dive
Now we'll examine TCP more closely.
A TCP segment contains information such as:
Source Port
Destination Port
Sequence Number
Acknowledgment Number
Flags
Window Size
Checksum
These fields help TCP provide reliable, ordered communication.
11. TCP Sequence Numbers
TCP uses sequence numbers to keep track of data.
Imagine a stream:
Data:
ABCDEFGHIJ...
TCP doesn't simply say:
"Here is some data."
It tracks where the data belongs within the stream.
Conceptually:
Sequence Number
↓
Position of data in TCP stream
12. TCP Acknowledgment Numbers
TCP also uses acknowledgments.
Conceptually:
Client
│
│ Data
│ Seq = X
▼
Server
│
│ ACK = next expected value
▼
Client
This helps the sender know which data has been received.
13. TCP Flags
Important TCP flags include:
| Flag | Purpose |
|---|---|
| SYN | Initiate/synchronize connection |
| ACK | Acknowledge |
| FIN | Gracefully close |
| RST | Reset connection |
| PSH | Push data toward application |
| URG | Urgent pointer significant |
The most important sequence for beginners remains:
SYN
↓
SYN + ACK
↓
ACK
🧪 Practical Lab 4 — TCP Handshake
Start Wireshark.
Generate a new TCP connection from your own machine.
Apply:
tcp
Look through the packets for:
[SYN]
[SYN, ACK]
[ACK]
Click the packets and expand:
Transmission Control Protocol
Look for:
Source Port
Destination Port
Sequence Number
Acknowledgment Number
Flags
Window Size
14. Filtering TCP Flags
Wireshark lets you filter specific TCP flags.
For SYN packets:
tcp.flags.syn == 1
For ACK:
tcp.flags.ack == 1
For reset packets:
tcp.flags.reset == 1
For FIN:
tcp.flags.fin == 1
These filters are useful when analyzing TCP behavior.
15. Finding the TCP Handshake
A useful filter is:
tcp.flags.syn == 1
You'll see SYN-related packets.
To find the initial SYN without ACK:
tcp.flags.syn == 1 && tcp.flags.ack == 0
This can make the handshake easier to identify.
16. TCP Conversation
A TCP connection consists of many packets.
Instead of examining each packet independently, you can examine the conversation.
In Wireshark:
Right-click a TCP packet → Follow → TCP Stream
This can help you understand which packets belong to the same TCP conversation.
⚠️ Only follow streams from traffic you are authorized to inspect.
17. TCP Stream Filter
After selecting a TCP conversation, Wireshark may provide a stream identifier.
You can also filter TCP conversations using fields such as:
tcp.stream
For example:
tcp.stream == 0
The exact stream number depends on your capture.
18. UDP Deep Dive
UDP is simpler than TCP.
A UDP header contains:
Source Port
Destination Port
Length
Checksum
There is no TCP-style:
SYN
SYN-ACK
ACK
because UDP is connectionless.
🧪 Practical Lab 5 — UDP
Generate DNS traffic.
Linux
dig example.com
macOS
dig example.com
Windows
nslookup example.com
Then use:
udp
as your Wireshark display filter.
You should be able to identify UDP packets associated with DNS if your DNS traffic is using UDP.
19. DNS Packet Analysis
Now use:
dns
Select a DNS query.
Expand:
Domain Name System
You may see information such as:
Transaction ID
Flags
Questions
Answers
Queries
20. DNS Query
A DNS query might conceptually say:
Client:
What is the IPv4 address for
example.com?
The DNS server responds:
Server:
example.com
→
IPv4 address
In Wireshark, inspect:
Queries
Answers
21. DNS Record Types
You may encounter:
A
AAAA
CNAME
MX
NS
TXT
For example:
A
↓
IPv4 address
AAAA
↓
IPv6 address
🧪 Practical Lab 6 — DNS Query
Start capture.
Run:
Linux/macOS
dig example.com
Windows
nslookup example.com
Stop the capture.
Apply:
dns
Find your DNS query.
Record:
Query name:
Query type:
DNS server:
Response:
22. DNS Over HTTPS / TLS
Not all DNS traffic is plain DNS over UDP port 53.
Modern systems and applications can use encrypted DNS technologies such as:
DNS over HTTPS
DNS over TLS
Therefore, simply filtering:
dns
may not reveal every DNS lookup generated by every application.
This is an important lesson:
Absence of visible plaintext DNS does not necessarily mean no DNS resolution occurred.
23. HTTP Analysis
If you have a local HTTP service or an authorized HTTP lab, you can filter:
http
You may see:
GET
POST
HTTP/1.1
Host
User-Agent
For example:
GET /index.html HTTP/1.1
⚠️ HTTP Privacy Warning
Plain HTTP can expose application data to anyone who can legitimately observe that traffic.
This is one reason HTTPS is important.
Never capture another person's HTTP traffic.
24. HTTPS / TLS
For HTTPS traffic, use:
tls
You may see:
Client Hello
Server Hello
Certificate
Encrypted Application Data
Modern TLS encrypts application data, so Wireshark generally cannot simply display the underlying HTTPS content as readable HTTP without the necessary session keys and appropriate authorized analysis setup.
25. TLS Client Hello
A TLS Client Hello can contain useful metadata such as:
TLS version information
Cipher-suite information
Extensions
Server Name Indication (where applicable)
Supported groups
This demonstrates an important security concept:
Encryption protects content, but network traffic can still expose metadata.
🧪 Practical Lab 7 — TLS
Generate HTTPS traffic from your own computer.
Open a website you are authorized to access.
Then filter:
tls
Find a:
Client Hello
Expand it.
Look at:
Handshake Protocol
Extensions
Supported Versions
Don't attempt to decrypt traffic that you aren't authorized to analyze.
26. Wireshark Statistics
Wireshark provides several statistics tools that help summarize a capture.
Useful areas include:
Statistics
↓
Protocol Hierarchy
↓
Conversations
↓
Endpoints
These are useful for understanding your own capture at a higher level.
27. Protocol Hierarchy
The protocol hierarchy can give you a summary such as:
Ethernet
└── IPv4
├── TCP
│ └── TLS
└── UDP
└── DNS
This gives you a quick overview of the protocols present in your capture.
28. Conversations
The Conversations view can help identify communication pairs.
Conceptually:
Endpoint A
↕
Endpoint B
You can investigate:
Packets
Bytes
Duration
Direction
Only analyze endpoints belonging to your authorized capture.
29. Endpoints
The Endpoints view helps identify addresses seen in the capture.
For example:
IPv4
MAC
TCP
UDP
This can help answer:
"Which addresses actually appeared in this capture?"
🧪 Day 9 Main Practical Lab
Let's combine everything.
Step 1 — Start Wireshark
Select your active interface.
Step 2 — Start Capture
Capture only your own authorized traffic.
Step 3 — Generate DNS Traffic
Linux/macOS
dig example.com
Windows
nslookup example.com
Step 4 — Generate ICMP Traffic
Linux/macOS
ping -c 4 127.0.0.1
Windows
ping 127.0.0.1 -n 4
Step 5 — Generate Normal HTTPS Traffic
Open an HTTPS website using your browser.
Step 6 — Stop Capture
Save as:
day9-wireshark-analysis.pcapng
🔎 Step 7 — Analyze the Capture
Use these filters one at a time:
arp
ip
tcp
udp
dns
tls
icmp
🔬 Step 8 — Analyze TCP Flags
Try:
tcp.flags.syn == 1
Then:
tcp.flags.fin == 1
Then:
tcp.flags.reset == 1
Observe how different TCP events appear.
📊 Step 9 — Create Your Analysis Table
| Protocol | What did you observe? |
|---|---|
| Ethernet | __________ |
| ARP | __________ |
| IPv4 | __________ |
| TCP | __________ |
| UDP | __________ |
| DNS | __________ |
| ICMP | __________ |
| TLS | __________ |
🐧 Linux Command-Line Analysis with TShark
If TShark is installed:
tshark --version
List interfaces:
tshark -D
Read your capture:
tshark -r day9-wireshark-analysis.pcapng
Display DNS packets:
tshark -r day9-wireshark-analysis.pcapng -Y "dns"
Display TCP packets:
tshark -r day9-wireshark-analysis.pcapng -Y "tcp"
Display TCP SYN packets:
tshark -r day9-wireshark-analysis.pcapng -Y "tcp.flags.syn == 1"
🪟 Windows Command-Line Analysis
PowerShell:
tshark --version
List interfaces:
tshark -D
Read your capture:
tshark -r day9-wireshark-analysis.pcapng
DNS:
tshark -r day9-wireshark-analysis.pcapng -Y "dns"
TCP:
tshark -r day9-wireshark-analysis.pcapng -Y "tcp"
TCP SYN:
tshark -r day9-wireshark-analysis.pcapng -Y "tcp.flags.syn == 1"
🍎 macOS Command-Line Analysis
Terminal:
tshark --version
List interfaces:
tshark -D
Read the capture:
tshark -r day9-wireshark-analysis.pcapng
DNS:
tshark -r day9-wireshark-analysis.pcapng -Y "dns"
TCP:
tshark -r day9-wireshark-analysis.pcapng -Y "tcp"
TCP SYN:
tshark -r day9-wireshark-analysis.pcapng -Y "tcp.flags.syn == 1"
🧠 Day 9 Security Mindset
When analyzing packets, don't immediately ask:
"Can I attack this?"
Instead ask:
1. What is happening?
What protocol?
2. Who is communicating?
Source ↔ Destination
3. How are they communicating?
TCP?
UDP?
ICMP?
4. What information is visible?
Metadata?
Plaintext?
Encrypted?
5. Is the communication expected?
Normal?
Unexpected?
Suspicious?
6. What security control protects it?
TLS?
Firewall?
Authentication?
Network segmentation?
This is the mindset of a defensive security professional.
📝 Day 9 Assignment
Answer these questions:
1.
What is an Ethernet frame?
2.
What information can you find under Ethernet II?
3.
What is ARP used for?
4.
What is the difference between a MAC address and an IP address?
5.
What does the IPv4 TTL field do?
6.
What is a TCP sequence number?
7.
What is a TCP acknowledgment number?
8.
What are SYN, ACK, FIN, and RST?
9.
Why doesn't UDP use the TCP three-way handshake?
10.
What information can you find inside a DNS query?
11.
What is the difference between HTTP and HTTPS from a packet-analysis perspective?
12.
Why can encrypted traffic still reveal metadata?
🏆 Day 9 Challenge
Complete this investigation using your own authorized traffic:
Start Wireshark
↓
Capture traffic
↓
Generate DNS traffic
↓
Generate ICMP traffic
↓
Generate HTTPS traffic
↓
Stop capture
↓
Find ARP
↓
Find IPv4
↓
Find TCP
↓
Find UDP
↓
Find DNS
↓
Find TLS
↓
Analyze TCP flags
↓
Check Protocol Hierarchy
↓
Check Conversations
↓
Write observations
Then answer:
What is the difference between what an application does and how that activity appears on the network?
For example:
Application:
"Open a website"
Network:
DNS
↓
TCP
↓
TLS
↓
Encrypted Application Data
Understanding this relationship is a major step toward professional network security analysis.
⚠️ Ethical Hacking Reminder
LEARNING PURPOSE ONLY: Wireshark and TShark can expose sensitive network information. Use them only on your own computer, your own lab, or a network for which you have explicit authorization. Never capture passwords, cookies, personal communications, or other users' traffic without permission.
Capture ethically. Analyze responsibly. Protect privacy.
✅ Day 9 Summary
Today you learned:
Ethernet frames
MAC addresses
ARP
IPv4 headers
Source and destination IPs
TTL
TCP headers
Sequence numbers
Acknowledgment numbers
TCP flags
TCP conversations
UDP
DNS analysis
HTTP and HTTPS
TLS
Wireshark statistics
Protocol hierarchy
Conversations
Endpoints
TShark analysis
Practical analysis on Linux, Windows and macOS
🔐 Key Lesson
A security professional doesn't just see packets—they understand the story those packets tell.
🔜 Day 10 — Reconnaissance Fundamentals
Tomorrow we'll begin learning reconnaissance, one of the earliest phases of an authorized penetration test.
We'll cover:
Passive vs active reconnaissance
Attack surface
Domains and subdomains
DNS information
WHOIS concepts
IP and hosting information
Technology identification
Metadata
Search-engine-based information gathering
Linux, Windows and macOS tools
Building a safe reconnaissance lab
Documentation and scope control
⚠️ All reconnaissance exercises will remain focused on your own assets or explicitly authorized targets.
🔐 LEARN → CAPTURE → ANALYZE → UNDERSTAND → SECURE.

No comments:
Post a Comment